TISAX · Automotive Security · VDA ISA

TISAX pentest:
Security evidence for the automotive industry

As a supplier or service provider in the automotive sector, you must demonstrate your information security to OEMs. Our TISAX pentest delivers the technical evidence required by the VDA ISA: structured and auditable, with a report ready within 5 working days.

  • VDA ISA mapping included in report
  • AL 1 to AL 3 fully covered
  • Report delivered within 5 working days

What TISAX requires of you

  1. 01

    Evidence per VDA ISA

    The VDA ISA questionnaire is the assessment basis for all TISAX labels. Our report maps every finding directly to the relevant controls.

  2. 02

    Technical penetration test

    From a high protection need, the VDA ISA requires critical systems to be tested technically and names the penetration test as a suitable means. We deliver the practical pentest report to support your audit.

  3. 03

    Prototype & data protection

    Dedicated TISAX labels for prototype protection and GDPR compliance require specific test scenarios, both physical and technical.

  4. 04

    OEM supplier obligation

    BMW, VW, Mercedes-Benz, Porsche, Audi, Bosch and Continental require TISAX from all Tier-1 and Tier-2 suppliers.

Our TISAX pentest report is designed as a technical evidence document for your approved TISAX audit provider and is ready for direct use in your assessment.

TISAX explained

What is TISAX and who does it affect?

TISAX (Trusted Information Security Assessment Exchange) is the binding information security standard of the German automotive industry, developed by the VDA. It is based on ISO/IEC 27001 and the VDA ISA questionnaire and defines how suppliers must demonstrate the protection of sensitive information. Results are shared exclusively via the ENX platform, not made publicly accessible.

  • TISAX labels are valid for three years, after which a full recertification is required.

  • Results are shared exclusively via the closed ENX platform; there is no public certificate.

  • Required by manufacturers and Tier-1 suppliers such as BMW, VW, Mercedes-Benz, Porsche, Audi, Bosch and Continental – whether it applies to you is in your contract.

  • Five disclosure levels (A to E) on the ENX platform let you decide exactly how much detail a requesting partner can see about your assessment result.

TISAX vs. ISO 27001

How does TISAX differ from ISO 27001?

TISAX® Criterion ISO 27001
Automotive Industry focus Cross-industry
VDA ISA + ISO 27001 Framework basis ISO 27001
Label via ENX platform Evidence type Public certificate
From AL 2 Technical review expected Optional
3 years Validity 3 years (annual surveillance)
Assessment levels

Which assessment level applies to your organisation?

TISAX distinguishes three protection requirement levels. Your OEM specifies which level you must meet. We conduct penetration tests for all three assessment levels.

  1. Assessment Level 1

    Normal protection requirement

    For organisations processing confidential information without particularly sensitive content. A qualified self-assessment without external review is sufficient, though this does not produce a TISAX label shareable on the ENX platform. A pentest is nonetheless recommended as additional voluntary evidence.

    • Self-assessment / own declaration
    • No on-site audit required
    • No registrable TISAX label on the ENX platform
  2. Assessment Level 2

    High protection requirement

    For organisations handling highly sensitive information such as development data or vehicle concepts. An approved audit provider checks the self-assessment for plausibility using evidence and interviews, typically via web conference, not necessarily on-site. From this protection need onwards, the VDA ISA requires critical IT systems to be tested technically and names the penetration test as a suitable means.

    • Plausibility check by an approved audit provider (usually via web conference)
    • Technical review of critical systems expected, pentest named as a means
    • Most common level for Tier-1 suppliers
  3. Assessment Level 3

    Very high protection requirement

    For organisations working with prototypes and strictly confidential data. An approved audit provider conducts a full on-site audit with document inspection and interviews, the highest level of scrutiny within TISAX.

    • Full on-site audit with document inspection
    • Extended physical security assessment
    • Full-scope infrastructure penetration test
AL 1 vs. AL 2 vs. AL 3

Assessment method, location, and outcome compared directly

Criterion Assessment Level 1 Assessment Level 2 Assessment Level 3
Assessment method Self-assessment (online questionnaire) Plausibility check with evidence & interviews Full audit with document inspection & interviews
Assessment location No appointment required Usually web conference (remote) On-site at the organisation
Conducted by No external review Approved audit provider Approved audit provider
TISAX label on ENX portal Not issued Yes Yes
Typical protection need Normal High Very high (e.g. strictly confidential, prototype protection)
Technical pentest Recommended, voluntary Expected in practice Expected, extended scope
TISAX labels explained

A TISAX label is not a blanket certificate

Contrary to common assumption, there is no blanket "TISAX certified" status. Each organisation receives a specific label tied to a concrete assessment object (location, protection objective, and assessment level), which it shares selectively with requesting partners via the ENX platform rather than publishing it.

