Skip to main content
Framework library
Framework module · tisax-isa-6

TISAX

The ENX-governed assessment and exchange mechanism for automotive information security, based on the VDA Information Security Assessment catalog. A TISAX label is scope- and site-specific; it is not an ISO certificate or a company-wide platform claim.

ISA 6.0.3 · ENX Association · published 2024-04-25

Standing today
Directory entry

00Answer

from the registry record
What is TISAX?
The ENX-governed assessment and exchange mechanism for automotive information security, based on the VDA Information Security Assessment catalog. A TISAX label is scope- and site-specific; it is not an ISO certificate or a company-wide platform claim.
Who does TISAX apply to?
TISAX applies to automotive, manufacturing, supply chain, EU, global, per ENX Association.
What is the current version of TISAX?
The current edition is ISA 6.0.3, issued by ENX Association and published 2024-04-25. Source: https://www.enx.com/en-US/TISAX/downloads/.
What does an assessment under TISAX require?
No control catalog has been ingested for TISAX yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

TISAX is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

The VDA ISA catalog and TISAX program materials carry their own use terms. Confirm rights for software integration, mappings, and redistribution before ingestion.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Information security · Prototype protection · Data protection · Assessment objectives and labels
Applies to
automotive · manufacturing · supply chain · EU · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30
Pending change
ENX has published ISA2027, which becomes the basis for TISAX assessments ordered from 2027-01-01. Assessments ordered before then may remain on ISA 6, and March 2027 is the final date to open an initial ISA 6 assessment.Expected: 2027-01-01

03Version ledger

2 editions
ISA 5.1.0Supersededdate not published
ISA 6.0.3Current edition · supersedes ISA 5.1.02024-04-25

05Change history

06Related frameworks

scored from registry facts
  1. Same framework family · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. Same framework family · PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).

  3. PCI DSSv4.0.1

    Same framework family · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.

  4. Same framework family · The PCI Software Security Framework standard for payment software design and development, replacing the retired PA-DSS lineage. Part of the family beyond bare PCI DSS that a payments-processing SaaS enterprise is routinely asked about.

TISAX | ControlFrame