Cybervize
Information security in the automotive industry

TISAX, IEC 62443 and NIS-2: one security function, one line of evidence.

Automotive is covered through the NACE category vehicles and components. TISAX is not a law but a contractual requirement OEMs place on their suppliers; UN R155 and R156 are type-approval obligations that bind vehicle manufacturers first, not automatically every tier-1 or tier-2 supplier. Our vCISO leads the implementation of the information security obligations from NIS-2 and TISAX and works with OdySecure, the security platform by Cybervize.

Book the NIS-2 risk check

NIS-2 classification: automotive

Classification
Annex 2 BSIG (Annex II), important entity
Size threshold
from 50 employees, or turnover and balance sheet each above €10M
Reporting deadlines
for a significant incident: 24 hours initial report, 72 hours follow-up, one month final report
Obligations
10 minimum measures under § 30 BSIG
Adjacent standards
TISAX via customer contracts, IEC 62443 for plant OT

Standard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.

Cybervize building blocks for automotive

Your vCISO works with OdySecure: ISMS, assessment (NIS-2 plus TISAX), TPRM and BCM on one data foundation. Especially relevant for automotive: TISAX mapping, multi-plant assessment, supplier tier logic.

Self-check available

NIS-2 maturity check: 30 questions, 10 §30 BSIG measures, instant traffic light

Free, no signup, around 5 minutes. Detailed evaluation by email if desired.

Start the check
More about Information security in the automotive industry

What NIS-2 and TISAX mean together for automotive in practice

On top of the classification above, OEMs and Tier-1/Tier-2 suppliers carry contractual TISAX requirements from the automotive supply chain. Four consequences of this dual regulation for OEM suppliers and plant operators. Sector alone is not enough: NIS-2 Annex II classification depends on size thresholds and concrete activity; TISAX remains a contractual requirement, not statute. The legally binding evaluation remains a matter for specialised counsel.

01

Important entity with reactive supervision

Annex II means lower sanctions than Annex I, but the same ten minimum measures per § 30 of the German BSI Act. Supervision is reactive but kicks in on incidents or audit findings.

02

TISAX as parallel security certification

TISAX (Trusted Information Security Assessment Exchange) is the industry standard for OEM suppliers. Audit levels 1 to 3 depending on protection needs. NIS-2 covers many TISAX requirements but not all, and vice versa.

03

OT in plants plus office IT in engineering

Production plants with OT (robotics, presses, paint shops) and engineering centres with CAD and product data have different risk profiles. Both belong in the NIS-2 scope.

04

Supply chain reciprocity

OEMs pass TISAX and NIS-2 requirements down to suppliers. Tier-1 suppliers pass them down to Tier-2 suppliers. Whoever sits in a supply chain receives the requirements contractually, even without being directly NIS-2-affected.

What applies in automotive, and what sits in the catalogue

Few suppliers face a single requirement. TISAX comes from customer contracts, IEC 62443 from plant OT, UN R155 and ISO/SAE 21434 from the vehicle, NIS-2 from law, each with its own system. In OdySecure they sit in one catalogue and share a data foundation instead of producing five separate evidence trails.

  • ISO/IEC 27001The shared language of the management system. The other catalogues map onto it where they overlap.123 records, reference
  • TISAX and VDA ISA 6A contractual requirement from manufacturers to their supply chain, not a law.43 records, reference
  • IEC 62443Security of production: zones, conduits and security levels per plant.37 records, reference
  • UN Regulation No. 155A cybersecurity management system of its own for type approval. It sits alongside the ISMS, not inside it. The catalogue tracks its requirements.14 records, full catalogue
  • ISO/SAE 21434Cybersecurity in the road vehicle, across the whole development cycle.11 records, reference
  • UN Regulation No. 156Management of software updates on the vehicle.10 records, full catalogue

Catalogue depth: “full” means a complete control catalogue, “reference” the structure with mapping onto your own measures. NIS-2 is added where the thresholds of § 28 BSIG apply. That classification is set out below.

Full catalogue with depth and type of assurance

Five minimum measures with automotive examples

Five NIS-2 minimum measures translated into automotive practice (with TISAX cross-reference).

01

Risk analysis for production and engineering

Risk register with plant OT (robotics, presses), engineering IT (CAD data, product IP) and office IT. Protection goals differ: production = availability, engineering = confidentiality, office = integrity.

02

Supply chain security with tier logic

Supplier inventory with tier classification and criticality. TISAX status of suppliers documented, alternative suppliers for single-source components identified.

