ISO 27001 vs TISAX is the choice in front of every Mercedes-Benz dealer in the United States right now, and for most stores the honest answer is that either one satisfies the requirement, but only one of them fits how a dealership actually operates.
Mercedes-Benz USA requires its dealers to prove they run a qualified information security program, evidenced by either ISO/IEC 27001 certification or a TISAX Assessment Level 2 (AL2) assessment, by September 30, 2026. It is a contractual requirement, not a suggestion, and it applies at the store level rather than the group level.
If you have been handed a Cyber Security Guideline and a deadline and nobody has translated either into plain English, this article is for you. We will cover what each standard actually is, what each one costs, how long each takes, and how to pick the one that fits your store, so you can make the call without needing a security background.
Verify with your factory representative. OEM cybersecurity guidelines are issued through dealer channels rather than published publicly, and requirements and dates can change. Confirm the standard your manufacturer accepts and the date it applies in writing before you budget against it.
What Mercedes Is Actually Asking You to Prove
Before comparing the two standards, it helps to understand that both exist to answer the same question: can you show, with documented evidence, that customer data in your store is protected?
The Mercedes-Benz Cyber Security Guideline sets out controls that must be implemented, monitored, and evidenced. Neither standard lets you skip them. The difference is only in how you get them verified.
Here is what sits behind the requirement, in plain terms:
- Individual accounts and multi-factor authentication. Shared logins on the sales floor are the single most common finding. Every system holding customer data needs MFA, including remote access.
- Encryption of customer data. At rest on your servers and in transit whenever it leaves the building.
- Working, tested backups and a recovery plan. Not just backups that run, but backups somebody has restored from.
- Logging and monitoring. You need to be able to answer who accessed a customer record and when. If you have no continuous monitoring, Mercedes expects an annual penetration test by a certified professional instead.
- Access and vendor reviews, in writing. Removing accounts when staff leaves, reviewing who can see what, and holding a security file on every vendor touching your systems.
- Governance. A named security owner, written policies that describe what your people actually do, and the ability to coordinate a cyber event with the manufacturer.
None of that is optional under either path. Choosing between ISO 27001 and TISAX is a choice about the verification route, not about the work.
ISO 27001 vs TISAX: The Short Version
Here is the comparison most dealer principals want before they read anything else.
| TISAX Level 2 | ISO 27001 | |
| What it is | An automotive-industry assessment run through the ENX Association, based on the VDA-ISA catalog | A global certification for an information security management system (ISMS) |
| Who recognizes it | German OEMs and their supply chains: Mercedes-Benz, BMW, Volkswagen Group, Audi, Porsche, Stellantis | Everyone. Lenders, insurers, enterprise customers, and regulators worldwide |
| Who verifies you | An independent ENX-accredited TISAX Audit Provider | An accredited certification body, via a Stage 1 and Stage 2 audit |
| Typical dealership timeline | 8 to 9 months from a standing start | 7 to 11 months from a standing start |
| Typical all-in year-one cost, one rooftop | $85,000 to $140,000 | $85,000 to $150,000 |
| Validity | Three years, then reassessment | Three years, with an annual surveillance audit |
| Ongoing burden | Lower between assessments | Higher, because the ISMS must be demonstrably running all year |
| Best fit | Dealerships whose OEM relationships are the reason they are doing this at all | Dealer groups that also serve lenders, fleet clients, or partners outside automotive |
The one-line version: most dealerships should take TISAX, because it was designed for exactly this situation and asks for less year-round overhead.
What TISAX Level 2 Involves
TISAX, the Trusted Information Security Assessment Exchange, is the automotive industry’s own mechanism for checking information security once and sharing the result with many partners. It is governed by the ENX Association, and the control catalog it uses, VDA-ISA, is maintained by the German automotive industry association.
For a dealership, the path breaks into four stages.
1. Registration and Scoping
You register your location and scope with ENX, which currently costs EUR 405 net per location per scope, roughly $475, paid once rather than annually. Scoping matters more than it sounds. It determines which systems, departments, and locations are in play, and getting it wrong is the most expensive mistake in the whole program.
