TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's mechanism for assessing and sharing suppliers' information security maturity, based on the VDA ISA catalog and governed by the ENX Association. German OEMs and their supply chains commonly require a TISAX label before sharing sensitive data such as prototypes or development material.
Key facts:
- Assessments are performed by accredited providers at assessment levels tied to data sensitivity, and results are shared as labels on the ENX platform rather than public certificates.
- The VDA ISA catalog aligns closely with ISO 27001, extended with automotive-specific topics like prototype protection.
- One assessment serves many customers: the exchange model exists so each OEM does not audit every supplier separately.
Why email matters in TISAX scope
Supplier ecosystems run on email: development data, drawings and credentials flow there, and business email compromise against a supplier is a proven route into OEM data. The VDA ISA's requirements on malware protection, incident management and secure information transfer make mailbox protection part of the assessed reality, especially at higher assessment levels.
Where email security fits, honestly
Sentaro supports the operational controls a TISAX assessment examines: protection against phishing and BEC, detection and evidence for incident management, and visibility into third-party access to mail and files. Scoping, the ISA self-assessment, documentation and the assessment process remain yours. Organizations also pursuing NIS2 readiness will find much of the underlying work overlaps.
This page is general guidance, not legal advice.