Automaker Security Requirements

ISO 27001 vs TISAX for Car Dealerships

Two ways to prove your store’s security program to an automaker, compared on who audits, what you get, the yearly upkeep and what your IT has to show.

Car dealership general manager and an information security auditor reviewing a printed checklist on a clipboard in a bright showroom

ISO 27001 vs TISAX is a choice between two proofs of one security program. ISO 27001 is a certificate that works in any industry. TISAX is an automotive-only assessment run through the ENX Association. The controls overlap. The audits don’t.

Last updated: October 10, 2026

A named security owner
A written risk assessment
Individual logins with MFA
Encryption and tested backups
Vendor access reviews
One program, proven two ways

Why car dealerships are comparing ISO 27001 and TISAX at all

A year ago most dealers had never heard of either one. Then the automakers got involved. In January, Helion Technologies founder Erik Nachbahr wrote that Mercedes-Benz USA’s Cyber Security Guidelines for Dealers ask stores to prove their security program with ISO/IEC 27001 or TISAX level 2 by September 30, 2026. His read on why automakers are raising the bar was blunt. “An ISO or TISAX audit doesn’t ask, ‘Do you have a policy?’ It asks, ‘Show me how this policy is implemented, monitored, tested, and improved.'”

That’s the real shift. Not the acronym. For years a store could buy a compliance product, file the binder on a shelf in the controller’s office and move on, and nobody outside the building ever opened it or asked a single question about it. Now an outside auditor does. Most of what gets checked is the day-to-day work behind cybersecurity for dealerships, which is why this page looks at both options from the IT side instead of the paperwork side.

A note on sources. Automakers send security guidelines to dealers through factory channels and don’t publish them, so check the wording and dates in your own copy. Helion doesn’t issue ISO certificates or TISAX labels. Accredited auditors do.

ISO 27001 vs TISAX After September 30, 2026

The date has passed. If your store holds a certificate or a label, the job now is keeping it. If it doesn’t, the first call goes to your factory rep. Don’t guess.

What an automaker does about a late store isn’t public, and it can differ from one dealer agreement to the next, so anyone quoting you a penalty without having read your agreement is guessing too. We walk through the next steps in what Mercedes-Benz dealers should do now that the ISO 27001 and TISAX deadline has passed.

What we can say from the IT side is simpler. A store with a dated gap list, a named owner and three months of evidence is in a very different conversation than a store with nothing. Auditors read progress. So do factory reps.

Late is fixable. Silent isn’t.

June 2024

The CDK Global ransomware attack disrupted more than 15,000 dealerships across North America for days. Stores wrote repair orders and deals by hand.

After that, a dealer’s word on security stopped being enough.

September 30, 2026

The date in Mercedes-Benz USA’s dealer guidelines for proving a security program through ISO/IEC 27001 or TISAX level 2, as Helion reported in January.

The proof is an outside audit. Not a signed form.

Side by side

ISO 27001 vs TISAX, Compared Line by Line

Everything in this table comes from the bodies that run each program, as of October 2026, and it’s your automaker’s guideline that decides which one it accepts and at what level. Read that first. Our guide to OEM cybersecurity requirements for dealers covers what GM and Mercedes-Benz USA ask for.

TopicISO/IEC 27001TISAX
What it isAn international standard for an information security management system. The current edition is ISO/IEC 27001:2022.The Trusted Information Security Assessment Exchange, an assessment and sharing system built for the automotive industry.
Who runs itPublished by ISO and the IEC.Governed by the ENX Association, using the ISA catalogue published by the German automotive association VDA.
Who audits youAn accredited certification body.An audit provider approved by ENX.
What you getA certificate you can show anyone.TISAX labels. You share the result with the partners you pick through the ENX portal.
How scope worksYou define the scope and choose from 93 reference controls in Annex A, with your reasons written down.Scope is set by location. The assessment level follows how sensitive the data is, level 2 for high and level 3 for very high.
How the audit runsTwo stages. A documentation review, then an audit of how the system works in practice.At level 2 the audit provider checks your self-assessment and evidence, with an interview that’s generally held by web conference.
How long it lastsThree years, with a surveillance audit every year in between.Three years.
Who recognizes itAny industry. Lenders, insurers and other automakers all know it.Automakers and their suppliers.

Sources: ISO/IEC 27001:2022, ENX Association on TISAX and the TISAX Participant Handbook.

Before the auditor

Six Things ISO 27001 and TISAX Both Ask a Dealership to Prove

Pick either path and the same six questions land on your IT. None of them is new, because a dealership that finances or leases already owes most of this work under the FTC Safeguards Rule, the federal regulation that treats a car dealer as a financial institution.

Not sure how your store would answer? A complimentary IT and cybersecurity assessment gives you the list in writing.

Dealership controller and IT manager reviewing a printed security policy binder and paper checklists at a conference table

Where Helion fits

The network, the logins, the monitoring and the evidence file. The auditor inspects that work. We do it.

Dealership audit readiness The same six questions on either path

1 Who owns security?

Both audits start with a name. The Safeguards Rule calls this person the Qualified Individual, and an outside provider can fill the role as long as someone at the dealership oversees them.

