TISAX certification cost is the question every automotive supplier asks the day an OEM or Tier 1 emails a request for a TISAX label, and almost every answer online gets the one fixed fee wrong. Vendor guides quote the ENX registration at “several thousand euros” or “around EUR 4,450 per scope”; the official ENX price list says EUR 405 per location per scope, charged once. That gap tells you something about the rest of the numbers you will read. This guide separates the three parts of the bill — the ENX fee, the audit provider’s fee, and the preparation work — explains what drives each one, and shows where the money is actually spent, so you can budget before you request a quote rather than after.
One framing point up front: there is no TISAX “certificate”. You register with the ENX Association, an approved audit provider assesses you against the VDA ISA catalogue, and you receive TISAX labels valid for up to three years. Buyers search for “certification”, so this article uses the term, but the structure of the cost only makes sense once you see it as an assessment you pay for in stages.
TISAX Certification Cost at a Glance
The table below is the whole TISAX certification cost picture for a single-site supplier with one assessment scope. The ENX fee is a published figure. The audit and preparation ranges are typical figures aggregated from 2026 guidance published by TISAX audit providers and consultancies — not a survey, and not a quote. Everything is net of VAT and stated in euros because ENX and most audit providers invoice in euros.
| Cost item | Who you pay | Typical 2026 range (EUR) | What drives it |
|---|---|---|---|
| ENX registration | ENX Association | 405 per location per scope (one-time) | Number of locations and scopes; 10–20% volume discounts |
| Initial assessment, AL2 | Audit provider | 3,000 – 8,000 | Auditor days (typically 2–3), number of objectives and interviews |
| Initial assessment, AL3 | Audit provider | 8,000 – 25,000 | Auditor days (typically 3–5 plus reporting), sites, prototype scope, travel |
| Preparation and consulting | Consultant or internal team | 10,000 – 35,000 | Gap to maturity level 3, existing ISO 27001 ISMS, documentation state |
| Internal effort | Your payroll | Several hundred hours | Self-assessment quality, evidence collection, corrective actions |
| Follow-up assessment | Audit provider | Usually quoted after the initial assessment | Number and type of non-conformities |
| Renewal after 3 years | ENX + audit provider | Roughly two-thirds of the first cycle | Delta to the current ISA catalogue, scope changes |
Add those up and a small single-site supplier going for AL2 labels typically spends EUR 15,000–30,000 across the first cycle, a mid-sized supplier needing AL3 labels EUR 30,000–60,000, and multi-site groups with prototype protection in scope run well past EUR 100,000. The audit provider’s fee is rarely the biggest line; the preparation is.
Why “TISAX Certification” Is the Wrong Word — and Why It Changes the Bill
ISO 27001 has a certification body that issues a certificate against a single international standard. TISAX has three parties, and each one shapes the TISAX certification cost differently.
- ENX Association runs the scheme, holds the register of participants, publishes the participant handbook and charges the registration fee. It does not assess anyone.
- TISAX audit providers are the firms ENX has approved to conduct assessments. They set their own prices. ENX’s handbook is explicit that every provider works to the same contract, criteria and methods, and that the result is accepted by every TISAX participant regardless of which one you choose — which is exactly why you should get more than one quote.
- The VDA ISA catalogue is the requirement set. It is a free Excel download from the ENX portal. You never pay for the standard itself, unlike the CHF 100–200 you spend on an ISO standard.
If you are still deciding whether TISAX is the right route at all, or whether an existing ISO 27001 certificate will satisfy your customer, read ISO 27001 vs TISAX first; that decision changes the numbers below more than anything else.
The One Fixed Fee: What ENX Actually Charges
The ENX TISAX price list uses an “Assessment Based Charges” model: EUR 405 net per location within one assessment scope, paid once. The document states there are no recurring fees during the validity period of your assessment. Discounts apply automatically — 10% per location for 5–9 locations in a scope, 20% for 10 or more. Payment is due within 30 days and is a prerequisite for ENX accepting your registration, so it sits on the critical path of your timeline.
Two details matter for larger groups. First, a scope covering one location costs EUR 405; the same scope covering four locations costs EUR 1,620. Second, if you plan to register 20 or more locations or many different scopes, ENX offers an alternative “Participation Based Charges” model at EUR 5,000 per year for an unlimited number of scopes and locations. It cannot be selected in the portal — you have to ask ENX for it — and active ENX members get it free.
