VDA ISA / ENX Association / ISA2027 from 1 January 2027

TISAX Readiness Consulting for Automotive Suppliers

Assessment Level 2 and 3 readiness, prepared against the ISA2027 catalogue and integrated with your ISO 27001 and NIS 2 obligations, so the ENX-approved provider you choose finds a mature system.

Readiness from $12,000 per location. We prepare you; the approved provider assesses you. We will never blur that line.

ISA2027 from the startAL3 physical and plant controlsOne programme for TISAX and NIS 2
TISAX readiness consulting for automotive suppliers at Assessment Level 2 and 3 by Atlant Security

Why Suppliers Come to Us for TISAX

An OEM purchasing contract now requires a TISAX label

BMW, the VW Group, Mercedes-Benz, Audi and their Tier 1 suppliers push TISAX down the chain as a purchasing gate. Without a label at the right assessment level for the right location, the sourcing conversation stops. More than 20,000 sites across 90 countries have already been assessed.

ISA2027 changes the catalogue you are being assessed against

The ENX Association published ISA2027 in July 2026 and it becomes mandatory for every assessment ordered from 1 January 2027, with an annual catalogue cycle after that. Preparing against the retiring VDA ISA 6 catalogue is the most expensive mistake available this year.

Your ISO 27001 certificate does not get you the label

TISAX shares most of its control logic with ISO 27001, and roughly 80 percent of the effort overlaps if you have a working ISMS. But the assessment is separate, per location, at a defined level, by an ENX-approved provider. A certificate is a head start, not a substitute.

More than 20,000 sites assessed under TISAX across 90 countries
ISA2027 becomes mandatory for TISAX assessments ordered from 1 January 2027

Assessment Levels, Modules and Scope

Your customer defines the protection needs, the protection needs define the level, and the level defines how deep the assessment goes and whether it comes on site. Getting the target wrong at scoping is the second most expensive mistake after preparing against the wrong catalogue.

Assessment Level 1
Self-assessment only. Rarely accepted by OEMs for real data exchange.
Assessment Level 2
Normal protection needs. Plausibility check of the self-assessment, usually remote.
Assessment Level 3
High and very high protection needs. On-site assessment including physical security.
Prototype protection
Additional module for suppliers handling vehicles, parts or components under embargo.
Data protection
Additional module covering GDPR-relevant processing on behalf of the OEM.
Label scope
Labels are issued per location and exchanged through the ENX portal, valid for three years.
TISAX assessment levels AL1, AL2 and AL3 and additional modules explained
Which automotive suppliers OEMs require TISAX labels from
What a TISAX readiness consultant can and cannot do: only ENX-approved providers issue labels

What We Do, and What Only an Approved Provider Can Do

We run the gap analysis, align the work with your ISMS, remediate with your team, build the evidence file and run a mock assessment. That is readiness, and it is where labels are won or lost.

The assessment itself is performed, and the label issued, only by the audit providers approved by ENX. There are seventeen of them. We are not one, we are independent of all of them, and we will help you choose.

We put this on the first screen because the consultancies that blur it are the ones whose clients discover the difference on assessment day.

Who Needs a TISAX Label?

Tier 1 to Tier 3 parts, component and assembly suppliers
Engineering, design, simulation and test service providers
Software, cloud and IT providers connected to OEM systems or data
Prototype logistics, tooling and contract manufacturing partners
Why TISAX and NIS 2 belong in one programme for manufacturers

Compared With Typical TISAX Consultancies

Atlant SecurityTypical consultancy
Honesty about the labelWe prepare you. Only the ENX-approved audit providers assess and issue labels, and we say so on page onePass guarantees and blurred lines about who issues what
Physical and OT controlsAL3 physical security, prototype areas and plant networks assessed by someone with critical-infrastructure fieldwork behind themOffice IT consultants who have never walked a plant
NIS 2 overlapOne programme designed to satisfy TISAX and the NIS 2 risk-management requirements togetherTwo parallel projects, two evidence files
CataloguePrepared against ISA2027 from the startStill selling VDA ISA 6 readiness
PricingPublished, fixed, per locationQuote after the free consultation

Readiness in Four Phases

1

Scoping

Locations in scope, protection needs from your OEM requirements, target assessment level, and which additional modules apply. Registration on the ENX portal if you are not yet a participant.

2

Gap analysis

Every VDA ISA control assessed against your current state, mapped to your ISO 27001 ISMS where you have one so nothing is built twice. Physical security and prototype handling assessed on site where AL3 applies.

