VDA ISA · ENX · objectives and assessment levels
No TISAX label, no bid. That is the position in automotive.
TISAX is not a standard but an assessment and exchange mechanism. Working for German manufacturers means going through it – and evidencing your own providers along the way.
It rests on the VDA information security catalogue, largely aligned with ISO/IEC 27001 and extended by sector-specific objectives: prototype protection, handling of particularly sensitive data, in part data protection. Accredited providers assess; results are shared with customers through the ENX platform.
The part that regularly trips suppliers up is not their own technology but the chain behind it. Passing development, production or IT operations onward means showing that the requirements apply there too – and that this is verified.
Who needs a label
- Direct suppliers to German automotive manufacturers, wherever they are based.
- Development and engineering providers with access to design data.
- Firms producing or storing prototypes and pre-series parts.
- IT and logistics providers of the above – through their evidence duties.
What concerns the chain
- Providers
- Anchor requirements for subcontractors contractually and verify compliance.
- Prototype protection
- Govern access, transport and storage at commissioned third parties too.
- Access
- Control external access to design and production data with documentation.
- Incidents
- Reporting routes that also capture events at a provider.
- Validity
- Labels expire; renewal wants planning, not discovery.
How SCRM covers it
Labels in view
Validity of your own label and your providers’ labels, with reminders.
Subcontractors
Who works on which data – the question the assessment asks.
Evidence store
Contracts, assurances and assessment results on the supplier, not in a project folder.
Customer demands
Which manufacturer requires which assessment level, with a deadline.
Frequently asked
Is ISO 27001 enough instead of TISAX?
Often not. TISAX includes objectives absent from ISO 27001, such as prototype protection. An existing ISMS is nevertheless the best preparation, because most requirements overlap.
We are a Swiss supplier. Does it apply?
Yes, as soon as a customer asks. TISAX is not law but a contractual market requirement – and those ignore borders.
Must our suppliers hold TISAX too?
Not necessarily. You must pass the requirements on and verify compliance. How deeply is a risk decision – one you must be able to justify.