NIS2 vs TISAX compliance gap analysis for automotive suppliers

Your TISAX Certificate Won’t Satisfy NIS2: The 4 Compliance Gaps Automotive Suppliers Must Close Before Enforcement

You passed your TISAX AL2 audit. Your OEM is satisfied, the ENX portal shows your label, and your documentation is solid. Then NIS2 Directive 2022/2555 arrives on your desk and the question becomes: how much of that work actually counts?

The answer is: most of it — with four specific exceptions that TISAX cannot close, regardless of your assessment level.

Automotive suppliers in the EU manufacturing sector (NACE code C29 — motor vehicles, trailers, and semi-trailers) fall under NIS2 as Important entities once they reach 50 employees or €10 million in annual revenue. That threshold covers the vast majority of Tier 1 and Tier 2 suppliers with active TISAX labels. Where TISAX and NIS2 overlap — and they overlap substantially — your existing VDA ISA documentation, controls, and audit evidence transfer directly to NIS2 purposes.

Where they do not overlap is precise and actionable. Four NIS2 obligations fall entirely outside VDA ISA scope: registering your entity with the national competent authority, notifying that authority of significant incidents under specific timelines, securing board-level approval and accountability under Article 20, and aligning with the technical benchmark that Commission Implementing Regulation (EU) 2024/2690 provides.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

This guide maps every VDA ISA domain to its corresponding NIS2 obligation, identifies each gap, and gives you the steps to close it.

Does NIS2 Apply to Your Organisation? A Quick Scope Check

The first question is not whether TISAX overlaps with NIS2 — it is whether NIS2 applies to your organisation at all. The answer depends on two cumulative criteria: sector and size.

Sector: Motor vehicles, trailers, and semi-trailers (NACE sector C29) appear in Annex II of the Directive. Manufacturers of electrical equipment and of computer, electronic, and optical products also fall within Annex II manufacturing sub-sectors. Annex II entities are classified as Important entities under Article 3(2) — subject to the same Article 21 security requirements as essential entities, but under lighter supervisory intensity and with lower maximum penalty ceilings. For context on which sub-sectors apply to your operations, our NIS2 scope guide for manufacturers covers the full Annex II classification tree.

Size: The medium-enterprise threshold is 50 or more employees, or annual turnover or balance sheet total exceeding €10 million. An Annex II manufacturer that crosses either threshold is in scope. Some member states have extended this — certain jurisdictions treat series motor vehicle production as a regulated activity regardless of company size — but the default EU threshold applies across most transpositions.

The critical difference from TISAX is that TISAX carries no regulatory size threshold. OEMs require TISAX certification from any supplier handling sensitive data, regardless of headcount. A supplier with 40 employees can hold an AL2 label and remain entirely outside NIS2. A supplier with 60 employees is both TISAX-certified and NIS2-obligated. For compliance purposes, these are separate determinations.

The penalty exposure at important entity level: Article 34(5) sets maximum fines for Important entity infringements at €7,000,000 or 1.4% of total worldwide annual turnover — whichever is higher. These figures apply specifically to breaches of Articles 21 (security measures) or 23 (incident reporting). Essential entities face higher ceilings: €10,000,000 or 2% under Article 34(4).

Criterion TISAX NIS2 (Annex II)
Trigger OEM contractual requirement Regulatory: Annex II sector + ≥50 employees or ≥€10M revenue
Assessment level AL2 (remote) / AL3 (on-site) Important entity (Annex II) or Essential entity (Annex I)
Governing body ENX Association (private) National competent authority (BSI, ANSSI, etc.)
Legal liability Contractual only Administrative fines + management personal liability
Max penalty Contractual consequences €7M or 1.4% worldwide turnover (Important entities)

Where TISAX Already Closes the Gap: The VDA ISA Control Overlap

VDA ISA’s 14 control domains provide thorough coverage of the technical and organisational security measures required by NIS2 Article 21. This is the good news, and it is substantial. Eleven of fourteen VDA ISA domains translate directly to Article 21(2) requirements, meaning your existing TISAX documentation — risk assessments, access control policies, incident procedures, BCM plans, and supplier security controls — constitutes valid compliance evidence for those areas before a national competent authority.

The table below maps each VDA ISA domain to its corresponding NIS2 Article 21(2) sub-paragraph. TISAX AL2 provides documented evidence for each area; AL3 adds on-site verification that controls are actively implemented rather than just documented.

