An OEM Has Asked for TISAX: Where Penetration Testing Fits for Automotive Companies

An OEM Has Asked for TISAX: Where Penetration Testing Fits for Automotive Companies

By EJN Labs · 14 Aug 2026 · 8 min read

TISAX does not name penetration testing as a mandatory control, but the VDA ISA catalogue behind it expects evidence that technical security measures are checked in practice. For most UK automotive suppliers, a scoped penetration test is the cleanest way to produce that evidence before an assessment. Typical TISAX-driven engagements run 4 to 8 days with a CREST-accredited firm, around £4,400 to £11,200.

TISAX penetration testing: why an OEM request changes your workload

If a vehicle manufacturer or tier-one customer has just made a TISAX label a condition of doing business, you are in good company. TISAX penetration testing questions land on our desk most often at exactly this moment: an OEM has made the label contractually mandatory, a deadline is attached to a contract renewal or programme award, and nobody in the business has been through an ENX assessment before.

The honest position is this. TISAX is an independent information-security assessment, not a technical test. A penetration test is supporting evidence, and how much you need depends on your risk profile and what your customer asks for. This article explains where testing genuinely fits, what to scope, and what UK suppliers typically pay.

What TISAX is and who is behind it

TISAX (Trusted Information Security Assessment Exchange) is an assessment scheme operated by the ENX Association on behalf of the VDA, the German automotive industry association. It exists so OEMs do not have to audit every supplier individually: one assessment covers many customer relationships.

Your organisation is assessed once by an ENX-approved audit provider against the VDA ISA catalogue, and the resulting label is shared with participating customers through the ENX platform.

TISAX is not a legal requirement. It becomes mandatory through contract: when a customer requires a label at a given assessment level, you cannot supply them without it. The VDA ISA catalogue is closely aligned with ISO 27001, with additional modules for prototype protection and data protection, and assessments are scored on maturity levels. The assessor wants controls that demonstrably operate, not policies that merely exist, and that is exactly where technical testing earns its place.

Does TISAX require a penetration test?

Not in so many words, and any provider who calls a pen test a hard TISAX prerequisite is overselling. The VDA ISA catalogue expects you to identify and manage technical vulnerabilities and verify that IT systems meet your security requirements, leaving the method to you, proportionate to risk.

In practice, TISAX sits in the class of frameworks that strongly trigger technical testing even though they do not prescribe it. Three reasons:

  • Assessors ask what proof you have that technical controls work. A recent penetration test report, with findings tracked to closure, is direct evidence of a working vulnerability management cycle; a scan alone shows detection, not exploitability.
  • Maturity scoring rewards demonstrated effectiveness, and independent testing shows a control has been exercised and measured.
  • OEM customers often ask directly: many manufacturers’ supplier security schedules require periodic penetration testing of systems that touch their data.

So the accurate answer is: TISAX expects evidence that technical measures are checked, your customer may require testing outright, and one well-scoped test satisfies both.

What to test in a typical automotive supplier estate

The scope you register with ENX defines which locations and processes are in play, and your testing scope should mirror it. Four areas matter most.

External infrastructure and remote access

Everything internet-facing at in-scope sites: VPN gateways, file transfer services used to exchange CAD and engineering data with OEMs, mail infrastructure and any exposed management interfaces. This is the fastest route an attacker has to the customer data your label is meant to protect, and external infrastructure penetration testing is the baseline evidence most assessments benefit from.

Engineering data flows and internal segregation

Prototype protection is a dedicated VDA ISA module. If you hold pre-series designs, test vehicle data or unreleased component specifications, the assessor will care who can reach the systems that store them. Internal testing that verifies segregation between office IT, engineering systems and any shop-floor or test-rig networks evidences that need-to-know is enforced technically, not just on paper.

Cloud platforms and customer portals

Suppliers now commonly run engineering collaboration, PLM or quality systems in AWS, Azure or SaaS platforms. A cloud penetration test covering identity configuration, storage exposure and tenant separation maps directly onto the catalogue’s expectations for secure operation of IT services.

APIs and connected products

If your product itself talks to vehicles, telematics platforms or OEM back ends, API penetration testing belongs in scope. It is far cheaper to find an authorisation flaw before an OEM’s security team does.