  • Formerly "Info High"

    Confidential

    Confirms adequate protective measures for confidential information with a high protection need, such as development documentation. Typically demonstrated via Assessment Level 2.

  • Formerly "Info Very High"

    Strictly Confidential

    The highest confidentiality tier, for strictly confidential information such as unreleased vehicle concepts. Issued exclusively via Assessment Level 3 with a full on-site audit.

  • New with VDA ISA 6.0

    High Availability

    Confirms that IT systems and processes meet defined recovery and continuity requirements for a high availability need.

  • New with VDA ISA 6.0

    Very High Availability

    Adds the highest availability tier: relevant where an outage would directly threaten the OEM's vehicle production.

  • Multiple labels by protection object

    Prototype protection

    Not a single label but several assessment objects: protection of components, test vehicles, presentation events, and confidentiality areas against unauthorised viewing or disclosure.

  • Basic / High

    Data protection

    Confirms implementation of data processing requirements under GDPR Article 28 across two tiers, relevant when processing personal data on behalf of an OEM.

On the ENX platform, five disclosure levels (A to E) let you decide exactly how much detail a requesting partner can see about your result, from a bare status to the full report.
Assessment areas

Which VDA ISA controls do we test technically?

The VDA ISA questionnaire covers all security-relevant areas. Our pentest delivers the technical evidence for the following controls, ready for direct use with your ENX auditor.

Current status: VDA ISA version 6.0, mandatory since 1 April 2024 for newly commissioned assessments, adding controls for crisis management, IT service continuity, and backup & recovery, plus dedicated availability labels.

  • VDA ISA 1.x

    Information security management

    Evidence of a functioning ISMS: policies, roles, responsibilities, and awareness measures in line with VDA ISA Chapter 1.

    Policy & governance review
  • VDA ISA 3.x

    Physical security

    Access control, building security, secure disposal of storage media, and protection of server rooms in line with VDA ISA Chapter 3.

    Physical pentest & tailgating
  • VDA ISA 4.x

    IT & cyber security

    Network segmentation, vulnerability management, patch management, access control, and logging in line with VDA ISA Chapter 4.

    Infrastructure pentest
  • Prototype protection module

    Prototype protection

    Special protection for prototype vehicles and components: covers, camouflage, secure storage, transport, and access control to prototype areas. A standalone VDA ISA assessment module, not a chapter of the core questionnaire.

    Prototype protection assessment
  • Data protection module

    Data protection (GDPR)

    Processing of personal data in the automotive context: consent, deletion concepts, and technical protective measures. A standalone VDA ISA assessment module for data processing under GDPR Article 28.

    GDPR technical layer review
  • VDA ISA 7.x

    Third parties & supply chain

    Security requirements for service providers and sub-suppliers: contracts, audits, remote access, and security clauses in line with VDA ISA Chapter 7.

    Supply chain risk assessment

Without a TISAX label you risk:

  • Loss of OEM contracts: without a valid TISAX label you will typically not be approved as a supplier or will be excluded from tenders.
  • Breach of contract: existing supply agreements can be terminated or not renewed if a TISAX label is missing or has expired.
  • Reputational damage: security incidents without proven protective measures put long-term OEM partnerships at risk.
  • GDPR liability: missing data protection evidence in the automotive context can result in proceedings under GDPR Article 83.
Who is affected?

Which organisations in the automotive supply chain does TISAX apply to?

TISAX becomes binding the moment a customer makes it a contractual condition – typically for organisations that process confidential information from OEMs or Tier-1 suppliers, regardless of company size or headcount.

  • OEMs & vehicle manufacturers
  • Tier-1 suppliers
  • Tier-2 suppliers
  • Software & IT service providers
  • Engineering & development offices
  • Design & prototyping firms
  • Logistics & transport (prototypes)
  • Research & development
  • Telematics & connected car
Our approach

How does your TISAX pentest work?

We guide you from scope definition to an audit-ready report, on time and fully aligned with the VDA ISA questionnaire.

  1. 01

    Scope definition & kickoff

    Joint definition of TISAX assessment objectives, assessment level, systems in scope, and timeline. Exclusion zones are documented as binding commitments.

  2. 02

    Information gathering & reconnaissance

    OSINT, network analysis, physical building walkthrough, and system inventory in line with the VDA ISA assessment catalogue.

  3. 03

    Technical penetration test

    Infrastructure pentest, Active Directory analysis, physical security assessment, and social engineering in line with VDA ISA requirements.

