TISAX Certification: What Canadian Auto Suppliers Actually Get
TISAXAutomotiveCanada

TISAX Certification: What Canadian Auto Suppliers Actually Get

By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · October 2026 · 8 min read

Your customer's purchasing team just sent a supplier form, and one line asks for your TISAX certification. Nobody on your team has heard the word before, and the contract renewal is sitting behind it.

That is how most Canadian auto parts suppliers meet TISAX. It does not arrive through a regulator. It arrives through a customer, usually a carmaker or a Tier 1 that shares drawings, specifications or prototype parts with you and wants proof you protect them. If that is where you are, you are not behind. You are being asked early, which is the best time to be asked.

Here is the part people get wrong about TISAX certification

People search for TISAX certification because that is the word their customer used. The thing you actually receive is not a certificate. The ENX Association, which governs TISAX, says the results are issued as TISAX labels, and its own TISAX Participant Handbook answers the question directly: if you were hoping for a certificate to hang on the wall, ENX does not provide one, because the results are shared through a standardized exchange instead.

That is not a technicality. It changes how the whole thing works. You do not send a PDF to every customer who asks. You complete one assessment, and you share the result through the ENX portal with the partners you choose. Each customer then sees the same result, and nobody has to audit you separately.

The second thing people get wrong is thinking TISAX is a European problem. The ENX site states that TISAX assessments are conducted worldwide by independent audit providers. If you supply a carmaker's program from Windsor, Oakville or the Waterloo region, the request can land on you exactly as it would on a supplier in Stuttgart.

What you are actually being assessed on

TISAX assesses you against the VDA Information Security Assessment, the catalog everyone calls the VDA ISA. The ENX downloads page lists ISA 6.0.3 as the current version. In the official ISA 6 workbook that ENX publishes, the catalog has three modules:

  • Information Security, which applies to everyone. It holds 46 control questions across seven chapters, from policies and human resources to physical security, access, IT security, suppliers and compliance.
  • Prototype Protection, 22 control questions, which applies only if you handle prototype parts or vehicles.
  • Data Protection, 12 control questions, which applies when you process personal data on behalf of a partner.

The information security and prototype controls are scored on a maturity scale from 0 to 5, and the target is level 3, which the catalog calls Established. That means the control is documented and followed consistently, not just written down. The data protection controls are answered differently in the same workbook, as OK or Not OK.

Which modules apply to you is not your choice alone. The handbook opens by describing the usual starting point: one of your partners asked you to prove your information security meets a defined level. Your customer's request names the assessment objectives they need. ENX's TISAX FAQ states there are currently 10 assessment objectives, and gives the example of a partner who requires the label for information with a high protection level. You select that same objective, and the matching label is what you receive if you pass.

The three assessment levels

The level decides how deeply an audit provider looks at you. The handbook describes all three:

  • Assessment level 1 is mainly for internal purposes, a self-assessment in the true sense. It is useful practice. It is rarely what a customer is asking for.
  • Assessment level 2 means the audit provider runs a plausibility check on your self-assessment for every location in scope.
  • Assessment level 3 means the audit provider runs a full verification of your compliance with the applicable requirements.

Read your customer's request carefully before you order anything. The level and the objectives come from them. Ordering the wrong one means paying for an assessment your customer cannot accept.

How the TISAX process runs

The ENX portal lays the process out in four stages, and they happen in this order:

  • Register your company as a TISAX participant and define at least one assessment scope.
  • Choose an audit provider once registration is complete.
  • Undergo the assessment at the level and objectives your customer named.
  • Exchange the results with existing and potential partners through the portal.

Between the third and fourth steps sits the part most suppliers do not plan for. If the audit provider finds gaps, the handbook describes a corrective action plan, an assessment of that plan, and a follow up assessment. It also describes temporary TISAX labels that can apply while that work is open. The practical lesson is simple. Every gap you close before the audit provider arrives is a gap you do not have to manage in a corrective action plan afterward.

Once issued, the result lasts. ENX states on its TISAX overview that the labels are valid for three years.

Why ISA2027 matters if you are starting now

This part is new. On July 1, 2026, ENX announced that the VDA has published ISA2027, the next version of the catalog. The same announcement states that ISA2027 will apply to all TISAX assessments ordered from January 1, 2027 onwards.

