TISAX labels are what a supplier actually receives at the end of the assessment: not a certificate, but one or more labels recorded on the ENX exchange platform, each corresponding to an assessment objective, valid for three years and visible to the partners the supplier chooses to share them with. There are twelve assessment objectives today, in three families — information security, prototype protection and data protection — and choosing the wrong ones is the most expensive mistake in TISAX, because the objectives fix which ISA catalogues apply, which assessment level is used, and which labels can result.
This guide sets out all twelve objectives as the ENX participant handbook lists them, the label hierarchy that hands you lower labels automatically, the 2024 renaming that retired “Info high” and “Info very high”, how validity and renewal work, and how to pick the objectives your customers are actually asking for.

Objectives, labels and the difference between them
TISAX separates the input from the output. The assessment objective is what you register for and what the audit provider assesses against — the handbook calls it “the benchmark for your information security management system” and “a key input for the TISAX process”. The TISAX label is the result: for each objective met, a label of the same name, recorded on the exchange platform. The handbook is explicit that labels are visible in the ENX portal only and “are not recorded in the TISAX assessment report”. A supplier does not hold a TISAX certificate; it holds labels, and it exchanges them. Our guide to TISAX Exchange covers the sharing side.
The twelve TISAX labels and assessment objectives
| # | Objective | What it covers (handbook description) | ISA catalogue | Assessment level |
|---|---|---|---|---|
| 1 | Info high | Handling of information with high protection needs — legacy; selectable only until 31 March 2024 | Information Security | AL 2 |
| 2 | Info very high | Handling of information with very high protection needs — legacy | Information Security | AL 3 |
| 3 | Confidential | High protection needs in the context of confidentiality (access to confidential information) | Information Security | AL 2 |
| 4 | Strictly confidential | Very high protection needs in the context of confidentiality (access to strictly confidential information) | Information Security | AL 3 |
| 5 | High availability | High protection needs in the context of availability | Information Security | AL 2 |
| 6 | Very high availability | Very high protection needs in the context of availability | Information Security | AL 3 |
| 7 | Proto parts | Protection of prototype parts and components | Prototype Protection | AL 3 |
| 8 | Proto vehicles | Protection of prototype vehicles | Prototype Protection | AL 3 |
| 9 | Test vehicles | Handling of test vehicles | Prototype Protection | AL 2 |
| 10 | Proto events | Protection of prototypes during events and film or photo shoots | Prototype Protection | AL 2 |
| 11 | Data | Data protection according to Article 28 (processor) of the GDPR | Data Protection | AL 2 |
| 12 | Special data | Article 28 processing involving special categories of personal data under Article 9 GDPR | Data Protection | AL 3 |
You must select at least one objective and may select several. Each objective defines the applicable ISA catalogue(s), the control questions to answer and the requirements to fulfil; for some objectives only a subset of questions applies, which the ISA’s applicability columns show. Our guide to TISAX assessment levels explains why the level column matters.
The 2024 renaming
With the ISA 6 release, ENX split the two information-security objectives into confidentiality and availability pairs. “Info high” and “Info very high” could be selected only until 31 March 2024; from 1 April 2024 participants select “Confidential” or “Strictly confidential” for the confidentiality dimension and “High availability” or “Very high availability” for the availability dimension. Labels already issued under the old names remain valid until their expiry, and the hierarchy below means their holders also carry the new labels.
The TISAX label hierarchy
Some labels are supersets of others, and the handbook states the rule: “if you receive a certain TISAX label, you automatically receive the TISAX labels ‘below’ that particular label.” The current hierarchy:
| This label | Automatically includes |
|---|---|
| Info high | Confidential, High availability |
| Info very high | Strictly confidential, Very high availability |
| Strictly confidential | Confidential |
| Very high availability | High availability |
| Special data | Data |
Labels are also granted retroactively: when ENX introduces a new label that is a subset of one you hold, it is assigned automatically — the handbook’s example is a participant with “Info high” receiving “High availability” when that label was introduced. The hierarchy can be derived from the applicability of requirements to each objective, and it matters commercially: a supplier assessed for “Strictly confidential” can satisfy a partner asking for “Confidential” without a second assessment. Prototype objectives have no hierarchy among themselves; each is assessed on its own.
