背景半波浪
Application Security

What is TISAX compliance?

Last updated: September 14, 2026

What is TISAX compliance?

TISAX represents the automotive industry's standardized approach to information security assessment and credential sharing. Developed by the German automotive association VDA and managed by the ENX Association, TISAX allows organizations to be "assessed once, recognized by many" across the complex automotive supply chain. Rather than undergoing separate security evaluations for each OEM or partner, suppliers can complete a single TISAX assessment and share their security labels through the ENX portal with authorized partners.

At its core, TISAX operates on the Information Security Assessment (ISA) catalog, with Version 6 becoming effective for new assessments as of April 2024. Organizations complete assessments at different levels: AL1 for self-assessment, AL2 for plausibility checks with a remote assessment option (AL2.5), and AL3 for comprehensive on-site verification. The resulting TISAX labels, valid for three years, demonstrate compliance with specific security objectives ranging from confidential data handling to prototype protection and high availability requirements. With over 20,000 locations worldwide holding valid TISAX labels as of December 2025, this framework has become essential infrastructure for automotive data governance.

For data engineers and analytics teams, TISAX creates both opportunities and constraints. While it simplifies partner onboarding by standardizing security expectations, it also demands sophisticated approaches to data classification, access control, incident detection, and evidence retention. The challenge lies in implementing technical controls that satisfy TISAX requirements while maintaining the agility and performance modern data pipelines require.

Why automotive organizations prioritize TISAX compliance

The automotive industry's shift toward connected vehicles, autonomous systems, and digital manufacturing has created unprecedented data sharing requirements across multi-tier supply chains. Traditional point-to-point security assessments between partners proved unsustainable as OEMs began working with hundreds of suppliers, each requiring separate security validations for prototype data, production systems, and confidential intellectual property.

TISAX addresses this complexity by creating a common security language. When BMW, Volkswagen, or Mercedes-Benz requires suppliers to handle confidential R&D data, they can specify TISAX labels rather than conducting separate audits. For example, Daimler Truck now requires AL3 assessment for production material suppliers beginning in 2025, creating clear expectations that extend across their entire supply network.

Cloud and SaaS provider adoption drives ecosystem value

Major technology providers recognize TISAX as a competitive requirement for automotive market access. Google Cloud maintains TISAX labels for Strictly Confidential and Very High Availability across assessed regions, while Atlassian provides AL2 certification for development collaboration tools. This ecosystem adoption means data engineers can leverage proven cloud services while meeting partner security requirements.

The framework particularly benefits organizations handling prototype vehicles, test data, and manufacturing systems. ISA 6 strengthens requirements around IT/OT availability and maps to IEC 62443 standards for industrial automation, addressing the convergence of traditional manufacturing with cloud-native analytics platforms. Teams building telemetry pipelines for connected vehicle programs or factory optimization initiatives find TISAX provides clear security expectations for these hybrid environments.

Common hurdles in TISAX implementation

Despite its standardization benefits, TISAX implementation presents significant operational challenges that data engineering teams must navigate carefully. The complexity stems from evolving requirements, fragmented partner expectations, and the technical reality of modern data architectures.

Managing evolving requirements and partner-specific mandates

ISA 6 introduced substantial changes that affect how teams design monitoring and incident response capabilities. New controls around event reporting, incident handling, and crisis management require mature logging infrastructure and coordinated response workflows. The framework also added requirements for service continuity and backup/recovery that impact how analytics platforms maintain availability during disruptions.

Different OEMs often prescribe specific labels and assessment levels beyond the standard framework. While TISAX aims to reduce duplicate audits, organizations frequently discover that Partner A requires AL2 for prototype data while Partner B mandates AL3 for similar scenarios. These variations create complex compliance matrices that data teams must track alongside technical implementation details.

Scope design challenges across distributed operations

TISAX mandates predefined "standard scope" definitions that differ from ISO 27001 approaches familiar to many security teams. Organizations with multiple development centers, manufacturing facilities, or cloud regions must decide whether to combine locations under unified scopes or pursue separate assessments. Multi-site scopes create dependencies where delays at one location affect the entire assessment timeline, while separate scopes multiply audit overhead and create inconsistent security postures across the organization.

Evidence management in cloud-native environments

The shift toward microservices, containers, and serverless architectures complicates evidence collection for TISAX assessments. Traditional security documentation assumes stable infrastructure and clear network boundaries, but modern data pipelines span multiple cloud services, auto-scaling container clusters, and ephemeral compute resources.