That is the entire ENX cost. The handbook says the online registration for one scope and one location takes a minimum of 20 minutes. Any guide that puts the ENX line at four figures is either confusing it with the audit fee or has not read the price list.
Audit Provider Fees: AL2 vs AL3
The assessment level is the single largest driver of the audit fee, and you do not choose it freely — your customer’s assessment objective sets it. The ENX participant handbook maps every current objective to a level (the older “Info high” and “Info very high” objectives, which closed to new registrations on 31 March 2024, were AL2 and AL3 respectively):
| Assessment objective (label) | Assessment level | Method the audit provider must use |
|---|---|---|
| Confidential, High availability, Test vehicles, Proto events, Data | AL2 | Plausibility check of your self-assessment, evidence review, interview with the information security lead — normally by web conference |
| Strictly confidential, Very high availability, Proto parts, Proto vehicles, Special data | AL3 | Full verification on site: document and evidence examination, planned interviews with process owners, observation of local conditions and process execution, unplanned interviews with staff |
Audit providers price in auditor days, so the audit share of your TISAX certification cost is a day count times a day rate. Published 2026 guidance from consultancies puts day rates at roughly EUR 1,200–1,500, with 20–30% variation between providers. An AL2 assessment for one site and one objective typically takes 2–3 days including the report, which is where the EUR 3,000–8,000 range comes from. An AL3 assessment adds on-site days, travel, and more interviewees; 3–5 auditor days plus expenses lands most single-site suppliers in the EUR 8,000–25,000 band, and each additional location or a prototype-protection objective pushes it higher.
There is a middle option worth knowing about. The handbook describes an “AL 2.5” — a full remote assessment instead of a plausibility check, formally recorded as AL2. It costs more than a plain AL2 but is methodically compatible with AL3, so if a second customer later demands AL3 labels, the provider only needs to add the on-site activities rather than start over. For a supplier that expects its customer list to grow, that is a cheaper path than two full assessments.
When you request quotes, attach the “TISAX Scope Excerpt” ENX emails you after registration. The handbook says providers need it to calculate the expected effort precisely; without it you get a padded estimate.
Preparation: Where the TISAX Certification Cost Really Lives
The audit provider checks whether you meet the requirements; getting there is your cost. The ISA sets a target maturity level of 3 for every question — a defined, documented process that is followed and can be shown to work — and you cannot offset a 2 on one question with a 4 on another. Every question has to clear the bar on its own.
For a supplier with no management system, published guidance typically puts that at 9–18 months and the consulting range in the table. For a supplier already certified to ISO 27001:2022, the ISA’s information security controls overlap heavily and the typical timeline compresses to a few months; the incremental work is the ISA-specific evidence and, if in scope, prototype protection and the GDPR Article 28 data protection module. That overlap is the main reason the ISO 27001 certification cost and the TISAX certification cost are often budgeted together.
Where consulting money goes, in order: gap analysis against the ISA, writing the policy and procedure set, running the self-assessment honestly, then preparing people for interviews. The handbook notes that compiling a self-assessment plausible enough for AL2 “can cause considerable internal effort, even for companies that are fundamentally well positioned”. Budget several hundred internal hours for that alone. A documentation set built for the ISA — rather than a repurposed ISO 27001 pack — is the cheapest way to shorten this phase; the TISAX Documentation Toolkit ships 40 templates aligned to the ISA2027 assessment objectives for $99, which is less than one consultant hour.
Hidden Costs: Corrective Actions, Follow-Ups and Temporary Labels
Many suppliers do not get a clean “conform” at the initial assessment, and the quotes you receive do not show the full TISAX certification cost for that reason; the assessment process is designed around corrective actions. Three cost consequences follow directly from the handbook rules.
- Follow-up assessments are usually not in the quote. Offers normally include the initial assessment and the corrective action plan assessment. Because the effort of a follow-up depends on what was found, providers typically quote it afterwards. Hold back 15–25% of the audit budget for it.
- Nine months is the hard limit. You have up to nine months after the closing meeting of the initial assessment to resolve all non-conformities. Miss it and the labels are not issued; you start a new initial assessment and pay for it again.
