NormX_Logo_Wide_White TISAX ISO 27001 B3S-Sicherheitsstandard

On the fast track to TISAX® assessment

Innovative. Automated. Flexible. Qualified.

On the fast track to TISAX® assessment

Innovative. Automated. Flexible. Qualified.


Are you a supplier or service provider to the automotive industry? To secure your future business opportunities, you should urgently acquire a so-called TISAX® certification* by 2023. This is a recognized certification of your information security standards. Often the TISAX® certification involves many months and high costs, which is why we have developed our “Norm X” software solution!

NORM X guides your company to the TISAX® assessment with the help of automated processes, checklists and instructions. If you have any questions, an ISEGRIM X Information Security Officer (IX ISO) from our company is also available to support you on your way.

TISAX® (Trusted Information Security Assessment Exchange). It enables your company in the automotive industry to share your information security assessment results with other participants or potential business partners of the industry.

If you are a service provider or supplier in the automotive industry, you will be asked by your business partners to provide your information security audit results of the TISAX® Audit. If you do not have a TISAX® certification and are not yet on the path to the assessment, your business partners will no longer consider you as a potential supplier. So, completing the TISAX® Assessment is essential for your company to continue to be successful in the automotive industry.


We offer two solutions for TISAX®:



Many SMEs need support in obtaining the TISAX® label, but cannot afford to hire classic consulting companies… Because the certification process is expensive, complex, lengthy and unpredictable!

With our NORM X solution you get the fast and efficient way to your TISAX® assessment. With our expertise of over 40 years and our IX Certification Engine, NORM X takes you on the fast track to reach your goal: TISAX®.

Icon Handschlag Partner

An individual IX ISO at your side throughout the entire process

Icon Zeiteinsparung

Time & cost savings on the way to certification

Icon Optimierung

Automated & optimized processes based on artificial intelligence


Vorschaubild TISAX Infoflyer Download
Preview image, please fill out form.


We summarized key facts about our solution for you in a document. You can easily request this document by e-mail.


You would like to benefit from our solutions or have open questions? We are at your disposal.


What is TISAX® and why is it important?

TISAX® stands for Trusted Information Security Assessment Exchange and is a registered trademark of the ENX Association. It is a security standard for the automotive industry – originally initiated by the German Association of the Automotive Industry (VDA) – which is intended to help increase information security in the industry. TISAX® thus serves to review and certify the information security of companies. After successfully passing the audit, companies receive a TISAX® label, which strengthens the trust of customers and partners and can serve as a competitive advantage.

Who needs a TISAX® certification?

Currently, there is no legal requirement for TISAX® certification. However, there is an unofficial obligation to obtain the label in order to be / remain competitive in the industry. Many OEMs now require a TISAX® label for cooperation with suppliers or partners. If you are a supplier, partner or manufacturer in the automotive industry, it is therefore advisable to obtain certification in order to increase your business opportunities.

How much does the TISAX® certification cost?

The more complex the requirements (assessment level 1 to 3 possible), the higher the costs tend to be. Various factors must be taken into account in order to determine the specific costs: Which assessment level according to TISAX® are you aiming for? Do you already have an ISMS established and is it already ISO 27001 certified? Etc.

What TISAX® assessment levels do exist?

The level 1 assessment is a self-assessment that is not audited by a service provider. It is therefore mostly only used for internal purposes. These assessment results are only of limited validity and do not constitute a valid TISAX® label. Most manufacturers therefore require at least Assessment Level 2.

In this case, the self-assessment is audited by an accredited auditor. These assessments are often carried out by telephone. An on-site test is only conducted if you have the “prototype protection” module tested or explicitly request an on-site test.

At Level 3, a comprehensive on-site audit of your self-assessment is carried out by an auditor. This takes 2-3 days on average.

How do I obtain a TISAX® label?

Once you have successfully completed the Level 2 or 3 assessment, you will receive a label summarizing your exam results. The label, together with the information about your assessment, can then be viewed in the ENX portal for authorized participants. In return, you can of course also view the TISAX® labels and results of other participants.

For how long is the TISAX® label valid?

Once you have received your label, it is valid for 3 years. It must then be renewed. The costs for renewal are usually lower than for initial certification because you already have experience and certain established information security processes.

How long does it take to prepare for the TISAX® audit?

The duration of the assessments can vary significantly and depends on various factors, such as the size of your company and the number of company locations. If the company is of average size, 2-3 days on site are sufficient for the assessment procedure itself. What may take more time, however, is the preparation for the assessment. The assessment or audit should only be carried out if you fulfill the TISAX® requirements from the VDA-ISA questionnaire. Otherwise, you will not pass the audit and will not receive a label. There is a risk that you will have to undergo a follow-up audit, which in turn involves additional costs.

The preparation and examination process can take up to 8 – 12 months. The examination process itself must not take longer than 9 months from registration, otherwise you will not receive a label. Therefore, sufficient preparation for the assessment is crucial!

Is ISO 27001 relevant for the TISAX® Assessment?

An already implemented and certified ISMS (information security management system) in compliance with the ISO 27001 standard is not a prerequisite for the TISAX® assessment. For the assessment, you only need to prove that you work with an information security management system and that the corresponding processes and procedures are implemented in the company. However, an existing ISO 27001 certification will provide you with a solid groundwork for the TISAX® certification.


Our scalable NORM X solution guides your company to the TISAX® assessment with the help of an information security officer from our company, automated processes, checklists and instructions. We tailor the service specifically to the needs of your company. In doing so, we enable up to 50% TCO and time savings.

TISAX® is a registered trademark of the ENX ASSOCIATION. ISEGRIM X has no economic relationship with ENX. Mentioning the TISAX® trademark does not imply any statement by the ENX Association as to the suitability of the services advertised herein.