← Glossary

TISAX

The automotive industry's shared information security assessment, based on the VDA ISA catalog and required by many OEMs before sharing sensitive data.

Updated

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's mechanism for assessing and sharing suppliers' information security maturity, based on the VDA ISA catalog and governed by the ENX Association. German OEMs and their supply chains commonly require a TISAX label before sharing sensitive data such as prototypes or development material.

Key facts:

  • Assessments are performed by accredited providers at assessment levels tied to data sensitivity, and results are shared as labels on the ENX platform rather than public certificates.
  • The VDA ISA catalog aligns closely with ISO 27001, extended with automotive-specific topics like prototype protection.
  • One assessment serves many customers: the exchange model exists so each OEM does not audit every supplier separately.

Why email matters in TISAX scope

Supplier ecosystems run on email: development data, drawings and credentials flow there, and business email compromise against a supplier is a proven route into OEM data. The VDA ISA's requirements on malware protection, incident management and secure information transfer make mailbox protection part of the assessed reality, especially at higher assessment levels.

Where email security fits, honestly

Sentaro supports the operational controls a TISAX assessment examines: protection against phishing and BEC, detection and evidence for incident management, and visibility into third-party access to mail and files. Scoping, the ISA self-assessment, documentation and the assessment process remain yours. Organizations also pursuing NIS2 readiness will find much of the underlying work overlaps.

This page is general guidance, not legal advice.

Questions we get asked.

What is TISAX in simple terms?

The automotive industry's shared security assessment: suppliers are assessed once against the VDA ISA catalog and share the resulting label with customers through the ENX platform.

Who needs TISAX?

Suppliers and service providers handling sensitive information for automotive manufacturers, typically at the OEM's demand, common throughout DACH supply chains.

How does TISAX relate to ISO 27001?

The VDA ISA catalog builds on ISO 27001's structure with automotive additions. An existing ISMS covers much of the ground, but TISAX requires its own assessment and label.

Does email security matter for TISAX?

Yes: malware protection, incident handling and secure information transfer are assessed areas, and email is where supplier-targeted attacks like BEC actually arrive.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.