VDA ISA / ENX Association / ISA2027 from 1 January 2027

Get the TISAX Label Your OEM Demands. Prepared Against ISA2027.

Assessment Level 2 and 3 readiness, prepared against the ISA2027 catalogue and integrated with your ISO 27001 and NIS 2 obligations, so the ENX-approved provider you choose finds a mature system.

Readiness from EUR 11,000 per location. We prepare you; the approved provider assesses you. We will never blur that line.

ISA2027 from the startAL3 physical and plant controlsOne programme for TISAX and NIS 2
TISAX readiness consulting for automotive suppliers at Assessment Level 2 and 3 by Atlant Security
Alexander Sverdlov, founder of Atlant Security
Alexander SverdlovFounder, Atlant SecurityCISSP, CEH, CHFI, Mandiant

Runs the TISAX preparation and tells you which assessment level you actually need.

Connect on LinkedIn

Why Suppliers Come to Us for TISAX

An OEM purchasing contract now requires a TISAX label

BMW, the VW Group, Mercedes-Benz, Audi and their Tier 1 suppliers push TISAX down the chain as a purchasing gate. Without a label at the right assessment level for the right location, the sourcing conversation stops. More than 20,000 sites across 90 countries have already been assessed.

ISA2027 changes the catalogue you are being assessed against

The ENX Association published ISA2027 in July 2026 and it becomes mandatory for every assessment ordered from 1 January 2027, with an annual catalogue cycle after that. Preparing against the retiring VDA ISA 6 catalogue is the most expensive mistake available this year.

Your ISO 27001 certificate does not get you the label

TISAX shares most of its control logic with ISO 27001, and roughly 80 percent of the effort overlaps if you have a working ISMS. But the assessment is separate, per location, at a defined level, by an ENX-approved provider. A certificate is a head start, not a substitute.

TISAX is assessed per location, not per companyParticipant companyRegistered once on the ENX portalLocation in scopeEach site assessed and labelled separatelyAssessment level and modulesAL2 or AL3, plus prototype or data protection where requiredA label covers the site and scope it was issued for. Additional sites need their own assessment.
Multi-site groups are priced per location, in writing, before work starts.
The catalogue change that decides your projectJul 2026ISA2027 publishedENX releases the newcatalogueNowBoth in useAssessments ordered in2026 may still use VDA ISA1 Jan 2027ISA2027 mandatoryEvery assessment orderedfrom this dateAnnualYearly catalogue cycleA new version each yearafter
Preparing against the retiring catalogue is the most expensive mistake available this year.

Assessment Levels, Modules and Scope

Your customer defines the protection needs, the protection needs define the level, and the level defines how deep the assessment goes and whether it comes on site. Getting the target wrong at scoping is the second most expensive mistake after preparing against the wrong catalogue.

Assessment Level 1
Self-assessment only. Rarely accepted by OEMs for real data exchange.
Assessment Level 2
Normal protection needs. Plausibility check of the self-assessment, usually remote.
Assessment Level 3
High and very high protection needs. On-site assessment including physical security.
Prototype protection
Additional module for suppliers handling vehicles, parts or components under embargo.
Data protection
Additional module covering GDPR-relevant processing on behalf of the OEM.
Label scope
Labels are issued per location and exchanged through the ENX portal, valid for three years.
Assessment levels and modulesLEVELPROTECTION NEEDHOW IT IS ASSESSEDAL 1LowSelf-assessment only, rarely accepted byOEMsAL 2NormalPlausibility check of theself-assessment, usually remoteAL 3High and very highOn-site assessment including physicalsecurityPrototypeVehicles and parts under embargoAdditional module, on siteData protectionGDPR processing for the OEMAdditional module
Your OEM or Tier 1 customer specifies the protection need, which sets the level.
Who is asked for a TISAX labelParts and assembly suppliersTier 1 to Tier 3 in the production chainEngineering and test servicesDesign, simulation, validation providersSoftware and cloud providersAnyone connected to OEM systems or dataPrototype and tooling partnersLogistics, tooling, contract manufacturing
More than 20,000 sites across 90 countries have been assessed.
What we do, and what only ENX providers can doAtlant Security: readinessScoping against your actual OEM requirementFull VDA ISA gap analysis mapped to your ISMSRemediation in the order the assessment examines itAL3 physical and prototype work on siteMock assessment and hand-off supportOnly an ENX-approved providerPerforming the official assessmentIssuing the TISAX labelGranting an exception or a passPublishing your result on the ENX portal
We are independent of the audit providers and help you select one. Any consultancy implying it can issue a label should be avoided.

What We Do, and What Only an Approved Provider Can Do

We run the gap analysis, align the work with your ISMS, remediate with your team, build the evidence file and run a mock assessment. That is readiness, and it is where labels are won or lost.

The assessment itself is performed, and the label issued, only by the audit providers approved by ENX. There are seventeen of them. We are not one, we are independent of all of them, and we will help you choose.

We put this on the first screen because the consultancies that blur it are the ones whose clients discover the difference on assessment day.

Who Needs a TISAX Label?

Tier 1 to Tier 3 parts, component and assembly suppliers
Engineering, design, simulation and test service providers
Software, cloud and IT providers connected to OEM systems or data
Prototype logistics, tooling and contract manufacturing partners
One programme, two obligationsShared control baseAround 80 percent overlaps with a working ISO 27001 ISMSTISAX-specificAutomotive controls, per-site scoping, prototype protectionNIS 2-specificIncident reporting to the national authority, board trainingENX, July 2025: TISAX covers all NIS 2 risk-management requirements.
Manufacturers in scope of NIS 2 should run one programme, not two.

