# TISAX Levels Simplified: Differences, Preparations & Checklists

## In this article:
- [TISAX level 1](https://www.strikegraph.com/blog/everything-you-need-to-know-about-tisax-levels#TISAX-Level-1-jumplink)
- [TISAX level 2](https://www.strikegraph.com/blog/everything-you-need-to-know-about-tisax-levels#TISAX-Level-2-jumplink)
- [TISAX level 3](https://www.strikegraph.com/blog/everything-you-need-to-know-about-tisax-levels#TISAX-Level-3-jumplink)
- [Who does TISAX apply to at each level?](https://www.strikegraph.com/blog/everything-you-need-to-know-about-tisax-levels#Who-does-TISAX-apply-to-at-each-level-jumplink)
- [How to prepare for TISAX](https://www.strikegraph.com/blog/everything-you-need-to-know-about-tisax-levels#How-to-prepare-for-TISAX-jumplink)

For automotive vendors, TISAX compliance is no longer optional — it’s a ticket to doing business in the competitive auto industry. This guide compares the three TISAX assessment levels to help you prepare for compliance. Also, get a free TISAX prep checklist.

## TISAX levels explained

TISAX, or Trusted Information Security Assessment Exchange, has three assessment levels. Level 1 is a self-assessment mainly for internal purposes. Level 2 is a remote document audit, and Level 3 advances to an on-site audit. Only levels 2 and 3 result in a TISAX certificate, called a label.

The three levels aim to establish standard security assessments for organizations throughout the automotive supply chain. TISAX is mandatory for any vendor working with a German auto manufacturer and is quickly becoming the gold standard for U.S. automakers like Ford and General Motors.

The TISAX assessment levels match the sensitivity of information an organization handles, as defined by its TISAX assessment objectives and scope ID. Scope ID helps delineate the specific areas covered by the company’s information security management system (ISMS). For example, a supplier handling prototype vehicle data may have a scope ID requiring assessment level 3 (AL 3), whereas an HR service provider handling employee data might only need AL 2.

Also, take note that suppliers already certified for ISO 27001 have a head start. The German Association of the Automotive Industry (VDA) developed TISAX based on ISO 27001 but also included automotive-specific requirements. (For more, see our article on [TISAX vs. ISO 27001](https://www.strikegraph.com/blog/tisax-vs-iso-27001).)

### TISAX Level 1 (AL 1)

TISAX Level 1, also called AL 1 for assessment level 1, is the entry point for organizations to establish information security. Level 1 relies on self-assessment and doesn’t result in a TISAX label.

### TISAX Level 2 (AL 2)

With TISAX Level 2, a third-party auditor remotely reviews your organization’s self-assessment and documentation and interviews you on a call. This is called a plausibility check.

### TISAX Level 3 (AL 3)

TISAX Level 3 (AL 3) includes an on-site security audit for organizations managing highly sensitive information. This includes prototypes, advanced development projects, and highly confidential business data.

## TISAX assessment levels vs. TISAX maturity levels

TISAX assessment levels (AL1, AL2, and AL3) define the audit type and depth, while maturity levels (0-5) measure an organization's information security management system (ISMS). TISAX requires aligning assessment levels with a strong ISMS maturity framework.

Here are the ISMS maturity levels from the TISAX Participant Handbook:
- Level 0 – Incomplete: No structured process exists.
- Level 1 – Performed: Process exists but is undocumented.
- Level 2 – Managed: Documented and effective process.
- Level 3 – Established: Standardized and consistently applied.
- Level 4 – Predictable: Process is measured and controlled.
- Level 5 – Optimizing: Continuous improvement based on business goals.

## How TISAX assessment levels connect with other TISAX elements

TISAX has four main elements. **Assessment objectives** define the security areas to be evaluated. **Assessment levels** determine the audit's depth. **Maturity levels** reflect how well you manage security processes. **TISAX labels** are the result.

## Who does TISAX apply to?

TISAX applies to companies in the auto supply chain. This includes parts suppliers and software, engineering, and logistics firms. Also, TISAX labels are location-specific. A company with more than one physical location must earn the necessary TISAX label for each location involved in the work.

## How to prepare for TISAX compliance at each level

1. **Understand the TISAX requirements**
2. **Establish an information security management system (ISMS)**
3. **Enact information security controls**
4. **Train your team**
5. **Conduct internal audits**
6. **Address the gaps**
7. **Schedule a TISAX assessment for AL2 and AL3**
8. **Maintain and improve your ISMS**

## TISAX checklist for preparation and certification

[Click here to download the checklist today](https://docs.google.com/spreadsheets/d/1j34LG-gybMIZixD6WWGkUogC7-2KcR2F/edit?usp=sharing&ouid=101028823056124760473&rtpof=true&sd=true)

## How ISO 27001 helps with TISAX certification levels

ISO 27001 provides an ISMS framework to meet TISAX requirements. Having ISO 27001 certification provides a head-start on TISAX, which is based on its principles and many of its controls.

## The benefits of completing TISAX at each level

Here’s a more detailed overview of TISAX benefits for assessment levels 2 and 3:
- **Enhanced trust and reputation**
- **Competitive advantage**
- **Streamlined assessment process**
- **Improved information security**
- **Regulatory compliance**

## How long does it take to get TISAX certification at each level?

How long TISAX takes depends on your starting point. It will often take 12-15 months or more, based on multiple factors.

## How much does TISAX cost at each level?

Expenses include the ENX registration fee, audit provider fees, implementation costs for security upgrades, and consulting fees. Costs can vary significantly based on organizational maturity, existing security practices, and resources.