3

Remediation

Policies, technical hardening, physical controls, supplier management and the evidence file, in the order the assessment will examine them. Your team does the work with us, so the maturity is real.

4

Mock assessment and hand-off

A dry run against the target level, then hand-off to the ENX-approved audit provider you choose. We support you during the assessment and through any corrective action plan.

TISAX readiness in four phases from scoping to mock assessment

TISAX Readiness Pricing

Published and fixed per location. The approved provider charges its assessment fee separately; we tell you what to expect there too, because nobody else does.

Assessment Level 2 Readiness

Normal protection needs, one location, remote assessment by the provider.

From $12,000per location
  • Scoping and ENX portal registration support
  • Gap analysis against ISA2027, mapped to your ISMS
  • Remediation plan and evidence file
  • Policy and technical control build with your team
  • Mock assessment before hand-off
Book Free Scoping Call
Most OEM contracts

Assessment Level 3 Readiness

High and very high protection needs, on-site assessment, physical and prototype controls.

From $22,000per location
  • Everything in AL2 readiness
  • On-site physical security and prototype area assessment
  • Plant and OT network segmentation review
  • Prototype and data protection modules
  • On-site mock assessment
  • Support during the assessment and corrective action plan
Book Free Scoping Call

Multi-location groups are priced per site in writing before we start. You review each deliverable before you pay.

Prepare Against ISA2027, Not the Catalogue Being Retired

One scoping call to confirm level, modules and locations from your actual OEM requirements, then a fixed-price plan in writing.

Book Your TISAX Scoping Call

Schedule Your Free TISAX Scoping Call

TISAX FAQ

What is TISAX?
TISAX, the Trusted Information Security Assessment Exchange, is the automotive industry scheme for assessing and sharing information security assessment results. It is governed by the ENX Association on behalf of the VDA, based on the VDA ISA catalogue. Suppliers are assessed once by an approved provider and share the resulting label with any participating OEM or customer through the ENX portal instead of undergoing separate customer audits.
Can Atlant Security issue a TISAX label?
No, and any consultancy that implies it can should be avoided. Assessments are performed and labels issued only by the audit providers approved by ENX, currently seventeen organisations. Our role is readiness: closing the gaps, building the evidence and running a mock assessment so that the approved provider you choose finds a mature system. We are independent of the audit providers and will help you select one.
What is ISA2027 and when does it apply?
ISA2027 is the next version of the VDA ISA catalogue, published by ENX in July 2026. It applies to all assessments ordered from 1 January 2027 and introduces an annual catalogue cycle. If your assessment will be ordered in 2027 or later, prepare against ISA2027 now.
Which assessment level do we need?
Your OEM or Tier 1 customer specifies the protection needs, which determine the level. Normal protection needs map to Assessment Level 2, high and very high to Assessment Level 3, which includes an on-site assessment. Prototype protection and data protection are additional modules some customers require. We confirm the target during scoping from your actual contract requirements.
We already hold ISO 27001. How much does that help?
Substantially. TISAX shares most of its control logic with ISO 27001 and a working ISMS typically covers around 80 percent of the effort. The remaining work is the automotive-specific controls, per-location scoping, physical and prototype requirements at AL3, and the evidence format the assessment expects. We map your existing ISMS so nothing is built twice.
Does TISAX cover NIS 2?
Largely. An ENX expert analysis published in July 2025 concluded that TISAX addresses all NIS 2 risk-management requirements, with only the national incident reporting obligations outside its scope. Manufacturers in scope of NIS 2 can therefore run one programme, and we design it that way.
What does readiness cost?
Assessment Level 2 readiness for a single location starts at $12,000 fixed. Assessment Level 3 readiness, including on-site physical and prototype work, starts at $22,000. The approved provider charges its own assessment fee separately, typically a few thousand euros for AL2 and roughly nine to twelve thousand for AL3. Multi-location programmes are priced per site in writing before we start.
How long does it take?
Three to five months for a single location with an existing ISMS, longer from a standing start or for AL3 with significant physical remediation. The binding constraint is usually your own remediation capacity, which is why we sequence the work in the order the assessment examines it.
We supply a North American OEM that asks about TPISR. Is that different?
AIAG TPISR is the older North American third-party information security requirement, referenced in GM supplier standard GMW18075. It is a self-assessment questionnaire, not a certification, and any organisation that is TISAX-ready can answer it. We cover it inside the TISAX engagement rather than as a separate service.

Related Services