Compared With Typical TISAX Consultancies

Atlant SecurityTypical consultancy
Honesty about the labelWe prepare you. Only the ENX-approved audit providers assess and issue labels, and we say so on page onePass guarantees and blurred lines about who issues what
Physical and OT controlsAL3 physical security, prototype areas and plant networks assessed by someone with critical-infrastructure fieldwork behind themOffice IT consultants who have never walked a plant
NIS 2 overlapOne programme designed to satisfy TISAX and the NIS 2 risk-management requirements togetherTwo parallel projects, two evidence files
CataloguePrepared against ISA2027 from the startStill selling VDA ISA 6 readiness
PricingPublished, fixed, per locationQuote after the free consultation

Readiness in Four Phases

1

Scoping

Locations in scope, protection needs from your OEM requirements, target assessment level, and which additional modules apply. Registration on the ENX portal if you are not yet a participant.

2

Gap analysis

Every VDA ISA control assessed against your current state, mapped to your ISO 27001 ISMS where you have one so nothing is built twice. Physical security and prototype handling assessed on site where AL3 applies.

3

Remediation

Policies, technical hardening, physical controls, supplier management and the evidence file, in the order the assessment will examine them. Your team does the work with us, so the maturity is real.

4

Mock assessment and hand-off

A dry run against the target level, then hand-off to the ENX-approved audit provider you choose. We support you during the assessment and through any corrective action plan.

How TISAX readiness runs1ScopingLocations, protection needs,target level, modules, ENXregistration2Gap analysisEvery VDA ISA control againstcurrent state, mapped to yourISMS3RemediationPolicies, hardening, physicalcontrols, evidence file, withyour team4Mock and hand-offDry run at the target level,then support through the realassessment
Three to five months for a single location with an existing ISMS; longer from a standing start or for AL3.

TISAX Readiness Pricing

Published and fixed per location. The approved provider charges its assessment fee separately; we tell you what to expect there too, because nobody else does.

Assessment Level 2 Readiness

Normal protection needs, one location, remote assessment by the provider.

From EUR 11,000per location
  • Scoping and ENX portal registration support
  • Gap analysis against ISA2027, mapped to your ISMS
  • Remediation plan and evidence file
  • Policy and technical control build with your team
  • Mock assessment before hand-off
Get Your Fixed Price
Most OEM contracts

Assessment Level 3 Readiness

High and very high protection needs, on-site assessment, physical and prototype controls.

From EUR 20,000per location
  • Everything in AL2 readiness
  • On-site physical security and prototype area assessment
  • Plant and OT network segmentation review
  • Prototype and data protection modules
  • On-site mock assessment
  • Support during the assessment and corrective action plan
Get Your Fixed Price

Multi-location groups are priced per site in writing before we start. You review each deliverable before you pay.

Prepare Against ISA2027, Not the Catalogue Being Retired

One scoping call to confirm level, modules and locations from your actual OEM requirements, then a fixed-price plan in writing.

Book Your TISAX Scoping Call

Get Your TISAX Scope and Price

TISAX FAQ

What is TISAX?
TISAX, the Trusted Information Security Assessment Exchange, is the automotive industry scheme for assessing and sharing information security assessment results. It is governed by the ENX Association on behalf of the VDA, based on the VDA ISA catalogue. Suppliers are assessed once by an approved provider and share the resulting label with any participating OEM or customer through the ENX portal instead of undergoing separate customer audits.
Can Atlant Security issue a TISAX label?
No, and any consultancy that implies it can should be avoided. Assessments are performed and labels issued only by the audit providers approved by ENX, currently seventeen organisations. Our role is readiness: closing the gaps, building the evidence and running a mock assessment so that the approved provider you choose finds a mature system. We are independent of the audit providers and will help you select one.
What is ISA2027 and when does it apply?
ISA2027 is the next version of the VDA ISA catalogue, published by ENX in July 2026. It applies to all assessments ordered from 1 January 2027 and introduces an annual catalogue cycle. If your assessment will be ordered in 2027 or later, prepare against ISA2027 now.
Which assessment level do we need?
Your OEM or Tier 1 customer specifies the protection needs, which determine the level. Normal protection needs map to Assessment Level 2, high and very high to Assessment Level 3, which includes an on-site assessment. Prototype protection and data protection are additional modules some customers require. We confirm the target during scoping from your actual contract requirements.
We already hold ISO 27001. How much does that help?
Substantially. TISAX shares most of its control logic with ISO 27001 and a working ISMS typically covers around 80 percent of the effort. The remaining work is the automotive-specific controls, per-location scoping, physical and prototype requirements at AL3, and the evidence format the assessment expects. We map your existing ISMS so nothing is built twice.
Does TISAX cover NIS 2?
Largely. An ENX expert analysis published in July 2025 concluded that TISAX addresses all NIS 2 risk-management requirements, with only the national incident reporting obligations outside its scope. Manufacturers in scope of NIS 2 can therefore run one programme, and we design it that way.
What does readiness cost?
Assessment Level 2 readiness for a single location starts at EUR 11,000 fixed. Assessment Level 3 readiness, including on-site physical and prototype work, starts at EUR 20,000. The approved provider charges its own assessment fee separately, typically a few thousand euros for AL2 and roughly nine to twelve thousand for AL3. Multi-location programmes are priced per site in writing before we start.
How long does it take?
Three to five months for a single location with an existing ISMS, longer from a standing start or for AL3 with significant physical remediation. The binding constraint is usually your own remediation capacity, which is why we sequence the work in the order the assessment examines it.
We supply a North American OEM that asks about TPISR. Is that different?
AIAG TPISR is the older North American third-party information security requirement, referenced in GM supplier standard GMW18075. It is a self-assessment questionnaire, not a certification, and any organisation that is TISAX-ready can answer it. We cover it inside the TISAX engagement rather than as a separate service.

Related Services