VDA ISA Domain NIS2 Article 21(2) Coverage
1. Information Security Policies (a) Risk analysis and IS security Strong
2. Organisation of Information Security (f) Effectiveness assessment policies Adequate
3. Human Resource Security (g) Cyber hygiene and training; (i) HR security Strong
4. Asset Management (i) Asset management Strong
5. Access Control (i) Access control policies; (j) MFA Strong
6. Cryptography (h) Cryptography and encryption Strong
7. Physical and Environmental Security CIR 2024/2690 Annex §13 (reference) Strong
8. Operations Security (e) Network and IS security Adequate
9. Communications Security (e) Network security Adequate
10. System Development and Maintenance (e) Vulnerability handling and secure dev Strong
11. Supplier Security (d) Supply chain security Strong
12. Incident Management (b) Incident handling Partial — internal only, no authority notification
13. Business Continuity and Disaster Recovery (c) BCM, backup, DR, crisis management Strong
14. Compliance and Legal Requirements (f) Effectiveness assessment Adequate

Domain 12 is the only technical area where TISAX evidence is partial. VDA ISA requires detection, analysis, containment, and recovery procedures. It creates no obligation to notify a regulatory authority — which is exactly what Article 23 requires. The other three gaps lie entirely outside this table: they are not weaknesses in VDA ISA’s technical content but obligations the standard was never designed to create.

Gap 1 — Entity Registration (Article 3(4))

TISAX certification involves registering your company in the ENX portal, where OEMs can verify your label. That registration is private, OEM-facing, and contractual. It has no connection to the public authority registration that Article 3(4) of the NIS2 Directive independently requires.

Under Article 3(4), essential and important entities must submit the following details to their national competent authority:

  • Entity name
  • Address and updated contact information, including email addresses, IP address ranges, and telephone numbers
  • Relevant sector and subsector (Annex I or II reference)
  • Member States in which services are provided

Changes must be reported without delay and, in any event, within two weeks. This is an ongoing obligation, not a one-time submission. Article 3(3) required Member States to establish complete entity lists by 17 April 2025, with entities self-registering before that date. Several member states set earlier windows — the Czech Republic, for example, required manufacturers to register by December 31, 2025. If your organisation met the NIS2 threshold before these dates and has not yet registered, that gap is already open and carries direct enforcement risk.

The competent authority varies by member state. In Germany, registration goes to the BSI. In France, it is ANSSI. In Ireland, the NCSC. For automotive suppliers operating across multiple EU jurisdictions, you may face registration obligations in each country where you provide services — not only your member state of main establishment. Our entity registration guide covers the process and authority contacts across member states.

The registration obligation costs minimal effort to complete but carries significant enforcement risk if missed. It is also the starting point for the competent authority’s supervisory relationship with your organisation.

Gap 2 — Incident Notification to Authorities (Article 23)

VDA ISA Domain 12 provides a solid internal incident response framework: detection, classification, escalation, containment, recovery, and post-incident review. TISAX AL2 and AL3 both verify this process exists and functions. None of it extends to external regulatory notification, because TISAX was designed to satisfy OEM information security requirements — not EU regulatory obligations.

Article 23 of the NIS2 Directive creates a three-stage mandatory notification process that applies to every significant incident — one that is capable of causing severe operational disruption or financial loss for your organisation, or that could cause considerable material or non-material damage to others. A full walkthrough of notification requirements is covered in our Article 23 incident notification guide. The three stages are:

Stage 1 — Early warning (within 24 hours of becoming aware): Alert the CSIRT or national competent authority that the incident has occurred. At minimum, indicate whether a malicious act is suspected and whether the incident has potential cross-border impact. A full root-cause investigation is not required at this stage.

Stage 2 — Incident notification (within 72 hours): Submit an updated assessment covering the incident’s severity, impact, and indicators of compromise available at that point. This replaces the early warning and must be more substantive.

Stage 3 — Final report (within one month): Provide a detailed account of the incident type, root cause, mitigation measures applied, actual cross-border impact, and the outcome of your post-incident review.

The 24-hour early warning is the hardest operational requirement for TISAX-certified organisations to meet. TISAX incident procedures typically prioritise thorough internal classification before escalation. Under Article 23, regulatory notification must begin within 24 hours of awareness — while your internal investigation is still running. The two processes must run in parallel, not sequentially.

