Attestation · Last verified

Trusted Information Security Assessment Exchange

TISAX is ENX Association's assessment and label exchange mechanism for automotive-industry information security, based on third-party assessment. A passed assessment earns a TISAX label, valid for three years, and ENX maintains the audit provider criteria and requirements; results are shared only within the closed TISAX community.

Class
Attestation
Owner
ENX Association
Who asks for it
Buyer-driven
Last verified

What it is

TISAX is run by ENX Association, which describes it as "an assessment and exchange mechanism for the information security of enterprises" that "allows recognition of assessment results among the participants". What a company receives is not a certificate but a label: in ENX's words, "'Assessment objectives' and 'TISAX labels' are almost the same … if you pass the assessment you receive the corresponding 'TISAX labels'." The assessment catalogue is the Information Security Assessment (ISA), and per the handbook, TISAX "covers the automotive industry's widely accepted information security requirements". An assessment result is valid for three years.

ENX states that there is no public register of results: "TISAX is closed community of trust, TISAX assessment results are only used within this community and not for the general public"; results are searchable only after login, by participants.

Who owns it

TISAX is run by ENX Association.

Who assesses it

ENX's role: "ENX maintains the audit provider criteria and assessment requirements (TISAX ACAR)." ENX publishes a list of approved audit providers.

Assessment levels

  • AL 1 — For an assessment in assessment level 1, an auditor checks for the existence of a completed self-assessment. He does not assess the content of the self-assessment.
  • AL 2 — For an assessment in assessment level 2, the audit provider does a plausibility check on your self-assessment (for all locations within the assessment scope). He supports this by checking evidence and conducting an interview with the person in charge information security.
  • AL 3 — For an assessment in assessment level 3, the audit provider does a comprehensive verification of your company's compliance with the applicable requirements.

Who asks for it

Demand comes from business partners in the automotive supply chain. The handbook opens from the supplier's side: "One of your partners requested that you prove that your information security management complies with a defined level according to the requirements of the 'Information Security Assessment' (ISA)." No legal instrument requiring TISAX was identified in the sources reviewed as of 29 August 2026 — confirm against ENX and the contracting customer.

Validity

Your assessment result is valid for three years, per the TISAX Participant Handbook.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Trusted Information Security Assessment Exchange." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/tisax

All frameworks & audits →