Automaker Security Requirements
ISO 27001 vs TISAX for Car Dealerships
Two ways to prove your store’s security program to an automaker, compared on who audits, what you get, the yearly upkeep and what your IT has to show.

ISO 27001 vs TISAX is a choice between two proofs of one security program. ISO 27001 is a certificate that works in any industry. TISAX is an automotive-only assessment run through the ENX Association. The controls overlap. The audits don’t.
Last updated: October 10, 2026
Why car dealerships are comparing ISO 27001 and TISAX at all
A year ago most dealers had never heard of either one. Then the automakers got involved. In January, Helion Technologies founder Erik Nachbahr wrote that Mercedes-Benz USA’s Cyber Security Guidelines for Dealers ask stores to prove their security program with ISO/IEC 27001 or TISAX level 2 by September 30, 2026. His read on why automakers are raising the bar was blunt. “An ISO or TISAX audit doesn’t ask, ‘Do you have a policy?’ It asks, ‘Show me how this policy is implemented, monitored, tested, and improved.'”
That’s the real shift. Not the acronym. For years a store could buy a compliance product, file the binder on a shelf in the controller’s office and move on, and nobody outside the building ever opened it or asked a single question about it. Now an outside auditor does. Most of what gets checked is the day-to-day work behind cybersecurity for dealerships, which is why this page looks at both options from the IT side instead of the paperwork side.
A note on sources. Automakers send security guidelines to dealers through factory channels and don’t publish them, so check the wording and dates in your own copy. Helion doesn’t issue ISO certificates or TISAX labels. Accredited auditors do.
ISO 27001 vs TISAX After September 30, 2026
The date has passed. If your store holds a certificate or a label, the job now is keeping it. If it doesn’t, the first call goes to your factory rep. Don’t guess.
What an automaker does about a late store isn’t public, and it can differ from one dealer agreement to the next, so anyone quoting you a penalty without having read your agreement is guessing too. We walk through the next steps in what Mercedes-Benz dealers should do now that the ISO 27001 and TISAX deadline has passed.
What we can say from the IT side is simpler. A store with a dated gap list, a named owner and three months of evidence is in a very different conversation than a store with nothing. Auditors read progress. So do factory reps.
Late is fixable. Silent isn’t.
June 2024
The CDK Global ransomware attack disrupted more than 15,000 dealerships across North America for days. Stores wrote repair orders and deals by hand.
After that, a dealer’s word on security stopped being enough.
September 30, 2026
The date in Mercedes-Benz USA’s dealer guidelines for proving a security program through ISO/IEC 27001 or TISAX level 2, as Helion reported in January.
The proof is an outside audit. Not a signed form.
Side by side
ISO 27001 vs TISAX, Compared Line by Line
Everything in this table comes from the bodies that run each program, as of October 2026, and it’s your automaker’s guideline that decides which one it accepts and at what level. Read that first. Our guide to OEM cybersecurity requirements for dealers covers what GM and Mercedes-Benz USA ask for.
| Topic | ISO/IEC 27001 | TISAX |
|---|---|---|
| What it is | An international standard for an information security management system. The current edition is ISO/IEC 27001:2022. | The Trusted Information Security Assessment Exchange, an assessment and sharing system built for the automotive industry. |
| Who runs it | Published by ISO and the IEC. | Governed by the ENX Association, using the ISA catalogue published by the German automotive association VDA. |
| Who audits you | An accredited certification body. | An audit provider approved by ENX. |
| What you get | A certificate you can show anyone. | TISAX labels. You share the result with the partners you pick through the ENX portal. |
| How scope works | You define the scope and choose from 93 reference controls in Annex A, with your reasons written down. | Scope is set by location. The assessment level follows how sensitive the data is, level 2 for high and level 3 for very high. |
| How the audit runs | Two stages. A documentation review, then an audit of how the system works in practice. | At level 2 the audit provider checks your self-assessment and evidence, with an interview that’s generally held by web conference. |
| How long it lasts | Three years, with a surveillance audit every year in between. | Three years. |
| Who recognizes it | Any industry. Lenders, insurers and other automakers all know it. | Automakers and their suppliers. |
Sources: ISO/IEC 27001:2022, ENX Association on TISAX and the TISAX Participant Handbook.
Before the auditor
Six Things ISO 27001 and TISAX Both Ask a Dealership to Prove
Pick either path and the same six questions land on your IT. None of them is new, because a dealership that finances or leases already owes most of this work under the FTC Safeguards Rule, the federal regulation that treats a car dealer as a financial institution.
Not sure how your store would answer? A complimentary IT and cybersecurity assessment gives you the list in writing.

