If you supply the automotive industry, particularly European or German manufacturers, sooner or later you will be asked for a TISAX label. TISAX (Trusted Information Security Assessment Exchange) is how the automotive sector assures information security across its supply chain. Here’s what it is, how it’s assessed, and how Australian suppliers prepare. In the assessments I’ve been involved with, the request nearly always lands with a tight deadline attached. The suppliers who cope best are the ones who had already made information security business-as-usual, long before a customer came asking.

What is TISAX?
TISAX is an industry assessment and exchange mechanism governed by the ENX Association on behalf of the German automotive industry association (VDA). Rather than every car maker auditing every supplier, suppliers undergo one standardised assessment and share the result (a TISAX label) with the manufacturers they work with. It’s built on the VDA ISA (Information Security Assessment) catalogue, which is closely aligned with ISO 27001.
Assessment levels and objectives
TISAX assessments come in three assessment levels (AL 1 to AL 3) reflecting the depth and rigour required. Higher levels involve on-site or more thorough evidence. You’re also assessed against specific assessment objectives, which commonly include information security, the protection of prototypes, and data protection, depending on what you handle for your customers.
How the TISAX process works
- Register on the ENX TISAX portal and define your assessment scope and objectives.
- Self-assess your information security against the VDA ISA catalogue and close the gaps.
- Be assessed by an ENX-accredited TISAX audit provider.
- Share your result (the TISAX label) with your customers through the exchange. Labels are typically valid for three years.
TISAX and ISO 27001
Because the VDA ISA is built on the same foundations as ISO 27001, an ISO 27001-aligned information security management system gets you most of the way to TISAX. If you already hold or are building ISO 27001, preparing for TISAX is largely a matter of mapping to the VDA ISA catalogue and addressing the automotive-specific requirements (such as prototype protection). The gap I most often find in otherwise solid ISO 27001 shops is exactly that prototype piece: physical controls around pre-release parts, camera and photography rules on the floor, tighter visitor management. It rarely gets attention until an automotive customer puts it on the table.
How Streamline helps
We provide TISAX readiness for Australian automotive suppliers: building your information security management system on an ISO 27001 base, mapping it to the VDA ISA, and getting you ready for the formal assessment. We prepare you for the assessment; the assessment itself is conducted by an ENX-accredited provider.
Frequently asked questions
Is TISAX the same as ISO 27001?
No, but they’re closely related. TISAX is the automotive industry’s assessment based on the VDA ISA, which aligns with ISO 27001. An ISO 27001 system is a strong foundation for TISAX, but TISAX adds automotive-specific requirements.
Do Australian suppliers need TISAX?
If you supply European or German automotive manufacturers, very likely. It’s commonly a contractual requirement. If you don’t, ISO 27001 is usually the more appropriate, broadly recognised choice.
Speak with an experienced ISO auditor
Need TISAX for an automotive customer? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











