The ultimate TISAX® Guide
Everything automotive suppliers need to get the TISAX® label

The practical TISAX® guide for automotive suppliers
We pulled lessons from European businesses that went through TISAX® assessments at Levels 1, 2, and 3, and turned their experience into a guide you can actually use.
How to successfully get a TISAX® label
The exact timeline from kick-off to label
How much TISAX® really costs

Everything you need to get the TISAX® label
Skip the guesswork. This guide walks you through exactly what ENX auditors check, how to prepare for it, and how to avoid the mistakes that trigger follow-up audits.
Based on real TISAX® assessments
Written for non-security managers
Covers AL 1, AL 2 and AL 3 assessment levels
Covers what ENX auditors specifically look for
Enter your details to download
FAQs
What is TISAX®?
TISAX® (Trusted Information Security Assessment Exchange) is an information security standard developed by the German automotive industry. It proves your business protects sensitive data and is often required to work with manufacturers like Audi, BMW, and Volkswagen.
How long does it take to get TISAX® certified?
With Secfix, preparation typically takes 1–3 months, significantly faster than the 12–18 months needed with traditional consultant-led approaches. After the initial document audit, the full TISAX® assessment must be completed within 9 months.
How much does TISAX® certification cost for an SMB?
For a company with 10–100 employees, expect €10,000–€30,000 with the automation-led approach versus €80,000–€150,000 annually with consultants. Add a ~€500 ENX registration fee per site and €5,000–€10,000 for the initial audit.
Is TISAX® mandatory?
TISAX® is not legally mandatory, but the major automotive manufacturers require it before working with suppliers. If you want to win or keep business with OEMs like Audi, BMW, or Volkswagen, you'll need to get certified.
What are the three TISAX® assessment levels?
AL 1 is a self-assessment for low-sensitivity data. AL 2 adds an independent auditor review and is used for highly sensitive information. AL 3 is for the most sensitive data and includes an on-site audit with direct team interviews.
How long is a TISAX® label valid?
A TISAX® label is valid for 3 years. However, maintaining certification requires ongoing investment in security, annual risk assessments, regular access reviews, yearly security awareness training, and continuous evidence collection for your next audit.
Do I need ISO 27001 before getting TISAX®?
No, ISO 27001 is not a prerequisite. But if you already have it, you're in luck! Both standards cover a lot of the same ground, so you've already done much of the groundwork. Auditors also recognize the effort behind ISO 27001, which can make your TISAX® assessment go more smoothly.
What customers say about Secfix
Get the TISAX guide
Free PDF. No call required. Everything you need to plan your TISAX assessment






