Blog Post

Omnex Blog > News > Cybersecurity > Why TISAX Has Become a Contract Requirement for Automotive Suppliers

Why TISAX Has Become a Contract Requirement for Automotive Suppliers

TISAX is no longer a “nice to have” in the automotive supply chain; for many OEMs and Tier-1s it is now a formal requirement to win new business. If you are not certified to the required TISAX label, you may not even receive an RFQ from some customers. This shift is driven by rising cyber threats and growing concern about intellectual property, personal data, and operational continuity.

This blog summarizes the key points from the TISAX and ISO 27001 webinar, explaining what TISAX is, how it compares to ISO 27001, how the ISA works, and what OEMs are now expecting from their suppliers.

What TISAX Is and Who Is Behind It

TISAX stands for Trusted Information Security Assessment Exchange. It is an information security assessment and exchange mechanism developed for the automotive industry and put forward by the ENX Association together with the German automotive association VDA.

ENX is made up of a group of member organizations and operates the ENX portal, where participants can register, access the TISAX participant handbook, download the ISA (Information Security Assessment) Excel document and manage their scopes and labels. The participant handbook effectively acts as the “TISAX bible” for organizations starting their journey, with a detailed table of contents and hyperlinks into specific topics.

Why Information Security Matters So Much to OEMs

Information security has become critical for OEMs and large suppliers because of:

  • Increasing instances of companies being hacked or hit with ransomware, often resulting in intellectual property or personal data being compromised.
  • The risk that highly valuable assets, such as prototypes or confidential designs, are lost or exposed through everyday human mistakes.

The webinar illustrates this with concrete examples:

  • The panic people feel when a mobile phone or laptop is lost, because of the sensitive information stored on it.
  • A real case where a very expensive Formula One prototype was left in the trunk of a rental car, creating serious risk to the intellectual property invested in the vehicle.
  • High-profile cyber incidents like the CrowdStrike event that caused millions of computers to show the blue screen of death worldwide.

Because of these risks, many OEMs and Tier-1s now treat TISAX as a mandatory prerequisite; if you are not certified, you may not qualify to respond to RFQs. In parallel, sanctioned interpretations of IATF 16949 have strengthened contingency planning expectations, including cyber scenarios on both IT and OT (shop floor) environments.

Why Organizations Pursue TISAX Certification

TISAX certification is pursued primarily to:

  • Protect organizational assets and information needed to run the business.
  • Safeguard customer intellectual property as well as the organization’s own domain expertise, proprietary processes and know-how.

The webinar emphasizes that people make mistakes, forget things and misplace devices, and that these human factors create exposure unless there is a structured framework to protect information. TISAX provides such a framework for the automotive context, and that is what justifies the effort to become certified.

TISAX Labels, the ISA and Maturity Levels

Unlike ISO standards that issue certificates, TISAX issues labels. A label indicates the level of protection and the assessment level achieved for a defined scope and is published on the ENX platform once you pass your assessment.

The core assessment tool is the ISA (Information Security Assessment) document:

  • It is an Excel file downloaded from the ENX website.
  • It contains 80 controls, divided into three tabs: information security, prototype protection, and data protection.

Each control is assigned a maturity level during assessment. In the TISAX ISA:

  • Maturity is evaluated control by control, based on how well the control is deployed, whether policies and procedures exist, whether people are aware of them and follow them in daily work, and what evidence is available.
  • A maturity level of 3 is the basic expectation in order to be certified.

Auditors review the ISA with you, look at evidence for each control and assign maturity levels accordingly. The goal is to reach at least level 3 across the relevant controls. The ISA also uses “must” and “should” requirements: “must” is the equivalent of “shall” in ISO standards and must be fulfilled to avoid nonconformities that can block certification, while “should” requirements are not strictly mandatory but can influence maturity scores and improvement recommendations.

When all controls are scored, the ISA produces results including a spider chart that visualizes maturity levels across the control groups in the three tabs and a summarized score in a results tab.

Assessment Levels AL1, AL2 and AL3

TISAX defines three assessment levels: AL1, AL2 and AL3. In practice, most organizations target AL2 or AL3.

  • AL2 is typically used where protection needs are “high” and involves:
  • A plausibility-based review of documentation.
  • Evidence sampling where auditors “cherry pick” what they see as important for your TISAX framework.
  • Remote interviews rather than fully onsite visits.
  • AL3 is required where protection needs are “very high” or “strict,” and involves:
  • More intensive, in-depth evidence collection.
  • Onsite audits and face-to-face interviews as a standard.

Assessment objectives for confidentiality, integrity, availability, prototype protection and data protection are defined in the ISA across the three tabs. For example, if you run a website that multiple customers depend on to access product information, high or very high availability may be necessary because downtime or slow responses directly affect your business. The combination of these assessment objectives (e.g., “high confidential” vs “very high” or “strictly confidential”) drives whether AL2 or AL3 is appropriate.

TISAX vs ISO 27001: Scope and Approach

The webinar presents a detailed comparison between TISAX and ISO 27001.

ISO 27001

  • ISO 27001 is built around an Information Security Management System (ISMS), analogous to a Quality Management System in ISO 9001 or IATF 16949.
  • It follows the Annex SL high-level structure, with clauses on context, leadership, planning, support, operation, performance evaluation and improvement.
  • Organizations define a scope in an ISMS manual, including a scope statement and a process map with sequences and interactions of processes.
  • A Statement of Applicability (SoA) covers the 93 Annex A controls, indicating whether each control is applicable and how it is implemented.
  • Certification is achieved through stage 1 and stage 2 audits, and a certificate is issued; surveillance audits typically occur in years one and two, followed by a recertification audit in year three.

TISAX

  • TISAX is not a complete management system standard; it uses the ISA as a structured questionnaire, based largely on ISO 27001 controls with additional specifications tailored to the automotive industry.
  • The ISA itself effectively becomes the equivalent of a Statement of Applicability, since you walk through each control, determine applicability, and show how it is fulfilled.
  • TISAX results in a label rather than a certificate, and that label is uploaded to the ENX platform where customers and other interested parties can see it.
  • Validity is three years, similar to ISO 27001, but instead of external surveillance audits every year, you are expected to rescore yourself against the ISA periodically, which plays a role similar to internal audits.

While ISO 27001 can apply to many industries and even pure service companies, TISAX is deliberately narrow and focused on the automotive sector, with dedicated controls for prototype protection and data protection that reflect automotive and European regulatory expectations. If you already have ISO 27001 certification, you may be 60–70% of the way toward TISAX because of the overlap in controls.

Assets, CIA and the ISMS Process View

Both TISAX and ISO 27001 exist to protect organizational assets. The webinar distinguishes several asset types:

  • Intellectual property and proprietary know-how.
  • Financial information, including sensitive financial data.
  • Software code and architecture.
  • Customer data and customer tooling.
  • Personal data managed by HR, such as health and compensation information.
  • Product designs, proprietary process secrets and accumulated organizational knowledge.

These assets can be grouped into three broad buckets: physical assets (buildings, equipment, hardware), information assets and people assets such as key employees with critical domain expertise. An asset inventory and matrix can help track what assets exist, who owns them, where they are located and which categories they fall into.

From an ISMS perspective, the main expected outcome is CIA – confidentiality, integrity and availability of information. The process map shown in the webinar illustrates:

  • Management processes at the top.
  • Core information security processes in the middle, such as identity and access management, risk management, backup and recovery, malware and vulnerability management, and penetration testing.
  • Support processes at the bottom.

CIA, along with any regulatory compliance obligations, is the overall output of this process landscape.

Leave a Reply

Discover more from Omnex Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading