The Mercedes-Benz dealer ISO 27001 or TISAX Level 2 date of September 30, 2026 has passed, and what a store does next depends on whether it’s certified, mid-audit, or hasn’t started. Mercedes-Benz USA’s guidelines for dealers aren’t published, so check the wording in your own copy.
Last updated: October 11, 2026
Every deadline I’ve watched in this business goes the same way. For months before the date, everybody with something to sell is selling urgency. Then the date goes by, and the same people switch to selling rescue.
That’s about where Mercedes-Benz dealers are this month.
I started on a dealership sales floor in the late ’90s, sold CRM software to dealers for five years after that, and I’ve spent the last 20 at Helion Technologies. So I’ve sat on both sides of the pitch. This post is for the dealer principal or controller at a Mercedes-Benz store who wants to know what to do now that the date is behind us, without anybody’s hand in their pocket. Bias disclosed, by the way. We run cybersecurity for dealerships, and we don’t issue certificates. Nobody in my line of work can.
First, What We Actually Know
Not as much as the internet thinks. Back in January, our founder Erik Nachbahr wrote about why automakers are raising the dealership cybersecurity bar, and he reported that Mercedes-Benz USA’s Cyber Security Guidelines for Dealers ask a store to prove it has a working information security program through ISO/IEC 27001 or TISAX Level 2 certification by September 30, 2026.
Those guidelines go to dealers through Mercedes-Benz channels. They aren’t posted anywhere public, and I’m not going to quote a document you can’t check. Pull your own copy. Read the date, the accepted standards, and the scope in the factory’s words, because that copy is the one that counts and mine isn’t.
Same goes for consequences. You’ll find articles that lay out, step by step, what happens to a store that’s late. I haven’t seen one that cites the dealer agreement it’s describing. Your agreement says what it says. Ask your Mercedes-Benz USA contact, and ask in writing.
Carry other brands too? Our guide to OEM cybersecurity requirements for dealers covers what GM and other automakers ask for.

What the Mercedes-Benz Dealer ISO 27001 Requirement Asks a Store to Prove
The Mercedes-Benz dealer ISO 27001 requirement, as Helion reported it in January 2026, asks a franchised store to show an outside party that its information security program works. A store proves that one of two ways, with an ISO/IEC 27001 certificate from an accredited certification body or with a TISAX Level 2 assessment result.
The two aren’t the same animal. ISO/IEC 27001 is an international standard for an information security management system, and the certificate is good in any industry. TISAX is the auto industry’s own program, run by the ENX Association, and you share the result with the automaker through the ENX portal instead of mailing anybody a certificate. We put the two side by side in our ISO 27001 vs TISAX comparison for car dealerships, so I won’t redo that here.
What matters for this post is the thing they share. Somebody from outside your building looks at how the store really handles customer data. Not the binder. The store.
Three Places a Mercedes-Benz Store Can Be Right Now
Which one’s yours? Be honest about it, because the first move is different in each.
| Where the store stands | What that usually looks like | First move this month |
|---|---|---|
| Certified or labeled | An ISO/IEC 27001 certificate or TISAX labels were in hand before the date | Put the surveillance and renewal dates on a calendar and name who owns each one |
| Audit under way | An auditor is engaged, findings are open, and corrective actions have due dates | Tell your factory contact where you are, in writing, and keep every corrective action dated |
| Not started | No auditor, no gap list, and maybe a compliance product somebody bought in 2023 | Email your factory contact, then get a written gap list before you buy anything |
If Your Store Hasn’t Started
Late is a position. It’s not a verdict. But the order you do things in matters a lot from here, and most of the expensive mistakes I see dealers make with technology come from buying first and asking second.
- Write to the factory before you write a check. Ask your Mercedes-Benz USA contact where your store stands, which standards the current guideline accepts, and what timeline they’ll work with. Keep the reply.
- Read your own guideline for scope. Does it speak to each rooftop or to the group? TISAX scope is set by location, according to the TISAX Participant Handbook, so a three-store group isn’t automatically one assessment.
- Get a gap list. Dated, in writing, one line per finding. An auditor is going to ask about individual logins, multi-factor authentication, encryption, backups you’ve restored from, monitoring, and who can reach your data from outside, and you’d rather hear all of that first from someone who isn’t grading you.
- Fix the big ones, then let the fixes run. This is the part nobody can hurry. An auditor wants evidence that a control has been working for a while, and you can’t backdate a log.
- Book the auditor early. They have calendars too.
How long does all that take? Months. The ENX handbook says the stretch between an assessment kickoff and handing over the self-assessment is typically one to three months, and that six isn’t unusual. That’s one step. So when somebody offers to get your store certified in 30 days, ask which part they’re leaving out.