It also introduces a new pattern. Future catalogs will be named for the year they become mandatory, published in summer, and effective on January 1 of the following year. So the catalog is now on an annual cycle, and the version you are assessed against depends on when you order.

For a supplier starting today, that creates a real decision. If your assessment will be ordered before the end of 2026, ISA 6 applies. If it will be ordered in 2027, you are preparing against ISA2027, and building your evidence against the old catalog means redoing part of it. Ask your customer when they need the label, work back from that date, and prepare against the catalog that will actually be in force.

If you already have ISO 27001

It helps, and it is worth being precise about how much. ENX's own ISA2027 announcement says the early versions of the ISA were heavily based on ISO/IEC 27001 and adapted to the needs of the automotive industry. It also says the ISA is no longer simply an industry specific interpretation of existing frameworks, while it stays aligned with ISO/IEC 27001, and that the mappings to ISO/IEC 27001:2022 were reviewed and refined for the new version.

In plain terms: an ISO 27001 program gives you a strong start on the information security module, and much of your existing evidence stays useful. Prototype protection and data protection are automotive specific, and the maturity scoring is a different way of being graded. If you are still deciding whether ISO 27001 is worth doing at all, our ISO 27001 checklist walks through what it involves. What does not work is running TISAX and ISO 27001 as two separate projects with two sets of evidence. Run one system and map it to both.

The evidence problem underneath all of this

Here is the honest pattern our team sees. The controls are rarely the hard part. Most suppliers already lock the doors, control who gets into the ERP, and back up the machines. What they cannot do is prove it on demand. The access review happened, but nobody kept the record. The policy exists, but it was last approved by someone who left in 2023. The supplier agreements are in a filing cabinet.

A maturity scale makes this worse, not better, because level 3 is about consistency over time. One screenshot taken the week before the assessment does not show a control that is established. A record that shows it running month after month does.

That is also why the dates above matter. A supplier who starts collecting evidence now, against the right catalog, walks into the assessment with a history. A supplier who starts the month before has a folder.

If you also sell into Canadian defense programs, the same evidence discipline carries into the federal program for defense suppliers. We cover that on our CPCSC compliance page.

Where we fit, and where we do not

We are not a TISAX audit provider and we do not issue TISAX labels. Only an audit provider working within the TISAX process does that, and it should stay that way. What SecuritComply does is organize the VDA ISA controls by the modules that apply to you, show where you stand against the level 3 target, and hold the evidence for each control in one place, with your compliance data kept in Canada.

To see where you stand before any of that, start with the free TISAX readiness check on our TISAX compliance page. It shows you which parts of the catalog to work on first. If you would rather walk through it with our team, you can book a demo.

Frequently asked questions

Is there such a thing as TISAX certification?

Not in the usual sense. TISAX results are issued as TISAX labels and shared with your partners through the ENX portal. ENX states in its participant handbook that it does not provide a certificate to hang on the wall.

Which TISAX assessment level do I need?

Your customer decides. Their request should name the assessment objectives and the level. Level 2 is a plausibility check on your self-assessment. Level 3 is a full verification of your compliance with the applicable requirements.

How long is a TISAX label valid?

Three years, according to the ENX Association.

Can a Canadian company get TISAX?

Yes. TISAX assessments are conducted worldwide by independent audit providers, and participation is not limited to Europe. Canadian suppliers register through the same ENX portal as anyone else.

Does SecuritComply issue TISAX labels?

No. Only an audit provider within the TISAX process can do that. SecuritComply is software that organizes the VDA ISA controls and your evidence, so you are ready when the audit provider arrives.

References

  • ENX Association, TISAX overview. https://www.enx.com/en-US/TISAX/
  • ENX Association, TISAX on the ENX portal. https://portal.enx.com/en-US/TISAX/
  • ENX Association, TISAX Participant Handbook. https://portal.enx.com/handbook/tisax-participant-handbook.html
  • ENX Association, TISAX frequently asked questions. https://www.enx.com/en-US/TISAX/faqs/
  • ENX Association, TISAX downloads, ISA 6.0.3 and ISA2027. https://www.enx.com/en-US/TISAX/downloads/
  • ENX Association, VDA ISA 6 workbook (English). https://www.enx.com/isa6-en.xlsx
  • ENX Association, 10 Years of TISAX, VDA ISA2027 Released, July 1, 2026. https://www.enx.com/news/isa2027

Ready to get compliant?

SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.

Start Free →