Skip to content
Background Banner
TISAX Certification Cost: The Full Budget, Line by Line
TISAX®July 19, 2026 · Iulian Bozdoghina (Lead Auditor and Consultant) · 5 min read

TISAX® Certification Cost: The Full Budget, Line by Line

What TISAX certification actually costs: ENX fees, audit day rates, preparation, internal effort, and the expensive line nobody budgets for.

Iulian Bozdoghina
Iulian BozdoghinaLead Auditor and Consultant

Executive Summary

TISAX® certification costs between roughly 15,000 and 60,000 EUR for most suppliers, spread across five budget lines: the ENX registration fee (a one-time charge of a few hundred euros per location and scope under the official ENX price list), the audit provider (day rates of 1,200 to 1,500 EUR, with two to three audit days for a remote AL2 assessment and three to five for an on-site AL3), preparation support, internal staff effort, and technical remediation. The number moves most with scope: every additional site and every additional label adds audit days and fees. The line most budgets miss is the cost of not passing: follow-up assessments, corrective action plan assessments, and months of delay while a customer contract waits on a label. This article breaks down each line, what pushes it up or down, and where suppliers overspend.

The short answer, before the breakdown

A single-site SME pursuing one label at AL2 with a reasonable security baseline typically lands between 15,000 and 30,000 EUR all-in for the first cycle. A mid-market supplier with two or three sites, AL3, and real remediation work is more realistically in the 30,000 to 60,000 EUR range. Large multi-site enterprises can exceed 100,000 EUR. Labels are then valid for three years, and recertification typically runs 60 to 70 percent of the initial cost because the ISMS already exists.

Those ranges match what the market converges on and what we see in the engagements we run. The interesting part is not the range. It is which lines you control and which you do not.

Line 1: ENX registration, the fixed part

Registration on the ENX portal is the smallest and most predictable line. Under the official ENX price list, the standard model is a one-time fee per location and assessment scope, in the low hundreds of euros, with discounts as location count grows. There are no recurring portal fees for the validity period of your assessment. Companies planning twenty or more locations can ask ENX about the participation-based model, an annual flat fee covering unlimited locations and scopes.

This line is not where budgets are won or lost. It is listed first because it is the only one with an official price tag, and because procurement teams sometimes mistake it for the whole cost of TISAX. It is not. It is the entry ticket.

Line 2: the audit provider

ENX-approved audit providers price in day rates, and the market sits between 1,200 and 1,500 EUR per day. What varies is the number of days:

  • AL2 (remote): typically two to three audit days for one site with one label scope.
  • AL3 (on-site): typically three to five days for one site, plus the auditor's travel and accommodation.
  • Each additional site or label scope adds roughly one to two days.

This is why AL3 costs more than AL2. Not because the requirements are harder; both levels assess the same VDA ISA catalogue against the same target maturity. The difference is verification depth, and on-site verification takes more paid days. Our guide to TISAX AL2 vs AL3 covers how your customer's required labels, not your budget, determine which level you need.

Day rates vary 20 to 30 percent between providers for the same assessment. Getting two or three quotes against an identical scope description is the easiest money you will save in the whole project.

Line 3: preparation and consulting

This is the widest line, from zero (if you have a mature ISMS and internal expertise) to 30,000 EUR or more for a from-scratch build with heavy external support. What actually drives it:

  • Your starting point. A supplier holding ISO 27001 already covers most of the VDA ISA Information Security module; preparation shrinks to the automotive-specific gaps and maturity evidence. The ISO 27001 to TISAX control mapping shows exactly how far an existing ISMS carries you.
  • Which modules are in scope. Prototype protection and data protection labels add requirements that most general-purpose ISMS work never touched.
  • Evidence maturity. TISAX grades every control on a 0 to 5 maturity scale and expects level 3. Having a control is not the same as evidencing it consistently. Closing the evidence gap is where most preparation hours go.

A structured gap assessment at the start is the cheapest way to size this line honestly before you commit to it.

Line 4: internal effort, the line that hides

The largest cost in many projects never appears on an invoice: your own people's time. Gap analysis participation, policy work, awareness training, evidence collection, the self-assessment, and audit days themselves. For an SME, budget the equivalent of one dedicated person for the project duration; for larger scopes, a small project team. Projects run "on the side" of day jobs reliably take about twice as long, which has its own cost when an OEM deadline is attached.

Line 5: technical remediation

Whatever the gap assessment finds that is missing in the environment itself: MFA rollout, backup and recovery capability that survives an auditor's questions, network segmentation, access reviews, physical security at AL3 sites. This line is entirely a function of your current posture, which is why no honest article can give you a single number for it. For suppliers with a reasonable IT baseline it is often modest. For suppliers who deferred security investment for years, this line, not the audit, is the real cost of TISAX.