Where Helion fits
The network, the logins, the monitoring and the evidence file. The auditor inspects that work. We do it.
Dealership audit readiness The same six questions on either path
1 Who owns security?
Both audits start with a name. The Safeguards Rule calls this person the Qualified Individual, and an outside provider can fill the role as long as someone at the dealership oversees them.
Put the name in writing. “The IT guy” won’t pass.
2 Is the risk assessment current?
A written one, with dates, built around your real risks. An assessment from two DMS vendors ago tells the auditor nobody has looked since.
Redo it after any big change. New store, new DMS, new lender portal.
3 Does everyone have their own login?
Shared logins at the parts counter and the service drive are where this usually breaks. Multi-factor authentication goes on anything that touches customer data.
Pull the user list. Count the names that left last year.
4 Is customer data encrypted and backed up?
Encryption at rest and in transit, plus backups that somebody has restored from on purpose. A backup nobody’s tested is a hope.
Write down the date of the last restore test.
5 Who’s watching the network?
Under 16 CFR 314.4, a store without continuous monitoring owes a penetration test every year and vulnerability scans every six months. Auditors want the reports. Not the invoice.
Keep the findings and the fixes together.
6 Which vendors can reach your data?
The DMS, the CRM, the F&I menu, the phone system and even the copier lease all count, because each one is a service provider you’re expected to vet before signing and then review again over time.
List them. It’s longer than you think.
Three Ways Dealerships Settle ISO 27001 vs TISAX
The dots show how much yearly upkeep each path carries.
TISAX level 2
Built for the auto industry. The result lasts three years and the automaker reads it in the ENX portal.
ISO 27001
A certificate that travels to lenders, insurers and other brands. An auditor comes back every year.
Both
ISO 27001 as the base with TISAX on top. More than a single store usually needs. Some large groups want it.
No path is wrong. A single-point store whose only ask comes from one automaker weighs this differently than a 30-rooftop group carrying six brands, two captive lenders and a cyber insurance renewal that already asks page after page of questions about controls every spring. Running IT for a dealer group? Settle it once at the group level, then apply it store by store.
What Helion Brings to a Dealership Security Audit
Helion runs hundreds of IT and cybersecurity assessments for dealerships every year, most of them for stores that aren’t clients yet, and the same gaps keep turning up no matter how big the group is or which brands it sells. Endpoint protection that’s installed but never configured. Vendor reports that look like monitoring and aren’t. An auditor finds those in an afternoon. Better that we find them first.
How Helion Gets a Dealership Ready for Either Audit
-
1
Complimentary assessment
We review the network, the logins, the security tools and the vendor list at each rooftop. You get the findings in writing.
-
2
Gap list
Findings get lined up against your automaker’s guideline and the Safeguards Rule. One list. Dated.
-
3
Fix and document
Individual logins, multi-factor authentication, encryption, backups and monitoring go in, and each change is written down as it happens.
-
4
Evidence on hand
When the auditor asks for last quarter’s access review, it’s there. No scramble.
Common Questions

Not sure where your store stands?
Start with a complimentary IT and cybersecurity assessment. You’ll know what an auditor would find before one shows up.
What’s the difference between ISO 27001 and TISAX?
Does US law require car dealerships to have ISO 27001 or TISAX?
If we already meet the FTC Safeguards Rule, are we covered?
Which one is easier for a single dealership?
How long does it take to get ready?
Our store missed the September 30, 2026 date. What now?
Does Helion certify dealerships for ISO 27001 or TISAX?
Pick the path your automaker accepts. Then make sure the IT under it can pass.
Get a Complimentary IT Assessment →