The practical implication: your existing TISAX incident response procedures need a separate notification track mapped to these three timelines. This track requires pre-approved notification templates for each stage, a named individual responsible for regulatory notification, and a documented escalation path that triggers the 24-hour clock correctly.

Gap 3 — Board and Management Liability (Article 20)

TISAX requires management commitment: senior leadership must authorise and sponsor the ISMS. VDA ISA scores management accountability as part of Domain 1 (Information Security Policies) and Domain 2 (Organisation of Information Security). But TISAX creates no personal liability for management. NIS2 does.

Article 20 creates a materially different obligation. Management bodies — at the level of the entity’s governing or executive leadership — must formally approve the cybersecurity risk-management measures required by Article 21. They must oversee implementation of those measures. And they can be held liable for infringements of Article 21 by the entity. For a full analysis of what this means for board-level roles, our board and director obligations guide covers the personal accountability framework under national transpositions.

Article 20 also requires Member States to ensure that management body members receive cybersecurity training, with the explicit purpose of giving them sufficient knowledge to identify risks and assess the impact of security practices on their organisation’s services. Member States must encourage entities to offer equivalent training to all employees on a regular basis.

Two concrete actions follow from this for TISAX-certified suppliers:

Board resolution: The management body must approve the cybersecurity policy and the Article 21 measures in documented form. A TISAX management review or ISMS scope document does not satisfy this requirement without explicit NIS2 framing, because the liability and approval context is different. The approval must be decision-level, recorded, and tied to the specific measures.

Training records: Evidence that management body members completed cybersecurity training covering NIS2 obligations, risk identification, and the impact of security measures on service delivery. This is a recurring requirement, not a one-time event.

The personal liability dimension is what distinguishes NIS2 from any contractual framework, including TISAX. Under national transpositions, management board members can face personal consequences — including temporary bans from holding management roles — for repeated or serious infringements. That exposure does not exist under the ENX framework.

Gap 4 — The CIR 2024/2690 Technical Benchmark

Commission Implementing Regulation (EU) 2024/2690 lays down detailed technical and methodological requirements for cybersecurity risk-management measures under NIS2. Its mandatory scope covers a specific set of entities: DNS service providers, TLD name registries, cloud computing providers, data centres, CDN providers, managed service providers, MSSPs, online marketplaces, social networking platforms, and trust service providers.

Automotive manufacturers and their Tier 1/2 suppliers are not on that list. CIR 2024/2690 does not directly bind you.

What it does provide is the most granular official interpretation of what “appropriate and proportionate” measures look like under Article 21 — developed in consultation with ENISA and the NIS Cooperation Group, drawing on ISO/IEC 27001, ETSI EN 319 401, and national standards. National competent authorities across the EU increasingly use its 13 Annex sections as the reference benchmark when assessing any NIS2 entity, regardless of sector. Our implementing regulation overview covers all 13 Annex sections in detail.

VDA ISA covers the same broad domains as the CIR Annex, but the CIR is more technically prescriptive in three areas relevant to automotive suppliers:

Access control and MFA (CIR Annex §11): The CIR specifies continuous authentication requirements and privileged account governance at a level of granularity that VDA ISA’s access control domain addresses more broadly. Where VDA ISA requires documented access rights with traceable assignments, the CIR Annex §11 specifies the controls around privileged accounts, session management, and the technical architecture of continuous authentication.

Logging and monitoring (CIR Annex §6): VDA ISA covers operational security including logging. The CIR Annex §6 specifies anomaly detection and SIEM-class monitoring requirements that go beyond the VDA ISA scope. If a national authority auditor uses the CIR as their benchmark, they may ask for evidence of structured anomaly detection that your TISAX documentation does not specifically demonstrate.

Cryptography (CIR Annex §9): Both VDA ISA and the CIR require documented cryptographic policies. The CIR Annex §9 is more specific on algorithm strength requirements and the key management lifecycle — areas where VDA ISA’s cryptography domain provides broader guidance without the same level of technical specification.

This gap is not a TISAX failure. VDA ISA was designed for automotive use cases — prototype protection, vehicle design confidentiality, supplier NDA management — and it excels in those areas. The CIR benchmark gap is a scope difference: VDA ISA was written for OEM supply chains, not for EU regulatory audits. Targeted documentation uplift in these three areas closes it without rebuilding your ISMS.

