TISAX and MFA: What the Assessment Tests, and How Legacy Automotive Systems Pass

Table of contents
TISAX is not a statute. It is the automotive industry's assessment and exchange mechanism, administered by ENX and based on the VDA Information Security Assessment catalogue. In practice, that distinction does not make it optional: OEMs and tier-1 customers often require a valid TISAX label before sharing sensitive information or awarding work.
MFA fits into TISAX through access control, authentication, protection needs, and assessment evidence. The VDA ISA catalogue is mapped from ISO 27001 and ISO 27002 concepts, so the same authentication-risk logic applies: higher-protection information and privileged access need stronger controls.
Where TISAX MFA Questions Usually Appear
Automotive suppliers often have a mixed application estate. The corporate cloud systems may be modern, but the systems holding OEM-sensitive information can be older:
- PLM and engineering document systems.
- MES and plant web clients.
- Quality and logistics tools.
- Supplier collaboration portals.
- Prototype and project-data repositories.
- Homegrown applications used on the plant network.
These applications can fall within the assessment scope because they process, store, or provide access to sensitive automotive information.
What Assessors Want to See
TISAX assessors review whether the controls match the protection needs and the assessment objective. Useful MFA evidence includes:
- System inventory and scope mapping.
- Authentication configuration.
- MFA challenge proof.
- Privileged-user and remote-access controls.
- Exception and compensating-control records.
- Logs showing access decisions.
The practical risk is partial coverage. If only the easy SaaS estate has MFA, the system with OEM engineering data can still create an assessment issue.
How Datawiza Helps Automotive Suppliers
Datawiza Access Proxy enforces MFA before users reach protected web applications. It can sit in front of plant, engineering, supplier, and internal web systems without installing anything on the application.
Use your existing IdP, such as Entra ID or Okta, when workforce identity should govern access. Use Datawiza built-in MFA when supplier, partner, or plant-floor users are outside the IdP.
This gives automotive suppliers a faster way to close MFA coverage gaps before a TISAX assessment or customer review.
Sources Reviewed
FAQ
Does TISAX require MFA?
TISAX does not work like a simple regulation with one universal MFA sentence. Assessments use VDA ISA access-control and authentication expectations, and strong authentication is commonly expected for remote, privileged, and high-protection access.
Who needs a TISAX label?
Automotive suppliers and service providers may need a TISAX label when OEMs or tier-1 customers require proof of information security for sensitive collaboration.
Which systems get examined?
Systems inside the assessment scope, especially those handling OEM-sensitive information, engineering documents, plant operations, supplier collaboration, prototypes, or high-protection data.
How do legacy plant systems meet MFA expectations?
Enforce MFA at the access layer. Datawiza Access Proxy can protect the web application without changing the underlying system.