2. The Self-Assessment
You complete a detailed self-assessment against the VDA-ISA catalog, currently released as ISA 2027, scoring each control on a maturity scale. This is where most stores discover they meet fewer requirements than they assumed, particularly in logging, vendor management, and written evidence.
3. Remediation and Evidence
You fix the gaps and, just as importantly, you document that you fixed them. Evidence is the part dealerships consistently underestimate. An auditor does not accept “we do that.” They ask to see the signed access review from six months ago.
4. The Assessment
An independent ENX-accredited audit provider reviews your evidence and interviews your team. Depending on the result, you receive a TISAX label you can share with Mercedes through the ENX portal.
One detail worth knowing if you are short on time: if the assessor finds only minor non-conformities, you can agree a corrective action plan and receive a temporary TISAX label valid for up to nine months. It cannot be renewed, but it buys real breathing room while you close the remaining gaps.
What ISO 27001 Involves
ISO/IEC 27001 is the international standard for running an information security management system. Where TISAX asks “are these controls in place and working,” ISO 27001 asks “do you operate a system that keeps them in place and working, all year, and can you prove it.”
That difference is the whole story. ISO 27001 is broader and more portable, and it is also more work to maintain.
Here is what an ISO 27001 program requires from a dealership:
- A defined scope and boundary. Which locations, systems, and processes the certificate covers.
- A risk register and a statement of applicability. A living document explaining which of the standard’s controls apply to you and why.
- A named security owner and a management review cadence. Leadership has to demonstrably engage, not just sign off.
- Internal audits. You audit yourself, on a schedule, and record the findings.
- A Stage 1 and Stage 2 external audit. Stage 1 checks your documentation; Stage 2 checks whether reality matches it.
- Annual surveillance audits. Every year of the three-year cycle, at additional cost.
Choose ISO 27001 when the certificate does more than one job for you. If your group finances through lenders who ask for it, serves commercial fleet clients with their own vendor requirements, or has ambitions outside the franchise, the broader recognition can be worth the extra overhead. If Mercedes is the only reason you are here, it usually is not.
What Compliance Really Costs a Dealership
Dealers are rarely quoted a full number, so here is the honest structure. Costs land in three buckets, and only one of them goes to a consultant.
Bucket 1: Assessment and Certification Fees
These go to ENX and to your independent assessor or certification body. Nobody, including us, can issue your label or your certificate.
| Line item | Typical US cost |
| ENX registration (TISAX) | EUR 405 net (approx. $475) per location, per scope, once |
| TISAX AL2 assessment, independent provider | $5,000 to $15,000 |
| TISAX AL3 assessment, on-site | $12,000 to $25,000 |
| ISO 27001 Stage 1 plus Stage 2 audit | $10,000 to $30,000 |
| ISO 27001 annual surveillance audit | $4,000 to $9,000 per year |
Bucket 2: Remediation and Tooling
This is where the money actually goes, and it scales with how modern your IT already is. Multi-factor authentication, endpoint detection and response, backup and disaster recovery, logging and monitoring, data loss prevention, and cleaning up vendor access.
| Dealership profile | Year-one remediation range |
| Single rooftop, modern IT | $25,000 to $60,000 |
| Two to four rooftops, mixed systems | $50,000 to $100,000 |
| Larger group, fragmented IT | $100,000 and up |
Most of this spend you should own regardless. The FTC Safeguards Rule has required much of it from US dealers since June 2023.
Bucket 3: Professional Services and Internal Time
Somebody has to write the management system, run the gap assessment, build the evidence room, and prepare your team for the interview. For a single rooftop on the TISAX AL2 path, that work typically runs $55,000 to $65,000; for two to four rooftops, $65,000 to $80,000. An ISO 27001 path for a comparable store lands between $50,000 and $100,000 depending on scope.
Then there is internal time, which is the cost nobody budgets: policy review, decision-making, evidence collection, and audit meetings across departments.
All in, for a single rooftop already running reasonably modern IT, plan for $85,000 to $140,000 in year one. A two-week readiness check, typically $7,500 fixed, replaces that range with a real number before you commit to anything.
How Long Does It Take, and Can You Still Make the Deadline?