AL2 and AL3 assessments require comprehensive documentation of security controls, yet many organizations struggle to map dynamic cloud configurations to static audit evidence. Teams need continuous monitoring and automated documentation capabilities that capture security posture across rapidly changing infrastructure while maintaining the detailed records assessors expect.

Getting started with tisax for data teams

Successfully implementing TISAX requires strategic planning that balances immediate compliance needs with long-term operational sustainability. The key lies in building security capabilities that satisfy assessment requirements while enhancing rather than hindering data pipeline performance and reliability.

Start with centralized observability and incident response

Begin by implementing comprehensive telemetry collection that supports both operational needs and TISAX evidence requirements. Centralizing metrics, logs, and traces through OpenTelemetry into platforms like the Dynatrace Grail data lakehouse provides the foundation for both real-time monitoring and historical analysis required during assessments.

Focus on the ISA 6 emphasis on detection and response capabilities. Configure Runtime Application Protection to detect and block common exploit attempts like SQL injection and command injection, generating high-fidelity security events that demonstrate proactive threat detection. Integrate monitoring platforms with Microsoft Sentinel for SIEM capabilities and ServiceNow for incident management, creating unified workflows that incident handling requirements while supporting day-to-day operations.

Design for continuous compliance rather than point-in-time audits

Structure security controls to operate continuously rather than activating only during assessment periods. Implement data masking at capture through OneAgent or at ingest to reduce exposure of personally identifiable information and confidential data in operational logs. This approach protects sensitive information while ensuring observability systems remain effective for troubleshooting and performance optimization.

Configure record-level permissions and bucket-level access controls in data platforms, backed by SSO integration and SCIM provisioning for automated user management. Maintain comprehensive audit logs at both environment and account levels, creating traceable access patterns that demonstrate least-privilege principles throughout the data lifecycle.

Align availability monitoring with ISA 6 service continuity requirements

ISA 6 strengthens availability requirements, making service-level objectives and site reliability engineering practices central to TISAX compliance. Implement SLOs and Site Reliability Guardian to demonstrate measurable availability tracking for production-relevant systems. These capabilities support both operational excellence and evidence of service continuity planning required for higher assessment levels.

Consider how factory systems and operational technology integrate with analytics platforms. The ISA 6 mapping to IEC 62443 creates opportunities to coordinate IT and OT security controls, particularly around backup and recovery procedures that span traditional manufacturing systems and cloud-based analytics infrastructure.

Plan scope and assessment level strategically

Choose the ENX "standard scope" for maximum partner recognition unless specific technical requirements demand customization. Standard scope receives universal acceptance across TISAX participants and significantly simplifies the assessment process for most organizations.

Map partner requirements early in the planning process to understand which labels and assessment levels your organization needs. Different OEMs may require varying combinations of confidentiality, availability, and data protection labels, each potentially demanding different assessment levels. Document these requirements alongside technical architecture decisions to ensure implementation choices support business objectives.

Prepare evidence infrastructure for long-term sustainability

Develop living documentation that maps ISA controls to specific technical implementations, monitoring dashboards, and operational procedures. For Dynatrace users, this includes documenting DQL queries for incident analysis, SLO configurations for availability tracking, data masking policies, access control configurations, and integration points with external systems. This documentation serves dual purposes: supporting operational teams during incident response and providing clear evidence during TISAX assessments.

Plan for three-year label validity cycles by building renewal considerations into architecture decisions. Changes in cloud providers, monitoring platforms, or data pipeline architectures during the label validity period should maintain rather than compromise TISAX compliance posture. Consider how emerging requirements, such as the January 2025 changes to test vehicle and prototype event defaults, might affect future assessments and build flexibility into technical implementations accordingly.

Implement credential management through secure vaults and maintain encrypted data handling across transit and rest scenarios. These foundational security practices support multiple TISAX objectives while establishing security hygiene that benefits broader organizational objectives beyond automotive partnerships. and maintain encrypted data handling across transit and rest scenarios. These foundational security practices support multiple TISAX objectives while establishing security hygiene that benefits broader organizational objectives beyond automotive partnerships.

Success with TISAX ultimately depends on treating it as a framework for operational security excellence rather than a compliance checklist. Organizations that accelerate this journey share a common advantage: a unified platform that brings observability and security together with full dependency mapping, data in context, and AI-powered automation. When your monitoring, incident detection, access controls, and evidence collection operate from a single data model with AI that understands the relationships between services, infrastructure, and business impact, TISAX requirements become a natural byproduct of how your systems run, not a separate audit exercise. Teams that build on this foundation find assessments validate existing capabilities rather than expose gaps, turning a complex compliance mandate into a competitive differentiator across the automotive supply chain