Our TISAX® and ISO 27001 experts help European automotive suppliers achieve compliance within 95 days.

The line nobody budgets: not passing

Here is the cost model most budgets skip. If the assessment ends with nonconformities, the process does not end; it extends. A corrective action plan assessment, follow-up assessment days at the same day rates, temporary labels at best while your permanent labels wait, and months of elapsed time. Meanwhile, the customer contract that triggered the whole project sits unsigned, which is the only line on this page that can be worth more than everything above it combined.

That is why the cheapest TISAX project is the one scoped and prepared to pass on the first attempt. It is also why we structure preparation around the assessment's actual pass criteria rather than generic security improvement. Better security is a side effect; the budget goal is one assessment, one pass, three years of validity.

The one lever that moves every line: scope

Every line above scales with scope. Each additional location adds registration fees and audit days. Each additional label can add module requirements and preparation work. The single most effective cost decision in a TISAX project is made before any of the spending starts: register only the locations and labels your customer actually requires. What OEM procurement really asks for, and how to read it off the contract, is covered in our guide to automotive supplier TISAX requirements. Companies with three or more sites and a centralised ISMS should also ask ENX about the simplified group assessment, which can reduce multi-site effort.

What the three-year cycle means for the budget

A TISAX label is valid for three years, and the spending is not evenly spread. Year one carries almost everything. Years two and three carry maintenance: keeping evidence current, internal audits, control operation. Then recertification arrives at roughly 60 to 70 percent of the initial cost, and it is cheaper still for suppliers who maintained their ISMS rather than letting it decay and rebuilding. When to start that clock, and what happens on the ENX portal if you miss it, is the subject of our TISAX recertification timeline guide.

Where to start

Before asking anyone for a quote, know your own gap. The self-service TISAX audit checklist scores your current posture against the VDA ISA control set and gives you a control-by-control read of where you stand, which turns every conversation that follows, with auditors and with us, into one about a defined amount of work instead of an open-ended range.

If you want the budget sized properly for your specific scope, labels, and starting point, book a gap assessment and we will map your posture against the labels your customer requires and give you a realistic cost and timeline instead of a bracket from the internet.

FAQ

How much does TISAX certification cost for a small company?

A single-site SME targeting one AL2 label with a reasonable security baseline typically spends 15,000 to 30,000 EUR in the first cycle across ENX fees, the audit, preparation, and internal effort. An existing ISO 27001 certificate pushes you toward the bottom of that range.

What does the ENX registration fee cost?

Under the official ENX price list, registration is a one-time fee in the low hundreds of euros per location and assessment scope, with volume discounts. Companies with twenty or more locations can ask about the annual participation-based model instead.

Is AL3 more expensive than AL2?

Yes, mainly through audit days. AL2 is a remote check of typically two to three days; AL3 adds on-site verification at three to five days plus auditor travel. The requirements themselves are the same VDA ISA catalogue at the same target maturity.

Does ISO 27001 certification reduce TISAX cost?

Considerably. An ISO 27001 ISMS covers most of the VDA ISA Information Security module, so preparation focuses on automotive-specific modules and maturity evidence. Running both programmes together typically saves 20 to 30 percent compared with two separate projects.

What does TISAX recertification cost after three years?

Typically 60 to 70 percent of the initial cost, because the ISMS exists and the work is delta review rather than build. Suppliers who maintain their ISMS through the cycle pay less than those who rebuild before each assessment.

What happens to the cost if we fail the assessment?

The process extends rather than ends: corrective action plan assessment, follow-up assessment days at normal day rates, and delay. The largest cost is usually commercial, the customer contract waiting on the label, which is why preparing to pass on the first attempt is the cheapest strategy.

Cost figures reflect market-typical ranges as of July 2026 and the current ENX price list; your audit provider quotes and your own gap determine the real number. This article is general information, not a quotation.

Iulian Bozdoghina

"Iulian Bozdoghina is a veteran cybersecurity strategist with over 15 years of experience in securing automotive supply chains and critical infrastructure. He specializes in TISAX®, ISO 27001, and the emerging NIS2/DORA regulatory landscape."

ISO 27001 Lead AuditorTISAX® SpecialistISO14001 AuditorISO42001 Auditor

Ready to get certified?

Book your free gap assessment today. Our experts will map your current posture against your target framework and give you a clear, honest roadmap to certification.

Book Free Gap Assessment

No commitment required • GDPR compliant • Strategy confirmed via secure link

Related Articles

Continue reading about similar cybersecurity and compliance topics.