The automotive sector and its subsidiaries operating in the European Union have been working intensively in recent months to comply with the NIS2 Directive’s requirements. Your TISAX® Certificate provides significant convenience in complying with NIS2 requirements. For more information, you can review this document.
This content explains how the TISAX® framework, based on ISA 6.0.3, supports NIS2 Articles 20-25 and how it aligns cyber security preparedness with regulatory expectations.
What is the connection between NIS2 and TISAX®?
The NIS2 Directive (EU 2022/2555) imposes stringent cybersecurity obligations on essential and important organisations across high-risk sectors, including automotive manufacturing. It covers governance, risk management, incident response, supply chain security, and reporting obligations.
TISAX® (Trusted Information Security Assessment) is the automotive industry’s standardised mechanism for assessing and sharing information security status, based on the ISA (Information Security Assessment) catalogue, currently at version 6.0.3.
Meeting NIS2 through TISAX®
The VDA ISA 6.0 standard, which is mandatory for TISAX® assessments requested after 1 April 2024, directly aligns with the core requirements of NIS2:
- Management and Governance (NIS2 Articles 20-22): TISAX® requires senior management to be actively involved in information security, providing oversight, approving measures, and receiving regular reports.
- Risk Management and Security Measures (NIS2 Article 21): The ISA 6.0 catalogue covers all relevant security areas, including risk management, information security policies, asset management, access control, and human resources security.
- Incident Response (NIS2 Article 23): ISA 6.0 significantly strengthens the incident management and crisis management requirements necessary for compliance with NIS2 reporting obligations.
- Supply Chain Security (NIS2 Article 21): TISAX®, a framework specifically designed for the automotive supply chain, ensures that security requirements are transferred and maintained throughout the supply chain.
- Technical Protection Measures: TISAX® includes requirements for encryption, network security, and vulnerability management, and ISA 6.0 strengthens these requirements.
Who must comply with TISAX®?
Compliance with TISAX® is not a legal requirement, but it is frequently applied in the automotive industry to ensure high supplier quality. All organisations operating in the automotive industry are expected to comply with this standard. In practice, most original equipment manufacturers (OEMs) consider TISAX® compliance a prerequisite for cooperation.
Organisations that frequently implement it in the context of mechanical, equipment and plant engineering, information and communication technology, marketing and creative services;
- Manufacturers
- Technology companies serving this sector
- Suppliers
- Research and development companies
- Logistics companies
TISAX® is no longer just a supplier requirement, but a strategic asset for NIS2 readiness. If your organisation operates within the EU automotive ecosystem, aligning your ISA6 controls with regulatory frameworks such as NIS2 is not only efficient but also expected.
For more information about CFECERT’s specially designed training programmes for the automotive sector, please review our catalogue and contact us at info@cfecert.co.uk.