Put the name in writing. “The IT guy” won’t pass.

2 Is the risk assessment current?

A written one, with dates, built around your real risks. An assessment from two DMS vendors ago tells the auditor nobody has looked since.

Redo it after any big change. New store, new DMS, new lender portal.

3 Does everyone have their own login?

Shared logins at the parts counter and the service drive are where this usually breaks. Multi-factor authentication goes on anything that touches customer data.

Pull the user list. Count the names that left last year.

4 Is customer data encrypted and backed up?

Encryption at rest and in transit, plus backups that somebody has restored from on purpose. A backup nobody’s tested is a hope.

Write down the date of the last restore test.

5 Who’s watching the network?

Under 16 CFR 314.4, a store without continuous monitoring owes a penetration test every year and vulnerability scans every six months. Auditors want the reports. Not the invoice.

Keep the findings and the fixes together.

6 Which vendors can reach your data?

The DMS, the CRM, the F&I menu, the phone system and even the copier lease all count, because each one is a service provider you’re expected to vet before signing and then review again over time.

List them. It’s longer than you think.

Three Ways Dealerships Settle ISO 27001 vs TISAX

The dots show how much yearly upkeep each path carries.

1

TISAX level 2

Built for the auto industry. The result lasts three years and the automaker reads it in the ENX portal.

2

ISO 27001

A certificate that travels to lenders, insurers and other brands. An auditor comes back every year.

3

Both

ISO 27001 as the base with TISAX on top. More than a single store usually needs. Some large groups want it.

No path is wrong. A single-point store whose only ask comes from one automaker weighs this differently than a 30-rooftop group carrying six brands, two captive lenders and a cyber insurance renewal that already asks page after page of questions about controls every spring. Running IT for a dealer group? Settle it once at the group level, then apply it store by store.

What Helion Brings to a Dealership Security Audit

82 sec Average time to reach a support agent
98% Client retention rate
2,000+ Automotive and heavy truck dealerships
1997 Working only with dealerships since

Helion runs hundreds of IT and cybersecurity assessments for dealerships every year, most of them for stores that aren’t clients yet, and the same gaps keep turning up no matter how big the group is or which brands it sells. Endpoint protection that’s installed but never configured. Vendor reports that look like monitoring and aren’t. An auditor finds those in an afternoon. Better that we find them first.

How Helion Gets a Dealership Ready for Either Audit

  1. 1

    Complimentary assessment

    We review the network, the logins, the security tools and the vendor list at each rooftop. You get the findings in writing.

  2. 2

    Gap list

    Findings get lined up against your automaker’s guideline and the Safeguards Rule. One list. Dated.

  3. 3

    Fix and document

    Individual logins, multi-factor authentication, encryption, backups and monitoring go in, and each change is written down as it happens.

  4. 4

    Evidence on hand

    When the auditor asks for last quarter’s access review, it’s there. No scramble.

Common Questions

IT technician unlocking a network cabinet with a key in a car dealership back office while a manager holds a paper inventory list

Not sure where your store stands?

Start with a complimentary IT and cybersecurity assessment. You’ll know what an auditor would find before one shows up.

What’s the difference between ISO 27001 and TISAX?
ISO 27001 is an international certificate for a security management system that any industry recognizes, while TISAX is an automotive-only assessment governed by the ENX Association. TISAX grew out of ISO 27001, so the controls overlap heavily. What differs is who audits you, how the result gets shared and whether an auditor returns every year.
Does US law require car dealerships to have ISO 27001 or TISAX?
No. The federal rule for dealerships that finance or lease is the FTC Safeguards Rule, and it doesn’t name either one. An ISO 27001 or TISAX requirement comes from an automaker, through its dealer guidelines.
If we already meet the FTC Safeguards Rule, are we covered?
Not automatically, though you’re a lot closer than a store starting cold. The Safeguards Rule has no certificate and no outside auditor, so an automaker can’t check it the way it checks a TISAX label. The good news is that a real Safeguards program already holds most of the evidence both audits ask for. Same work. New reader.
Which one is easier for a single dealership?
Usually TISAX level 2. The audit provider checks your self-assessment and evidence, the interview is generally held by web conference, and the result runs three years without a yearly surveillance audit. ISO 27001 asks more of you each year and gives you a certificate that works outside automotive.
How long does it take to get ready?
Months, not weeks. The audit itself is the short part. Most of the calendar goes to fixing what the gap list turns up and then running the fixed process long enough to build up evidence that it works the way the written policy says it does. Nobody can rush that part.
Our store missed the September 30, 2026 date. What now?
Call your factory rep and ask where you stand, in writing. Then get a dated gap list and start closing it. Nobody outside your dealer agreement can tell you the consequence, so skip the guessing and build the record.
Does Helion certify dealerships for ISO 27001 or TISAX?
No, and no IT provider can. ISO 27001 certificates come from accredited certification bodies, and TISAX assessments come from audit providers approved by ENX. Helion runs the managed IT, the security controls and the evidence those auditors inspect.

Pick the path your automaker accepts. Then make sure the IT under it can pass.

Get a Complimentary IT Assessment →