TISAX-certified annotation platforms meet the information security requirements that European automotive OEMs and Tier-1 suppliers demand from vendors handling production vehicle sensor data. Kognic holds a current TISAX assessment and is ISO/IEC 27001:2022 certified, covering the full annotation pipeline from ingest through delivery.
TISAX (Trusted Information Security Assessment Exchange) is the German automotive industry's information security framework, governed by the ENX Association on behalf of VDA (Verband der Automobilindustrie, the German Association of the Automotive Industry).
It exists because automotive supply chains involve hundreds of vendors handling sensitive data: vehicle blueprints, prototype specifications, raw sensor recordings from test fleets, and customer information. Every OEM used to audit every vendor independently, which was duplicative and expensive. TISAX consolidated this into a single certification model. A vendor gets assessed once by an accredited auditor, and the result is recognized by all OEMs participating in the network.
TISAX is administered through the ENX portal. Assessments are performed by accredited audit providers and follow the VDA Information Security Assessment (ISA) catalogue, a structured set of controls covering information security, data protection, prototype protection, and connection security.
Autonomous driving programs generate enormous volumes of sensitive data. Camera footage, LiDAR point clouds, radar streams, and behaviour logs from test fleets fall under high-protection categories under the VDA ISA catalogue. They contain proprietary vehicle setups, identifiable individuals in some cases, and reveal the OEM's testing locations and strategies.
When an OEM contracts an annotation vendor, the vendor inherits responsibility for protecting that data through the full annotation pipeline: data ingest, annotator workstations, quality review systems, and delivery infrastructure. If any of those have weak controls, the OEM's data is at risk.
TISAX certification gives OEMs a single, recognized signal that the vendor meets the information security baseline. Most European OEMs now require TISAX certification before signing production contracts. Vendors without it are typically limited to non-sensitive pilot programs or simulation data.
For AV annotation specifically, the protected data tends to include:
TISAX defines three Assessment Levels, mapped to the protection needs of the data being handled:
A common misconception is that AL3 is the bar for every AV program. It is not. The level follows the protection class the OEM assigns to the data, and in practice most automotive scopes are set at AL2. AL1 is a self-assessment and rarely satisfies a production contract on its own. The practical question for a buyer is not "does this vendor have the highest level" but "does this vendor's assessment cover the level, scope, and labels my program actually requires".
Each assessment is valid for three years and must be renewed through the same process. Vendors must maintain controls between audits and can be subject to follow-up checks.
At AL2 and above a TISAX assessment is not a paper exercise. The auditor examines evidence across the full ISA catalogue, with specific focus on:
Governance and risk management. Information security policies, risk assessment processes, supplier management, incident response, and business continuity planning. The auditor verifies the policies exist, are followed, and are reviewed regularly.
Access control and identity management. Multi-factor authentication, least-privilege access, account lifecycle management, and audit logging. For an annotation vendor, this includes how annotator accounts are provisioned, what data each annotator can access, and how access is revoked.
Physical and environmental security. Office access controls, server room security, asset management, and clean-desk policies. For remote-first annotation operations, this extends to home office security and device management.
Operations security. Patch management, vulnerability scanning, malware protection, network segmentation, and secure development practices.
Data protection. Encryption at rest and in transit, data classification, retention policies, and secure deletion. For an annotation vendor, this includes how OEM data is stored, who can export it, and how it is destroyed after contract end.
Supplier and connection security. Third-party risk management and secure connections to OEM systems.
The auditor verifies each control through documentation review, technical testing, and interviews with personnel across multiple levels of the organization.
The number of annotation platforms holding any TISAX assessment is small. Most general-purpose labeling platforms (Scale AI, Labelbox, V7, SuperAnnotate) do not publicly list TISAX certification. CVAT is open-source and not a managed service. Annotation platforms focused on the European automotive market are the most likely to be certified.