Realistically, a dealership starting from scratch needs eight to twelve months to reach a label or a certificate. That is not a sales timeline; it is the sum of a gap assessment, four to six months of remediation, evidence collection, a mock audit, and an assessor’s own calendar.
Which means the honest answer for anyone starting in mid-2026 is that you will not hold a label on September 30, and neither will anyone else who starts today.
What you can realistically have in place by the deadline:
- A completed readiness check. Two weeks. You hold a documented scope, a gap report, and a ranked roadmap.
- ENX registration completed and an accredited assessor booked. Assessor calendars are filling, and that queue only gets longer.
- Quick wins closed. MFA everywhere, shared logins eliminated, same-day offboarding in place. These are the findings that block assessments, and they are also the cheapest to fix.
- A funded, scoped, evidenced program visibly in flight, with dates.
Ask your factory representative, in writing, what they will accept as evidence of progress on September 30. A dealer with a documented plan and a booked assessment is in a materially different conversation than a dealer with nothing on paper.
Frequently Asked Questions
What is the difference between ISO 27001 and TISAX?
ISO 27001 is a global certification for an information security management system, issued by an accredited certification body and valid for three years with annual surveillance audits. TISAX is an automotive-specific assessment governed by the ENX Association and based on the VDA-ISA catalog, verified by an independent ENX-accredited audit provider. TISAX is narrower in recognition but lighter to maintain, which is why most dealerships choose it.
Is TISAX or ISO 27001 required by law for US dealerships?
Neither is required by law. Both are contractual requirements imposed by manufacturers, in this case Mercedes-Benz USA, which set a deadline of September 30, 2026. Separately, the FTC Safeguards Rule has been federal law for US dealers since June 2023 and requires many of the same controls, so the underlying security work is a legal obligation even though the certification is not.
How much does TISAX cost for a car dealership?
For a single rooftop with reasonably modern IT, plan for $85,000 to $140,000 all in during year one. That breaks down into roughly $55,000 to $80,000 in professional services, $5,500 to $15,500 in ENX registration and independent assessment fees, and $25,000 to $60,000 in tooling and remediation. A two-week readiness check, typically $7,500 fixed, gives you a firm number before you commit.
How long does TISAX Level 2 take?
Eight to nine months for a typical single-rooftop dealership starting from a standing start, and nine to eleven months for a group of two to four rooftops. The timeline is driven by remediation and evidence collection rather than by the assessment itself, which is usually a matter of days.
What happens if a dealership misses the Mercedes deadline?
Missing the deadline puts a documented non-compliance against the security clause in your dealer agreement and starts a notice-to-cure process. In practice, the friction shows up first in OEM program eligibility and portal access rather than in a formal letter. State franchise laws require good cause, written notice, and a cure period before termination, so this is a breach-and-cure situation rather than an overnight shutdown, but an uncured non-compliance is a live item at every renewal.
Can a dealership still get TISAX certified before September 30, 2026?
No dealership starting from scratch in mid-2026 will hold a full label by that date. What is achievable is being registered with ENX, scoped, gap-assessed, booked with an accredited assessor, and visibly remediating. If your eventual assessment finds only minor non-conformities, TISAX also allows a temporary label valid for up to nine months while you close a corrective action plan.
Choose Your Path with CyberGlobal by Your Side
A deadline you did not set, a standard nobody explained, and a number nobody will give you straight. That is a frustrating place to run a store from, and it is the position most dealer principals are in this summer.
It does not have to stay that way. Our team works on GRC and compliance programs every week, including third-party risk assessments, policy development, and the identity and access management work that sits at the heart of both standards. Where continuous monitoring is required, our Security Operations Center and penetration testing teams cover the rest. We have supported enterprise clients including Mercedes-Benz, and behind the certifications there are real people who will sit on your side of the table.
We are not your assessor, on purpose. The formal assessment has to be run by an independent provider, which means our only job is to get you ready and stand with you through every audit interaction, every step of the way. Let us be your ally in this one. Reach out today!
Secure Your Dealership With CyberGlobal
Two weeks and a fixed price replaces a scary range with a real number, a ranked roadmap, and a date you can plan against.