TISAX Levels Simplified: Differences, Preparations & Checklists
For automotive vendors, TISAX compliance is no longer optional — it’s a ticket to doing business in the competitive auto industry. This guide compares the three TISAX assessment levels to help you prepare for compliance. Also, get a free TISAX prep checklist.
TISAX levels explained
TISAX, or Trusted Information Security Assessment Exchange, has three assessment levels. Level 1 is a self-assessment mainly for internal purposes. Level 2 is a remote document audit, and Level 3 advances to an on-site audit. Only levels 2 and 3 result in a TISAX certificate, called a label.
The TISAX assessment levels match the sensitivity of information an organization handles, as defined by its TISAX assessment objectives and scope ID. Scope ID helps delineate the specific areas covered by the company’s information security management system (ISMS).
Also, take note that suppliers already certified for ISO 27001 have a head start. The German Association of the Automotive Industry (VDA) developed TISAX based on ISO 27001 but also included automotive-specific requirements.
TISAX Level 1 (AL 1)
TISAX Level 1, also called AL 1 for assessment level 1, is the entry point for organizations to establish information security. Level 1 relies on self-assessment and doesn’t result in a TISAX label. However, it does help prepare an organization for Level 2 or Level 3.
TISAX Level 2 (AL 2)
With TISAX Level 2, a third-party auditor remotely reviews your organization’s self-assessment and documentation and interviews you on a call. This is called a plausibility check. The required security controls remain the same across all three TISAX levels. However, Level 2 demands stronger enforcement, clearer evidence of compliance, and a more formalized approach to risk management.
TISAX Assessment Level 3 (AL 3)
TISAX Level 3 (AL 3) includes an on-site security audit for organizations managing highly sensitive information like prototypes, advanced development projects, and highly confidential business data.
TISAX Assessment Levels Table
| TISAX Assessment Level 2 vs. Level 3 | AL2 | AL3 |
| Assessment Type | Self-assessment with external plausibility check | Comprehensive external audit by a TISAX-approved auditor |
| Evidence Requirement | Limited documentation review | Extensive documentation review, including evidence collection |
| Site Visits | Not required (remote plausibility check is sufficient). | Mandatory on-site audits for in-depth verification. |
| Depth of Review | Evaluates existence of security measures. | Evaluates effectiveness, implementation, and sustainability of security measures. |
TISAX Elements Interconnection
TISAX has four main elements:
- TISAX assessment objectives: Define the scope of the evaluation.
- Assessment levels: Determine the audit's depth.
- Maturity levels: Reflect how well you manage security processes.
- TISAX labels: Represent compliance.
Preparing for TISAX Compliance
- Understand the TISAX requirements: Assess the sensitivity of the information you handle.
- Establish an information security management system (ISMS): Develop based on ISO 27001 standards.
- Enact information security controls: Implement controls specified in the VDA ISA catalog.
- Train your team: Ensure employees understand their roles regarding information security.
- Conduct internal audits: Evaluate ISMS effectiveness.
- Address gaps: Update security measures based on findings.
- Schedule a TISAX assessment: Hire a TISAX-approved auditor for remote reviews or on-site audits.
- Maintain and improve your ISMS: Continuously monitor and improve security processes.
FAQs on TISAX Levels
How do I determine which TISAX level applies to my organization?
Your TISAX level depends on audit requirements set by your business partners and the sensitivity of the information you handle.
Do all TISAX levels require an audit?
Only AL2 and AL3 require an external audit. AL1 is a self-assessment with no auditor validation.
What role does encryption play in meeting the higher TISAX levels?
Encryption is essential for AL2 and AL3 to protect confidential and highly sensitive data.