As a supplier or service provider in the automotive sector, you must demonstrate your information security to OEMs. Our TISAX pentest delivers the technical evidence required by the VDA ISA: structured and auditable, with a report ready within 5 working days.
The VDA ISA questionnaire is the assessment basis for all TISAX labels. Our report maps every finding directly to the relevant controls.
From a high protection need, the VDA ISA requires critical systems to be tested technically and names the penetration test as a suitable means. We deliver the practical pentest report to support your audit.
Dedicated TISAX labels for prototype protection and GDPR compliance require specific test scenarios, both physical and technical.
BMW, VW, Mercedes-Benz, Porsche, Audi, Bosch and Continental require TISAX from all Tier-1 and Tier-2 suppliers.
Our TISAX pentest report is designed as a technical evidence document for your approved TISAX audit provider and is ready for direct use in your assessment.
TISAX (Trusted Information Security Assessment Exchange) is the binding information security standard of the German automotive industry, developed by the VDA. It is based on ISO/IEC 27001 and the VDA ISA questionnaire and defines how suppliers must demonstrate the protection of sensitive information. Results are shared exclusively via the ENX platform, not made publicly accessible.
TISAX labels are valid for three years, after which a full recertification is required.
Results are shared exclusively via the closed ENX platform; there is no public certificate.
Required by manufacturers and Tier-1 suppliers such as BMW, VW, Mercedes-Benz, Porsche, Audi, Bosch and Continental – whether it applies to you is in your contract.
Five disclosure levels (A to E) on the ENX platform let you decide exactly how much detail a requesting partner can see about your assessment result.
| TISAX® | Criterion | ISO 27001 |
|---|---|---|
| Automotive | Industry focus | Cross-industry |
| VDA ISA + ISO 27001 | Framework basis | ISO 27001 |
| Label via ENX platform | Evidence type | Public certificate |
| ✓ From AL 2 | Technical review expected | — Optional |
| 3 years | Validity | 3 years (annual surveillance) |
TISAX distinguishes three protection requirement levels. Your OEM specifies which level you must meet. We conduct penetration tests for all three assessment levels.
Assessment Level 1
For organisations processing confidential information without particularly sensitive content. A qualified self-assessment without external review is sufficient, though this does not produce a TISAX label shareable on the ENX platform. A pentest is nonetheless recommended as additional voluntary evidence.
Assessment Level 2
For organisations handling highly sensitive information such as development data or vehicle concepts. An approved audit provider checks the self-assessment for plausibility using evidence and interviews, typically via web conference, not necessarily on-site. From this protection need onwards, the VDA ISA requires critical IT systems to be tested technically and names the penetration test as a suitable means.
Assessment Level 3
For organisations working with prototypes and strictly confidential data. An approved audit provider conducts a full on-site audit with document inspection and interviews, the highest level of scrutiny within TISAX.
| Criterion | Assessment Level 1 | Assessment Level 2 | Assessment Level 3 |
|---|---|---|---|
| Assessment method | Self-assessment (online questionnaire) | Plausibility check with evidence & interviews | Full audit with document inspection & interviews |
| Assessment location | No appointment required | Usually web conference (remote) | On-site at the organisation |
| Conducted by | No external review | Approved audit provider | Approved audit provider |
| TISAX label on ENX portal | ✗ Not issued | ✓ Yes | ✓ Yes |
| Typical protection need | Normal | High | Very high (e.g. strictly confidential, prototype protection) |
| Technical pentest | Recommended, voluntary | Expected in practice | Expected, extended scope |
Contrary to common assumption, there is no blanket "TISAX certified" status. Each organisation receives a specific label tied to a concrete assessment object (location, protection objective, and assessment level), which it shares selectively with requesting partners via the ENX platform rather than publishing it.
Confirms adequate protective measures for confidential information with a high protection need, such as development documentation. Typically demonstrated via Assessment Level 2.
The highest confidentiality tier, for strictly confidential information such as unreleased vehicle concepts. Issued exclusively via Assessment Level 3 with a full on-site audit.
Confirms that IT systems and processes meet defined recovery and continuity requirements for a high availability need.
Adds the highest availability tier: relevant where an outage would directly threaten the OEM's vehicle production.
Not a single label but several assessment objects: protection of components, test vehicles, presentation events, and confidentiality areas against unauthorised viewing or disclosure.
Confirms implementation of data processing requirements under GDPR Article 28 across two tiers, relevant when processing personal data on behalf of an OEM.
The VDA ISA questionnaire covers all security-relevant areas. Our pentest delivers the technical evidence for the following controls, ready for direct use with your ENX auditor.
Current status: VDA ISA version 6.0, mandatory since 1 April 2024 for newly commissioned assessments, adding controls for crisis management, IT service continuity, and backup & recovery, plus dedicated availability labels.
Evidence of a functioning ISMS: policies, roles, responsibilities, and awareness measures in line with VDA ISA Chapter 1.
Policy & governance reviewAccess control, building security, secure disposal of storage media, and protection of server rooms in line with VDA ISA Chapter 3.
Physical pentest & tailgatingNetwork segmentation, vulnerability management, patch management, access control, and logging in line with VDA ISA Chapter 4.
Infrastructure pentestSpecial protection for prototype vehicles and components: covers, camouflage, secure storage, transport, and access control to prototype areas. A standalone VDA ISA assessment module, not a chapter of the core questionnaire.
Prototype protection assessmentProcessing of personal data in the automotive context: consent, deletion concepts, and technical protective measures. A standalone VDA ISA assessment module for data processing under GDPR Article 28.
GDPR technical layer reviewSecurity requirements for service providers and sub-suppliers: contracts, audits, remote access, and security clauses in line with VDA ISA Chapter 7.
Supply chain risk assessmentTISAX becomes binding the moment a customer makes it a contractual condition – typically for organisations that process confidential information from OEMs or Tier-1 suppliers, regardless of company size or headcount.
We guide you from scope definition to an audit-ready report, on time and fully aligned with the VDA ISA questionnaire.
Joint definition of TISAX assessment objectives, assessment level, systems in scope, and timeline. Exclusion zones are documented as binding commitments.
OSINT, network analysis, physical building walkthrough, and system inventory in line with the VDA ISA assessment catalogue.
Infrastructure pentest, Active Directory analysis, physical security assessment, and social engineering in line with VDA ISA requirements.
All findings are mapped directly to the corresponding VDA ISA controls, for maximum auditability and minimum effort during the ENX audit.
Detailed pentest report with CVSS ratings, VDA ISA mapping, prioritised remediation recommendations, and an executive summary for senior management.
Illustrative example – no real customer data.
We combine physical, digital, and social engineering attack vectors into a single TISAX assessment from one provider, fully mapped to VDA ISA.
Access control, tailgating, lock bypass, camera blind spots, and prototype areas: we test whether your physical security holds up under TISAX AL 2 and AL 3 requirements.
Learn moreNetwork segmentation, patch status, Active Directory security, and remote access: technically verified and directly mapped to VDA ISA Chapter 4.
Learn morePhishing, vishing, and pretexting targeting your employees: we test the human firewall that VDA ISA Chapter 1 requires as a central protective measure.
Learn moreIn 30 minutes we discuss your TISAX scope, clarify the assessment level, and you receive a no-obligation fixed-price quote, free of charge and without commitment.