03

Security in procurement of controllers and robotics

Procurement process with security requirements for new production assets, patch management with maintenance windows, remote-maintenance access for machine vendors documented.

04

Encryption for engineering data and product IP

CAD data and product IP encrypted at rest and in transit, key management documented, data classification aligned with TISAX protection levels.

05

Multi-factor authentication for engineering access

MFA for engineering workstations, cloud CAD platforms and supplier portals. Privileged accounts separated. Access rights recertified regularly.

Three requirements we keep meeting at automotive suppliers

Not a customer story, but recurring patterns from conversations with OT and security leads, alongside how the platform handles them.

Maturity across plants and lines

The requirement

Manufacturing across several sites means knowing the security posture of every plant, not just headquarters. Customer audits and OEM requirements ask about the site where the part is made. The review therefore has to exist per plant, on a fixed rhythm and against the same scale. Four plants assessing on their own produce four truths.

How the platform handles it

The cycle runs as a campaign across all sites, using the same question catalogue and scoring scale, for example along IEC 62443-2-1. Each plant sees its progress, the group level sees all of them side by side. The released snapshot freezes the state at the moment of release. In a customer audit you can evidence not only where you stand today, but where you stood two years ago and what changed since.

View the assessment module

Security by design in equipment procurement

The requirement

Production equipment runs ten years and more. Whatever was not required at specification time often cannot be retrofitted later. The usual flow has two stages: first clarify internally which security requirements apply to this machine, then walk through with the equipment supplier what they can meet. No supplier meets everything, and the remainder is what decides.

How the platform handles it

Both stages run as separate assessments with phase and section status, the questionnaires attach as documents. Internal clarification has to be complete before the supplier stage starts. Whatever the supplier cannot meet stays on record as a finding and becomes a compensating measure of your own, with an owner. That makes it possible to show why a machine runs despite a known gap and what was secured instead.

View the TPRM module

Metrics that land in the boardroom

The requirement

Security metrics rarely fail at measurement and almost always at translation. The board wants three numbers and a direction, ISMS management wants the structure behind them, the operational level wants to know which plant is stuck on what. On top of that, every organisation has its own vocabulary, and a tool that does not speak it will not be used.

How the platform handles it

Metrics are modelled canonically along ISO/IEC 27004, with the distinction between performance and effectiveness measurement and the chain from base measure to objective. Outward facing, the terms can be renamed per tenant: a terminology table maps the standard vocabulary onto the wording of the organisation. On the same data, three views are available, for the board, for ISMS management and for operations, per plant with a traffic light and a group rollup.

View the ISMS module

Why Cybervize fits automotive

The platform covers TISAX and NIS-2 from a single control set.

TISAX
audit levels 1 to 3 coverage
Multi-plant
group-wide rollout
NIS-2 + TISAX
from one control mapping
50
frameworks held as a catalogue

Frequently asked questions from automotive

TISAX covers many NIS-2 minimum measures, but not all. In particular BSI reporting obligations (24/72 hours), management accountability and the NIS-2-specific supply chain logic are not part of TISAX. OdySecure maps both from a single control set so duplicate work falls away.

Tier-2 suppliers receive NIS-2 and TISAX requirements contractually from Tier-1 suppliers or OEMs. In practice that means supplier questionnaires with similar depth to NIS-2 obligations, without being directly NIS-2-affected. Structured answers are a competitive matter.

Product IP and CAD data are engineering assets with the highest confidentiality classification. NIS-2 requires encryption, access control and documented data flows. TISAX has its own protection levels for "high" and "very high" confidentiality that map directly.

No. The platform allows differentiated maturity levels per plant. Older plants with legacy OT and greenfield plants with modern equipment have different risk profiles and compensating controls. Important is documentation of the differentiation, not one-size-fits-all.

The platform licence is priced by modules and digitally connected people, assessments by assessment units. Without a CISO of your own, a vCISO mandate from €3,600/month fills the role, with OdySecure included. A multi-plant rollout typically takes 16 to 20 weeks for three to five plants in Germany, longer for international subsidiaries. The risk check gives you a specific indication.

Classify NIS-2 and TISAX in 30 minutes

Free risk check with indicative NIS-2 classification, TISAX status indicator and path recommendation. Ideally with IT leadership or TISAX owner plus management board present.

Book the NIS-2 risk check

In scope? How you get to a provable security posture

If the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.

Book a vCISO callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT