TISAX Registration (ENX Platform)
TISAX provides a structured method for assessing information security across the automotive supply chain. First, organisations set objectives, define scope, and choose confidentiality levels. As a result, OEMs and suppliers share clear expectations. Therefore, TISAX delivers recognised assurance, supports secure collaboration, and enables compliant data exchange across international manufacturing programmes.
What the ENX platform is and why it matters
The ENX platform is the official system for managing TISAX participation. Every organisation that wants a TISAX assessment must register on ENX before any audit can begin. This registration step formally confirms the organisation as a TISAX participant and allows assessment results to be shared securely with customers.
Without ENX registration, an organisation cannot receive a valid TISAX assessment or share results with OEMs and Tier 1 suppliers. This makes early registration an essential first step, especially where TISAX is a contract or RFQ requirement.
Setting objectives and defining scope
During registration, organisations must define their assessment objectives and assessment scope. These decisions shape how the assessment will be conducted and what the audit provider will review.
The assessment scope describes which locations, systems, people, and processes will be assessed. Any part of the organisation that handles or protects customer information must be included. A clear and accurate scope helps avoid later changes, delays, and extra audit work.
Assessment objectives describe the type of information being protected, such as confidential data or prototype information. These objectives determine the required assessment level and the depth of the checks to be applied.
Understanding Assessment Levels (AL)
TISAX uses Assessment Levels (AL) to match audit effort to information risk.
AL1 – Self‑assessment
AL1 is mainly for internal use. An auditor confirms that a self‑assessment exists, but does not review evidence in detail. AL1 results are not accepted by OEMs and are not used for official TISAX labels.
AL2 – Independent assessment
AL2 is the most commonly requested level by customers. It applies where information has high protection needs. The audit provider reviews evidence, checks the self‑assessment, and interviews key staff, usually remotely. AL2 results can be shared with customers through the TISAX Registration (ENX Platform).
AL3 – Full on‑site assessment
AL3 is required where protection needs are very high, such as strictly confidential data or prototype activity. The audit provider verifies controls in detail, including on‑site checks, observations, and interviews. AL3 provides the highest level of assurance and also meets AL2 requirements.
Choosing the correct assessment level is important. It must match customer expectations and the type of information being handled.
Secure sharing and recognised assurance
Once an assessment is complete, results are uploaded to the TISAX Registration (ENX Platform). Organisations control who can see their results and at what level of detail. This secure exchange enables OEMs and suppliers to rely on a single, recognised assessment rather than repeated audits.
Assessment results are normally valid for three years, giving confidence to customers across multiple projects and programmes.
Supporting global collaboration
By using a common platform and assessment approach, TISAX supports secure collaboration across international automotive supply chains. ENX registration ensures that expectations are clear, assessments are trusted, and data is exchanged consistently and securely.