If Your Audit Is Under Way
You’re in better shape than it feels like. A store with an engaged auditor and a dated plan has something concrete to show, and that’s a different conversation with the factory than silence.
On the TISAX side, the handbook spells out how results work. An assessment ends as conform, minor non-conform, or major non-conform. With minor non-conformities and an accepted corrective action plan, a store can receive temporary TISAX labels while it finishes the work, and no corrective action can run longer than nine months from the closing meeting of the initial assessment. Nine months sounds generous until you remember that month-end, a sales event, and somebody’s vacation all land inside it. Don’t let the plan drift.
ISO/IEC 27001 certification runs in two stages, a review of your documentation and then an audit of how the system works in practice. Whether an open audit satisfies Mercedes-Benz USA for now is the factory’s call. Ask.
One practical thing. Send your factory contact a short status note with the auditor’s name, the stage you’re in, and your target date. Nobody asked for it? Send it anyway.
If You’re Already Certified
Congratulations. Now the work starts. I’m only half kidding.
Neither result is permanent. A TISAX result is valid for three years, and ENX recommends starting the renewal at least a year before the labels expire. An ISO/IEC 27001 certificate also runs three years, with a surveillance audit each year in between, which means an auditor is coming back whether the store has kept up or not.
What knocks a certified store off course is ordinary dealership life. The group buys a store, and the new rooftop isn’t in scope. The DMS changes. The person who owned the evidence file takes a job across town, and nobody inherits the folder. Six months later the access review that was supposed to happen every quarter has happened once. I’d put a name on each recurring task and a backup name next to it. Then check it.

Who’s Selling You What Right Now
Here’s where my years on the vendor side come in handy. After a deadline, a dealer’s inbox fills up, and it helps to know who can do what.
The auditor grades you. They can’t also be the one who builds your program. The standard that governs ISO certification bodies, ISO/IEC 17021-1, bars them from offering management system consulting, and the TISAX handbook says an audit provider that consults for you can no longer assess you. So if one company offers to fix everything and then certify it, something’s off.
Consultants write the policies and run the gap assessment. Some are good. A policy still doesn’t turn on multi-factor authentication at the parts counter.
Software that tracks compliance tasks is fine for tracking. It isn’t a security program, and an auditor can tell the difference in about ten minutes.
And then there’s your IT provider, which is us for a lot of stores. We can’t certify anyone either. What an IT and security team does is the work the auditor inspects, meaning the logins, the network, the monitoring, the backups, and the record that shows it’s all still running. The carrier that sells you internet and phones isn’t in this picture at all, whatever the bundle is called.
When a plan looks finished, I ask one question. What am I not doing? For most stores in this spot the answer isn’t another product. It’s that four vendors each own a slice, and nobody owns the whole thing. I think a dealer is better off with one partner handling infrastructure, security, and compliance together, because the auditor is going to ask about all three in the same meeting. That’s how we work. Helion Technologies has supported only dealerships since 1997, which today means 2,000-plus dealerships and 35,000 end users, a 98% client retention rate, and an average of 82 seconds to reach a support agent. Our IT services for dealer groups page explains how that runs across rooftops.
The Certificate Doesn’t Replace the FTC Safeguards Rule
Easy to forget. The Mercedes-Benz requirement comes from the factory. The federal one never went anywhere. The FTC’s Safeguards FAQs for automobile dealers say a dealer that finances or facilitates financing, or leases vehicles for longer than 90 days, is a financial institution under the rule, and 16 CFR 314.4 lays out what the written security program has to contain.
The good news is that it’s mostly the same work. A Qualified Individual, a written risk assessment, access controls, encryption, multi-factor authentication, testing, vendor oversight, and an incident response plan are all in the federal rule already. Our FTC Safeguards compliance program keeps that file current, and a store that runs it for real has most of what either audit asks to see.
Why do the automakers care this much? June 2024. When CDK Global went down, Group 1 Automotive told the SEC in an 8-K filing that the incident had disrupted business applications and processes across its US operations, and that its dealerships were conducting business using alternative processes. Alternative processes means pens. Every automaker watched its stores hand-write repair orders, and a dealer’s word on security got a lot less persuasive after that.

Questions Worth Settling Before You Call the Factory
Our store missed September 30. Is the franchise at risk?
Can our IT company just certify us?
Which path is quicker for a store that’s behind, TISAX or ISO 27001?
Only one of our five rooftops is a Mercedes-Benz store. Is the whole group on the hook?
Would a SOC 2 report do instead?
We passed. Can we stop thinking about it for three years?
Find Out Where the Store Stands
Certified, mid-audit, or not started, the first useful thing is the same. A written list of what an auditor would find, from someone who isn’t selling you the audit.
Our complimentary IT and cybersecurity assessment gives you that list for each rooftop. Bring your Mercedes-Benz USA guideline and we’ll line the findings up against it. Late can be fixed. Guessing can’t.