- Temporary labels buy you time, not a discount. If your result is “minor non-conform” with an approved corrective action plan, you receive temporary TISAX labels for up to nine months that most customers accept. Implementation periods over three months need justification, over six months need evidence, and nothing can exceed nine months.
The other quiet line item is travel. For AL3 the auditor must come to every location in scope, and the handbook lists travel cost as one of the criteria for comparing offers — a provider with auditors in your country is cheaper than one flying in.
The Three-Year Cycle and the ISA2027 Clock
TISAX certification cost is not a one-off. Labels are valid for three years from the end of the assessment process. Renewal means a new initial assessment, a fresh ENX fee per location and the audit provider’s fee again — published guidance puts a renewal at roughly two-thirds of the first cycle because the ISMS exists and the work is a delta. Over six years, expect to spend about 1.7 times your first-cycle figure.
The 2026 wrinkle is the catalogue change. VDA published ISA2027 on 1 July 2026 and ENX has confirmed it applies to every TISAX assessment ordered from 1 January 2027; assessments ordered before that date can still run on ISA 6. Labels keep their three-year validity either way, so the annual release cycle does not increase how often you pay. The cost trap is preparing to the wrong catalogue: a gap analysis and document set built to ISA 6 in late 2026, for an assessment you will only order in 2027, means paying twice for the prototype-protection work, where ISA2027 renumbered and consolidated the controls. Decide the ordering date first, then buy the preparation.
How to Reduce Your TISAX Certification Cost Without Cutting Corners
- Scope precisely. Register only the locations and objectives your customer asked for. Each extra location is EUR 405 plus auditor time; each extra objective, especially a prototype label, is more evidence and possibly a jump to AL3.
- Use one scope for multiple locations when objectives match. The handbook notes the provider then assesses your central processes once, which reduces the assessment cost — at the price of the result only being issued when every location passes.
- Get three quotes with the scope excerpt attached. Same method, same acceptance, different price and availability.
- Choose AL 2.5 if AL3 may come later. Upgrading is the on-site portion only.
- Run the self-assessment before you book the auditor. Every finding you close beforehand is a finding you do not pay a follow-up for. The TISAX audit checklist walks through the seven steps in order.
- Reuse your ISO 27001 evidence. If you hold a 27001:2022 certificate, hand the auditor the Statement of Applicability and internal audit results; they shorten the plausibility check.
TISAX Certification Cost: FAQ
Is the ENX fee really only EUR 405?
Yes, under the standard Assessment Based Charges model: EUR 405 net per location within one scope, one time, with no recurring fee during the label’s validity. Volume discounts apply from five locations. The larger figures you see online usually bundle in the audit provider’s fee, which is separate and set by the provider.
Do I pay less if I already have ISO 27001?
You pay the same ENX fee and a similar audit fee, but far less in preparation. The ISA’s information security module overlaps substantially with ISO 27001:2022’s controls, so the gap is usually ISA-specific evidence plus any prototype or data protection module your customer requires. Note that a 27001 certificate does not replace a TISAX label; customers who ask for a label want the label.
What happens to the cost if I fail the initial assessment?
If the result is “major non-conform” you agree a corrective action plan, implement it and pay for a corrective action plan assessment and at least one follow-up assessment. With an approved plan you can hold temporary labels for up to nine months. If you have not resolved everything nine months after the closing meeting, no labels are issued and you must pay for a new initial assessment.
Should I rush an assessment before ISA2027 applies?
Only if you are genuinely ready. Assessments ordered before 1 January 2027 run on ISA 6; those ordered afterwards run on ISA2027. Rushing into an initial assessment you fail costs more than waiting a quarter and passing against the new catalogue. If you are starting preparation now for an early-2027 order, build to ISA2027 from the outset.
How much does a TISAX renewal cost?
Published 2026 guidance puts the renewal share of TISAX certification cost at about two-thirds of the initial cycle: the ENX fee per location is charged again, the audit provider’s effort is lower because the ISMS exists, and preparation shrinks to closing the delta against whichever ISA release is current at the time you order.
The honest summary of TISAX certification cost is this: the scheme fee is trivial, the auditor’s fee is predictable once you know your assessment level, and the preparation is where budgets are won or lost. Fix the scope and the ordering date first, run the self-assessment against the right ISA release, and the quote you receive will be the one you actually pay. The primary source for every process rule above is the ENX TISAX Participant Handbook (version 2.8) — read it before you sign with a provider.