Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TISAX Exchange steps and the active and passive participant roles

TISAX Exchange: The Half of TISAX Suppliers Never Use

TISAX Exchange is the part of TISAX that most explanations skip, and it is the part that explains why the whole thing exists.

TISAX is not a certification scheme with a certificate you file away. It is an exchange mechanism — ENX’s own summary is “assessed once, recognized by many” — and if you are not using the exchange, you have paid for an assessment and thrown away the benefit.

What TISAX Exchange actually is

ENX describes TISAX as an assessment and exchange mechanism for enterprise information security that allows recognition of assessment results among participants. Its purpose is to reduce effort on both sides: for organisations processing sensitive customer information, and for those evaluating the security of their own suppliers.

That framing matters because it changes what success looks like. A completed assessment is not the outcome. A result that your customers can see, and that stops them sending you a bespoke questionnaire, is the outcome.

The four TISAX Exchange steps

The four TISAX Exchange steps and the active and passive participant roles

Registration comes first: you register as a participant and define at least one TISAX assessment scope. The scope is the single most consequential decision in the process, because it determines what is assessed, what the result covers, and therefore what a customer can rely on.

Selection is choosing an audit provider. ENX does not assess you — it publishes the list of providers and you engage one directly.

Assessment is the audit itself, against the applicable VDA ISA catalogue.

Exchange is where the value lands, and where organisations most often stop too early. TISAX Exchange is the step that removes the questionnaires.

TISAX Exchange has two roles, not one

This is the distinction that reframes TISAX Exchange for most people.

Active participants are assessed and provide their result to others through TISAX Exchange. Passive participants request results from other participants and access them in the ENX Portal once the request is confirmed.

ENX is explicit that every participant can hold both roles at the same time, and that TISAX does not differentiate between them.

The practical consequence is one most suppliers never act on. If you were pushed into TISAX by a customer, you are an active participant — but you almost certainly have your own suppliers handling sensitive information, and you can use the same registration to request their results rather than running your own questionnaire programme.

TISAX Exchange is not only an obligation, it is a tool you can use. Very few organisations turn that around.

Scope decides what TISAX Exchange delivers

Because TISAX Exchange shares a result rather than filing it, the scope you register defines what your customers actually receive.

  • Too narrow and a customer reads the result, finds their work sits outside it, and sends the questionnaire anyway. You have paid for an assessment that did not remove the effort it was meant to remove.
  • Too broad and you are assessed against locations and processes that no customer required, at your own cost.
  • Multiple scopes are possible — registration requires at least one — which is how organisations with genuinely different sites or service lines handle the problem.

Decide scope from the customer requirement that triggered the process, then check it against the work you actually do for them. That comparison is the whole exercise, and it happens before you speak to an audit provider.

Keeping current

The assessment catalogue moves. VDA ISA2027 has been released — ENX has published a redline document showing the changes and run a webinar series, with recordings available.

The redline is the efficient way in for anyone who already holds a result: it shows what changed rather than making you re-read the catalogue. Our guide to what ISA2027 changes covers the substance, including the control numbering that shifted meaning.

How TISAX relates to other frameworks

Framework Relationship
ISO 27001 The closest neighbour, and the usual foundation. An ISMS gives you most of the control substance, but TISAX assesses against the VDA ISA catalogue and delivers a shareable result — ISO 27001 certification is not a TISAX result
NIS2 ENX has published material on the interaction. For automotive suppliers in scope of both, the control work overlaps substantially
IATF 16949 The quality equivalent in the same supply chain. Different subject, same customer-driven dynamic
EU CRA Where products contain digital elements, the Cyber Resilience Act obligations sit alongside and are not covered by a TISAX result

Where to start

  1. Get the customer requirement in writing — which scope, which catalogue, by when.
  2. Define the assessment scope against the work you do for them, before contacting a provider.
  3. Register, then select a provider from the published list.
  4. Read the Participant Handbook, which is the reference for the process itself.
  5. Use the exchange in both directions — request your own suppliers’ results as a passive participant.
  6. Take the ISA2027 redline rather than re-reading the whole catalogue.

This guide reflects the ENX Portal at 15 August 2026.

The TISAX Documentation Toolkit provides 40 editable compliance templates covering the scope definition, the control implementation records against the VDA ISA catalogue, and the evidence an audit provider expects to see.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.