Verifying current status is straightforward: the ENX portal at portal.enx.com/en-US/TISAX lets you search for a vendor by name and see their current assessment status, level, and the data labels included.
If you are evaluating annotation vendors for a European OEM program, ask each vendor for their TISAX scope ID and verify it directly. Don't rely on marketing pages that mention TISAX without specifying the assessment level or scope.
Kognic holds a current TISAX assessment. The scope covers the full annotation pipeline:
You can verify Kognic's current TISAX status, assessment level, and scope directly on the ENX portal, and we would rather you did that than take a marketing page at face value.
Alongside TISAX, Kognic is ISO/IEC 27001:2022 certified. The scope is the information security management system supporting the annotation platform for AD and ADAS model training and validation, including the cloud infrastructure it runs on. Between the two, Kognic meets the information security baseline that European OEMs and the Tier-1 suppliers in their supply chains apply to vendors handling production sensor data.
Four steps to verify before signing:
For some programs, OEMs additionally require a separate Data Protection (DP) label or a Connection-to-Third-Parties (CTP) label on top of the base assessment. Confirm with the OEM's procurement team what labels apply to your project before committing to a vendor.
TISAX (Trusted Information Security Assessment Exchange) is the German automotive industry's information security certification, governed by the ENX Association on behalf of VDA. It standardizes information security audits across automotive supply chains so that a single assessment is recognized by all participating OEMs. TISAX assessments are based on the VDA ISA catalogue and are performed by accredited auditors.
Kognic holds a current TISAX assessment covering the full annotation pipeline from ingest through delivery, and is ISO/IEC 27001:2022 certified. Most general-purpose labeling platforms do not publicly list any TISAX assessment, since their primary market is not European automotive. To verify any vendor's current TISAX status, level, and scope, search the ENX portal at portal.enx.com/en-US/TISAX with the vendor name.
TISAX defines three. AL1 is a self-assessment with no external audit. AL2 adds a plausibility check by an accredited auditor with remote evidence review and interviews, and is the level most automotive programs are scoped at. AL3 adds a full on-site audit with process observation, and applies where the data carries a very high protection need or the OEM specifically requires an on-site assessment. The level is determined by the protection class of the data in your program, not chosen by the vendor.
For production contracts with European OEMs handling sensitive vehicle data, TISAX is effectively required. Vendors without TISAX certification are typically limited to non-sensitive pilot work, public datasets, or simulation data. The exact requirement depends on the data classification of each project and the OEM's procurement standards.
TISAX certifications are valid for three years from the date of assessment. Renewal requires a new assessment cycle with the accredited auditor. Vendors must maintain the controls covered by the certification between audits and may be subject to follow-up checks.
ISO 27001 is the international standard for information security management systems, recognized across industries globally. TISAX is specific to the automotive industry and uses a control catalogue (VDA ISA) tailored to automotive supply chain requirements, including prototype protection and connection security. SOC 2 is a US attestation standard, most often asked for by North American enterprise buyers, that reports on how controls operated over a period rather than certifying a management system. ISO 27001 is the broadest, TISAX is the deepest for automotive, and SOC 2 is the one North American procurement teams tend to recognize. Kognic is ISO/IEC 27001:2022 certified and holds a current TISAX assessment.
Yes. TISAX is run by ENX in Germany but is open to vendors from any region. The assessment is performed against the same VDA ISA catalogue regardless of vendor location. US-based or other non-European annotation platforms can pursue and hold TISAX certification.
Search the ENX portal at portal.enx.com/en-US/TISAX with the vendor's name. The portal shows current assessment status, level, scope, and validity dates. Ask vendors to provide their TISAX scope ID directly. A vendor that cannot supply a scope ID likely does not hold a current certification.
Ready to learn more about how Kognic's TISAX-assessed, ISO 27001 certified annotation platform handles your production data? Book a demo or explore the Kognic annotation platform and our ADAS annotation capabilities.