How long TISAX labels are valid
TISAX labels are generally valid for three years, and the validity period starts at the end of the assessment process — before the assessment report is issued. The period can be shortened if something significant in the scope changes, such as relocation or new locations. To keep labels, the participant runs the process again: register a scope, get assessed, exchange. Annual ISA releases do not shorten validity; a label issued under ISA 6 remains valid for its three years even after ISA2027 becomes the assessment basis for new assessments on 1 January 2027. Our guide to VDA ISA2027 covers the version rules.
Choosing the right objectives
- Ask the customer for the objective by name. Partners specify objectives, and increasingly a minimum assessment level. “We need TISAX” is not a specification; “Confidential and Proto parts” is.
- Read the protection need off the information, not the relationship. Handling design data under NDA is typically “Confidential”; handling data the customer classifies as strictly confidential — future model data, unreleased designs — is “Strictly confidential”. The customer’s classification decides.
- Add prototype objectives only where prototypes are physically present. Proto parts and Proto vehicles are AL 3 assessments of your physical environment; Test vehicles and Proto events are AL 2 and cover public-road testing and events. A supplier that never sees a physical prototype does not need them.
- Add Data or Special data where you process personal data as an Article 28 processor for the partner. Special data is AL 3 and applies where Article 9 categories are involved.
- Use the hierarchy to future-proof. If several partners will ask at different levels, assess at the higher one once; the lower labels come with it.
- Register objectives per scope. Objectives attach to an assessment scope of one or more locations. A group with sites doing different work may need different objectives per scope rather than everything everywhere.
Our guide to TISAX certification cost shows how the objective choice — through the assessment level and the catalogues in scope — drives the price.
Frequently asked questions
How many TISAX labels are there?
Twelve assessment objectives, each yielding a label of the same name: six information-security objectives (including the two legacy ‘Info’ labels), four prototype-protection objectives and two data-protection objectives.
What is the difference between an assessment objective and a label?
The objective is the input — what you register for and are assessed against. The label is the result, recorded on the ENX exchange platform and valid three years. Labels appear in the portal, not in the assessment report.
Is there a TISAX certificate?
No. TISAX issues labels, exchanged through the ENX platform with the partners you authorize. There is no certificate document.
What happened to ‘Info high’ and ‘Info very high’?
They were replaced from 1 April 2024 by the Confidential / Strictly confidential and High availability / Very high availability pairs. Existing ‘Info’ labels stay valid to expiry and include the new labels through the hierarchy.
How long are TISAX labels valid?
Three years from the end of the assessment process, shortened if the scope changes significantly. Renewal means running the TISAX process again.
Where this leaves you
Get the objective by name from each partner, read the protection need off the information you will handle, add prototype and data objectives only where they physically or legally apply, and assess at the higher level once so the hierarchy hands you the rest. The twelve TISAX labels are the whole output of the process; choosing the right ones is the first decision and the one that sets every cost after it.
References
- ENX Association: TISAX Participant Handbook — Sections 4.3.3 (assessment objectives) and 5.4.14 (TISAX labels, hierarchy, validity).
- ENX Association: TISAX — The scheme operator’s overview and downloads.
More on TISAX
- TISAX labels — you are here
- TISAX Exchange: the half suppliers never use
- TISAX assessment levels: AL 1, 2 and 3
- The TISAX self-assessment
- TISAX prototype protection
- TISAX certification cost
The scope definition, the VDA ISA Statement of Applicability workbook that records which objectives and questions apply, the prototype protection policy and register, and the data protection policy and DPA template are in the TISAX Documentation Toolkit, or start with the free templates.