Your NIS2 Action Plan for TISAX-Certified Suppliers

The bulk of NIS2 compliance work — implementing and documenting the ten Article 21 security measures — is already complete for any supplier with an active TISAX AL2 or AL3 label. What remains is four targeted activities that sit outside VDA ISA scope.

Step 1 — Confirm your NIS2 scope: Verify that your organisation meets the size threshold (50+ employees or €10M revenue) and identify your entity classification. Most automotive Tier 1/2 suppliers qualify as Important entities under Annex II (NACE C29). Confirm whether any of your operations in Annex I sectors (for example, intelligent transport systems) would place part of your organisation in the Essential entity category.

Step 2 — Register with your national competent authority: Submit the Article 3(4) required information to the competent authority in each member state where you provide services. Check your member state’s registration window and deadline. If you missed the initial registration period, register immediately — late registration is substantially better than no registration from an enforcement perspective.

Step 3 — Build a parallel notification track: Draft an Article 23 notification procedure that runs alongside your existing TISAX incident response process. This track requires pre-approved notification templates for each stage (24h, 72h, and 1-month), a named individual responsible for triggering the regulatory notification, and a documented escalation path that starts the 24-hour clock correctly at the point of awareness, not at the conclusion of your internal investigation.

Step 4 — Secure board approval and training records: Present a formal board resolution approving your NIS2 cybersecurity measures under Article 20 and produce documented evidence that management body members completed cybersecurity training. The resolution and training records are both audit evidence under NIS2 that TISAX documentation does not contain.

None of these four steps require rebuilding your ISMS from scratch. Your TISAX controls, documentation, and AL2/AL3 audit evidence remain the foundation. These four activities complete the picture that NIS2 requires of Important entity automotive suppliers in EU.

Frequently Asked Questions

Does TISAX AL3 make your organisation an NIS2 Essential entity?
No. TISAX assessment levels and NIS2 entity classifications are entirely separate frameworks with no direct correspondence. AL3 is a higher-scrutiny audit under a private automotive standard. Essential entity status under NIS2 depends on sector (Annex I) and size (250+ employees or more than €50 million revenue) per Article 3(1) — not on any third-party certification, including TISAX.

Can you use your TISAX audit report as evidence for NIS2 compliance?
Yes, for Article 21 technical measures. Your TISAX documentation — risk assessments, access control policies, incident procedures, BCM plans, supplier security controls — constitutes valid compliance evidence for the eleven VDA ISA domains that map directly to Article 21(2) sub-paragraphs. It does not serve as evidence for entity registration under Article 3(4), regulatory incident notifications under Article 23, or board approval under Article 20. Those three gaps require separate NIS2-specific documentation.

Which national authority do I register with?
Under Article 3(4), you register in each member state where you provide services. Your primary registration goes to the competent authority in the member state of your main establishment. For suppliers operating across multiple EU countries, you may need separate registrations in each jurisdiction. Your national authority also determines your supervisory contact point for Article 23 notifications.

Does the size threshold apply to my group as a whole or to my individual legal entity?
The Article 3 thresholds apply to each legal entity individually, not to a consolidated group. A Tier 2 supplier with 60 employees that is a subsidiary of a large automotive group meets the threshold in its own right and must register and comply independently. Member state transpositions may introduce variations, so verify with the national authority in your jurisdiction.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. European Union. NIS2 Directive 2022/2555, Article 3: Essential and important entities. NIS-2-Directive.com.
  2. European Union. NIS2 Directive 2022/2555, Article 20: Governance. NIS-2-Directive.com.
  3. European Union. NIS2 Directive 2022/2555, Article 21: Cybersecurity risk-management measures. NIS-2-Directive.com.
  4. European Union. NIS2 Directive 2022/2555, Article 23: Reporting obligations. NIS-2-Directive.com.
  5. European Union. NIS2 Directive 2022/2555, Article 34: General conditions for imposing administrative fines. NIS-2-Directive.com.
  6. NISD2.eu. CIR 2024/2690 — NIS2 Technical Measures. NISD2.eu.
  7. Docusnap. TISAX Label and Level Explained: AL1, AL2, AL3 at a Glance. Docusnap.com.
  8. StrikeGraph. TISAX Levels Simplified: Differences, Preparations and Checklists. StrikeGraph.com.
  9. Havel & Partners. Impact of the NIS 2 Directive on the Automotive Sector. HavelPartners.blog.
  10. ISMS Lite. TISAX Certification: Requirements, Process, and Assessment for Automotive Suppliers. ISMSLite.de.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: