For many automotive suppliers, TISAX® initially appears only as a clause in the supply contract. As soon as the first OEM requires a valid label, it becomes a project with fixed deadlines and measurable evidence. Anyone who understands the TISAX® requirements early on can plan effort, costs, and documentation realistically, instead of failing due to gaps at the self-assessment stage. This article categorizes the requirements along the lines of the assessment catalog, maturity levels, and assessment levels, and shows what matters when it comes to implementation.
Key Takeaways at a Glance
- The basis for all TISAX® requirements is the VDA ISA, the assessment catalog of the German Association of the Automotive Industry. It is published and maintained by the ENX Association.
- The catalog is divided into three modules: Information security (46 controls), prototype protection (22 controls), and data protection (12 controls), together comprising more than 300 assessment questions.
- On average, at least maturity level 3 must be demonstrated for a label, meaning processes are actively practiced and verifiable.
- The assessment level (AL 1 to AL 3) determines the depth of the audit, not the scope of the requirements.
- A TISAX® label is valid for three years. After that, a new assessment is required.
What lies behind the TISAX® requirements?
TISAX® stands for Trusted Information Security Assessment Exchange and is the assessment and exchange procedure for information security in the automotive industry. It was developed by the German Association of the Automotive Industry (Verband der Automobilindustrie, VDA) and is operated by the ENX Association, headquartered in Frankfurt. The goal is to standardize security audits between manufacturers and suppliers: Instead of auditing each supplier individually, participants mutually recognize a valid label.
In terms of content, the TISAX® requirements catalog is closely aligned with ISO/IEC 27001. Around three-quarters of the controls overlap, supplemented by industry-specific topics such as prototype protection and extended data protection. Companies that already operate an ISMS in accordance with ISO 27001 have a solid foundation for the information security module. However, an existing certificate does not replace the label.
Who is subject to the TISAX® requirements?
The TISAX® requirements apply to all companies along the automotive value chain, not just to traditional parts manufacturers. As soon as a company processes information worthy of protection from an OEM or tier 1 supplier, a label can be contractually required. Accordingly, this also affects engineering service providers, logistics partners, IT providers as well as media and advertising agencies, print shops, and booth builders operating on behalf of the automotive industry.
Whether a label is needed is not determined by a company's own self-image, but by its position in the supply chain. Many manufacturers now pass the requirement on to their direct suppliers, who in turn impose it on their subcontractors. For suppliers, this means: The question is rarely whether TISAX® will become relevant, but rather when and to what extent. Clarifying the assessment objective and assessment level early on prevents a label required at short notice from delaying contract signing.
How is the TISAX® requirements catalog structured?
The VDA ISA is a structured Excel document containing more than 300 assessment questions. Since April 1, 2024, version 6.0 has been the binding basis for assessments. The catalog consists of three modules:
- Information security: 46 controls. This core module applies to nearly every participant and covers topics such as access management, backup and recovery, incident and crisis management, supplier management, and business continuity.
- Prototype protection: 22 controls in five sections. Relevant for companies working with unreleased vehicles, components, or design data. Requirements include physical access controls, non-disclosure agreements, and transport regulations, among others.
- Data protection: 12 controls aligned with the GDPR. Relevant when personal data is processed on behalf of a client.
For each requirement, the catalog distinguishes four levels: must requirements, should requirements, and additional requirements for high and very high protection needs. Which levels apply depends on the chosen assessment objective and the label derived from it, such as confidential, strictly confidential, or data.
What maturity level does TISAX® require?
Whether a requirement is met is assessed by the auditor using a maturity level from 0 to 5. The scale ranges from 0 for a missing or incomplete process to 5 for a continuously improved process. On average, at least maturity level 3 must be demonstrated for a label, meaning an established standard process that has verifiably been in place over an extended period.
Only a maximum value of 3 is factored into the calculation. A particularly well-implemented requirement therefore cannot offset a weak one. In practice, companies need an average of at least 2.7 to pass. Documentation alone is not enough: The auditor verifies whether authorization concepts, backups, training, and incident handling are actually being applied.
TISAX® certification: Which requirements apply to each assessment level?
The assessment level determines the depth of the audit. It is based on the protection needs of the information and is generally specified contractually by the OEM.
- AL 1: self-assessment only, without external review. No OEM accepts this level as evidence. It is only suitable for internal benchmarking.
