Attestation · Last verified
Trusted Information Security Assessment Exchange
TISAX is ENX Association's assessment and label exchange mechanism for automotive-industry information security, based on third-party assessment. A passed assessment earns a TISAX label, valid for three years, and ENX maintains the audit provider criteria and requirements; results are shared only within the closed TISAX community.
- Class
- Attestation
- Owner
- ENX Association
- Who asks for it
- Buyer-driven
- Last verified
What it is
TISAX is run by ENX Association, which describes it as "an assessment and exchange mechanism for the information security of enterprises" that "allows recognition of assessment results among the participants". What a company receives is not a certificate but a label: in ENX's words, "'Assessment objectives' and 'TISAX labels' are almost the same … if you pass the assessment you receive the corresponding 'TISAX labels'." The assessment catalogue is the Information Security Assessment (ISA), and per the handbook, TISAX "covers the automotive industry's widely accepted information security requirements". An assessment result is valid for three years.
ENX states that there is no public register of results: "TISAX is closed community of trust, TISAX assessment results are only used within this community and not for the general public"; results are searchable only after login, by participants.
Who owns it
TISAX is run by ENX Association.
Who assesses it
ENX's role: "ENX maintains the audit provider criteria and assessment requirements (TISAX ACAR)." ENX publishes a list of approved audit providers.
Assessment levels
- AL 1 —
For an assessment in assessment level 1, an auditor checks for the existence of a completed self-assessment. He does not assess the content of the self-assessment.
- AL 2 —
For an assessment in assessment level 2, the audit provider does a plausibility check on your self-assessment (for all locations within the assessment scope). He supports this by checking evidence and conducting an interview with the person in charge information security.
- AL 3 —
For an assessment in assessment level 3, the audit provider does a comprehensive verification of your company's compliance with the applicable requirements.
Who asks for it
Demand comes from business partners in the automotive supply chain. The handbook opens from the supplier's side: "One of your partners requested that you prove that your information security management complies with a defined level according to the requirements of the 'Information Security Assessment' (ISA)." No legal instrument requiring TISAX was identified in the sources reviewed as of 29 August 2026 — confirm against ENX and the contracting customer.
Validity
Your assessment result is valid for three years, per the TISAX Participant Handbook.
Sources
- ENX Association — TISAX (scheme owner) ↗ — accessed
- ENX — TISAX Participant Handbook ↗ — accessed
- ENX Association — about ↗ — accessed
- ENX — public list of TISAX audit providers ↗ — accessed
- ENX — TISAX assessment results sharing (closed-community rule) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.