About this Framework
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's standard for assessing and sharing information security assessment results across supply chains, based on the VDA Information Security Assessment (ISA) and aligned with ISO/IEC 27001. Assessments are conducted by ENX-accredited auditors, with results exchanged via the ENX TISAX portal. BMW, Mercedes-Benz, Volkswagen, Stellantis and other major OEMs require valid TISAX labels from all suppliers handling prototype data, personal data or connected vehicle information systems.
Key Control Domains
Information Security Management
Physical Access Control
Prototype & Vehicle Data Protection
Connected Vehicle & Software Security
Personal Data Protection (GDPR alignment)
Third-Party Risk Management
Incident Response
Business Continuity
Who Needs This?
- Tier 1 and Tier 2 automotive component and system suppliers
- Engineering and design partners handling OEM prototype data
- IT service providers and managed service companies serving OEMs
- Logistics and manufacturing partners in automotive supply chains
- Any company handling BMW, VW, Mercedes-Benz or Stellantis confidential data
Compliance Benefits
- Mandatory prerequisite for major OEM supplier contracts
- Single assessment — results shared across all OEM customers via ENX portal
- Eliminates multiple separate customer security audit cycles
- Globally recognised across European, U.S. and Asian automotive ecosystems
Official Reference
ENX TISAX Portal
https://enx.com/en-US/TISAX/
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/tisax-automotive-security-assessment