- AL 2: Standard case for most participants. An accredited assessment provider evaluates the self-assessment, usually remotely, based on documents and interviews. Around two-thirds of all active labels are at this level.
- AL 3: highest level of scrutiny with on-site audit and intensive verification. Mandatory as soon as particularly sensitive data or prototypes are in scope.
Regardless of the level, companies must demonstrate a functioning ISMS and meet the requirements of the VDA ISA. The level changes the depth of verification, not the catalog.
TISAX® level 3 requirements: What does this mean in concrete terms?
Two things are often confused with the term "Level 3." It can refer to assessment level 3 (AL 3), meaning the audit depth, or maturity level 3, meaning the required process maturity. For a label, maturity level 3 is always the benchmark, regardless of the chosen assessment level.
Assessment level 3 also entails specific additional requirements. The audit takes place on site; the auditor verifies evidence directly at the location and examines technical implementations more thoroughly than in a remote audit. AL 3 is mandatory for the prototype protection assessment objective and for information with very high protection needs. Suppliers with access to prototype data, unpublished designs, or test vehicle data cannot avoid this level. Preparation effort and costs are correspondingly higher, since physical security, access controls, and seamless chains of evidence must also be demonstrated.
What will change with VDA ISA 2027?
On July 1, 2026, the VDA released the successor catalog. Instead of a version number, it bears the year-based designation VDA ISA 2027. The information security module retains its 46 controls, though the majority of them have been revised. Prototype protection shrinks from 22 to 20 controls and is being structurally rebuilt. Data protection remains unchanged at 12 controls. New additions include a mapping to ISO/IEC 27001:2022 and the NIST Cybersecurity Framework 2.0. In addition, several previous recommendations become binding obligations. Supplier management is also moving further into focus.
Important for planning: Until the ENX Association announces a binding transition date, assessments will continue to be conducted under VDA ISA 6.0. Existing labels do not automatically lose their validity. A gap analysis against the revised controls is nevertheless worthwhile in order to be prepared early on.
How do automotive suppliers meet the TISAX® requirements with Athereon GRC?
Implementation of the TISAX® requirements rarely fails because of the catalog itself, but rather due to a lack of structure: unclear responsibilities, outdated documentation, no up-to-date asset register. This is where Athereon GRC comes in, the leading European GRC platform. It consolidates the relevant records, measures, and processes in one place and makes the maturity level transparent for each requirement.
Athereon GRC is built on a framework-agnostic architecture. You can manage TISAX®, ISO 27001, GDPR, and other requirements in parallel without having to maintain records twice. The specialized modules ISMS, ERM, BCM, DSM, and SRM interlock, so that a record maintained once takes effect across multiple frameworks.
AI agent LAiKA supports you in the preparation. It operates according to a clear escalation logic: from the foundation through LAiKA Assist to the specialized agents Infrastructure Mapper, Compliance Assistant, and Questionnaire Assistant. The Questionnaire Assistant helps with completing the VDA ISA and suggests appropriate evidence, while the Infrastructure Mapper captures your system landscape and the Compliance Assistant makes open items visible for each control. The following applies: Nothing without your OK. Every action remains under your control; suggestions are only adopted after your approval. As a platform that is 100% made in Germany, Athereon GRC itself meets high standards for data storage and sovereignty, which is a particular advantage in the automotive supply chain. You can find a regulatory overview on our TISAX® page. You can find more in-depth information as well as insider tips in our white paper (available in German): „TISAX® in der Praxis. Strategien, Hürden & neue Anforderungen.“
Frequently Asked Questions About TISAX® Requirements
Are the TISAX® requirements legally mandatory?
No, there is no legal obligation. In practice, however, a label is a prerequisite for collaboration with many OEMs and Tier 1 suppliers.
How long is a TISAX® label valid?
A label is valid for three years. After that, a new assessment is required.
Does an ISO 27001 certification replace the TISAX® requirements?
No. An ISO 27001 certification covers a large portion of the information security module, but it does not replace the label.
Which assessment level do I need?
This is usually specified contractually by the OEM. Without such a specification, the level is determined by the protection needs of the information being processed.
Conclusion: Compliance as an Opportunity
The TISAX® requirements are demanding, but manageable with proper planning. By considering the assessment catalog, maturity levels, and assessment level together early on, you shorten preparation time and avoid costly rework. With Athereon GRC, you keep evidence, deadlines, and responsibilities in one place and turn compliance into an opportunity to strengthen your position in the automotive supply chain.

.svg.webp)