  4. 04

    Analysis & VDA ISA mapping

    All findings are mapped directly to the corresponding VDA ISA controls, for maximum auditability and minimum effort during the ENX audit.

  5. 05

    Report & handover

    Detailed pentest report with CVSS ratings, VDA ISA mapping, prioritised remediation recommendations, and an executive summary for senior management.

TISAX pentest report · sample excerpt Sample
Unencrypted CAD file share accessible on internal networkCritical
Server room access without MFA and badge controlCritical
Tailgating: server room entry without authenticationHigh
Active Directory: kerberoastable service accountsHigh
Missing network segmentation between development and productionMedium
Outdated TLS configuration on internal web serverLow
VDA ISA mapping included TISAX is a registered trademark of the ENX Association.

Illustrative example – no real customer data.

  • 3 yearsValidity of the TISAX label
  • 5 daysReport after test completion
  • AL 1-3All levels covered
  • 100+Completed pentests
Our services

TISAX pentests from a single source

We combine physical, digital, and social engineering attack vectors into a single TISAX assessment from one provider, fully mapped to VDA ISA.

  • Physical security pentest

    Access control, tailgating, lock bypass, camera blind spots, and prototype areas: we test whether your physical security holds up under TISAX AL 2 and AL 3 requirements.

    Learn more
  • Infrastructure & Active Directory

    Network segmentation, patch status, Active Directory security, and remote access: technically verified and directly mapped to VDA ISA Chapter 4.

    Learn more
  • Social engineering & awareness

    Phishing, vishing, and pretexting targeting your employees: we test the human firewall that VDA ISA Chapter 1 requires as a central protective measure.

    Learn more
Frequently asked questions

TISAX pentest: your questions answered

Every organisation that works for OEMs or Tier-1 suppliers and processes their confidential information. From a high protection need, the VDA ISA requires critical IT systems to be tested technically and names the penetration test as a suitable means. At AL 1 it is recommended as voluntary evidence. OEMs that require TISAX from their suppliers include BMW, VW, Mercedes-Benz, Porsche, Audi, Bosch, and Continental, among others.
Costs depend on scope, company size, and assessment level. Contact us for an individual quote; you will typically receive one within 24 hours of the free initial consultation. An AL2 assessment with a plausibility check costs noticeably less than a full AL3 on-site audit with prototype protection.
Typically 3 to 10 working days depending on scope and assessment level. The written report with VDA ISA mapping is delivered within 5 working days of completing the test. For AL3, with a full on-site audit and a prototype protection review, the test duration falls at the upper end of that range.
No. The TISAX audit is conducted by an approved TISAX audit provider. Our pentest report is the technical evidence document that the auditor requires and accepts for VDA ISA-relevant controls. The auditor checks against the current VDA ISA questionnaire, mandatory in version 6.0 for newly commissioned assessments since 1 April 2024.
Yes. The TISAX prototype protection label has its own questionnaire. We conduct targeted physical assessments for this: camera blind spots, vehicle covers, secure storage areas, access control, and transport processes. The prototype protection assessment covers several separate labels rather than one certificate, depending on what's being protected, such as components, test vehicles, or confidentiality areas.
TISAX builds on ISO 27001 and extends it with automotive-specific requirements from the VDA ISA catalogue. Existing ISO 27001 evidence is taken into account during the TISAX audit but does not fully replace it. TISAX results are never published; they are shared only via the ENX platform with partners you choose.
AL1 is a pure self-assessment with no external review and does not produce a label shareable on the ENX platform. AL2 is a plausibility check by an approved audit provider, usually via web conference. AL3 requires a full on-site audit with document inspection and interviews, for the highest protection needs, such as prototype protection.
VDA ISA 6.0 has been mandatory for newly commissioned assessments since 1 April 2024. It adds five new controls (including software approval, crisis management, IT service continuity, and backup & recovery), introduces dedicated availability labels, and aligns with ISO/IEC 27001:2022.
No one automatically. Results are not published; they are shared exclusively via the ENX platform with partners you choose. Five disclosure levels (A to E) let you decide how much detail a requesting partner can see.
The TISAX label is valid for three years, but the VDA ISA requires regular review of technical measures, not just one at assessment time. A rhythm that has proven itself in practice: a full pentest before the assessment, then a shorter test each year on the systems that have changed, such as new sites, new remote maintenance access or a rebuilt prototype area. That way the re-assessment holds no surprises, and you have an unbroken chain of evidence for the auditor instead of a three-year-old report.

Ready for your TISAX pentest?

In 30 minutes we discuss your TISAX scope, clarify the assessment level, and you receive a no-obligation fixed-price quote, free of charge and without commitment.