How a TISAX-driven engagement runs

Engagements run in four stages: scoping that maps your registered TISAX assessment scope to a concrete asset list, testing by UK-based testers through the agreed scope, reporting structured so it can be handed to a TISAX assessor as verification evidence, and retesting once fixes land.

Scoping agrees which systems handle OEM data or prototypes. Testing runs from external reconnaissance through authenticated testing, with safe-testing windows for anything connected to production or test-rig environments. Each finding carries business impact, reproduction steps and remediation guidance, and the updated report issued after retest shows your vulnerability management cycle closing, which is what maturity scoring rewards.

Preparing internally first? Our penetration testing checklist covers what to have ready before testers arrive.

What it costs and how scope drives the price

UK penetration testing is priced by effort, at a day rate of £1,100 to £1,400 for a CREST-accredited firm. The registered TISAX scope drives the day count: number of sites, internet-facing footprint, and whether cloud or product APIs are included.

EngagementTypical effortTypical UK price
External infrastructure test2 to 4 days£2,200 to £5,600
Internal network and segregation test3 to 5 days£3,300 to £7,000
Cloud configuration and platform test3 to 5 days£3,300 to £7,000
Web application or API test4 to 6 days£4,400 to £8,400
Combined TISAX evidence package4 to 8 days£4,400 to £11,200

These are typical UK ranges rather than quotes; the exact figure comes from a short scoping conversation. For a fuller breakdown, see our guide to penetration testing costs in the UK.

How EJN Labs approaches TISAX-driven testing

EJN Labs is a CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. For automotive suppliers we start from the ENX scope registration rather than a generic asset list, because assessors want evidence tied to the scope on the label. When scoping these estates we pay particular attention to the file exchange routes suppliers use with OEMs; in our experience the managed transfer platforms and legacy SFTP endpoints that carry CAD data are where externally reachable weaknesses most often sit, and they are precisely the systems a customer security schedule cares about.

Reports serve two audiences at once: your engineering and IT teams, who need reproduction detail, and your TISAX assessor, who is looking for a working test-fix-retest cycle. If you are comparing suppliers, our guide to choosing the best UK penetration testing provider sets out the questions worth asking, and our CREST penetration testing page explains what the accreditation covers.

Frequently Asked Questions

Does TISAX require a penetration test?

No. Nothing in the VDA ISA catalogue names penetration testing as a mandatory control. The catalogue expects you to identify and manage technical vulnerabilities and to verify that systems meet your security requirements, with the method left proportionate to risk.

A penetration test is the strongest common form of that verification evidence, and many OEM contracts require testing directly in their own security schedules.

What does TISAX penetration testing cost in the UK?

Around £2,200 to £5,600 for a single-discipline test such as external infrastructure over 2 to 4 days, and around £4,400 to £11,200 for a combined TISAX evidence package covering external, internal and cloud scope over 4 to 8 days, at CREST-accredited day rates of £1,100 to £1,400.

The registered assessment scope is the main cost driver.

Can we pass a TISAX assessment without a penetration test?

Yes, in principle, if you can evidence vulnerability management and technical verification another way, for example through structured scanning, hardening reviews and audit trails. In practice, suppliers aiming for solid maturity scores find independent testing the most persuasive evidence available.

If your customer’s contract separately requires a penetration test, no amount of scanning substitutes for it.

Does the TISAX assessment level change what we should test?

The assessment level changes what you should aim to cover, not the testing method. Your customer sets the level to reflect the protection need of the information you handle, and higher levels bring more rigorous assessment methods, so your testing ambition should rise with them.

Suppliers handling data with high protection needs, or prototypes, generally want internal segregation and cloud scope tested, not just the external perimeter.

How often should we retest for TISAX?

Retest annually for in-scope systems, with additional testing after significant changes such as new customer portals, cloud migrations or acquisitions. TISAX labels are valid for three years, but a three-year-old test report is weak evidence, so the label’s lifespan is not a sensible testing cadence.

An annual cycle also gives your assessor a visible pattern of findings raised, fixed and verified over time.

Get a TISAX-ready penetration test scoped this week

If an OEM deadline is on the table, the fastest move is a short scoping call: we map your ENX assessment scope to a day count and a fixed price, usually within one working day. Request a CREST penetration testing quote, tell us your assessment level and label deadline, and we will build the plan around it.

Leave a Reply

Your email address will not be published. Required fields are marked *