Skip to main content
General

The 5 Best TISAX® Tools from Germany for 2026

Five TISAX® tools from Germany compared: TISAX relevance according to the vendor, integration and selection criteria for preparing a TISAX assessment.

Srdan ManasijevicCEO, fuentis AG5 min read
Contents
  1. What Should a TISAX Tool Deliver?
  2. Which TISAX Tools from Germany Are There in Comparison?
  3. Which TISAX Tool Fits Which Situation?

Five TISAX® tools from Germany are fuentis, DataGuard, secjur, Secfix and verinice. They support TISAX assessment preparation by bundling requirements, evidence and measures. They do not award a TISAX label: it arises only from an assessment by an audit provider approved by ENX and is valid for three years.

According to ENX (December 2025), more than 20,000 locations worldwide hold a valid TISAX label. With ISA2027, a new assessment catalog has been available since July 2026, and a tool should be able to map the current catalog.

The selection is editorial: it covers vendors based in Germany that mention TISAX on their own website. The publisher of this blog is itself the vendor of the fuentis Suite and lists it first. There is no business affiliation between the publisher of this blog and the ENX Association. Information on the other tools comes from their official websites (as of October 2026).

What Should a TISAX Tool Deliver?

TISAX is not a certification but an assessment: according to ENX, those who pass it receive a TISAX label that is valid for three years. A tool keeps requirements, evidence and measures in one place, making assessment preparation plannable. It does not replace the assessment.

According to ENX, the VDA ISA2027 assessment catalog was published in July 2026, and the German version ISA2027.1 has been available since 1 October 2026. Participation runs through ENX, and assessments are carried out by audit providers approved by ENX. The scope covers all areas of the company that process information classified as confidential from business partners in the automotive industry. How the standard relates to ISO 27001 is explained in the article on the difference between ISO 27001 and TISAX®.

Which TISAX Tools from Germany Are There in Comparison?

The comparison covers what each vendor states about TISAX on its own website and how the tool is integrated: platform, deployment, support. Quality or suitability is not evaluated. The assessment checks TISAX compliance, not the tool, and the information comes from the vendors.

ToolTISAX® relevance according to the vendorIntegration
fuentisTISAX® in the Catalog Manager, documentation, audit readinessPart of the fuentis Suite; SaaS, private cloud or on-premise (Enterprise)
DataGuardPreparation for the TISAX® assessment, support from analysis to audit preparationPlatform plus expert support
secjurTISAX® named as an implementable standardDigital Compliance Office: policies, risk assessments and evidence in one place
SecfixTISAX named alongside ISO 27001 and SOC 2Offices in Berlin and Munich according to its own website
veriniceDedicated VDA ISA pageOpen-source license according to the vendor; cloud or on-premise

The Catalog Manager from fuentis manages TISAX®, BSI IT-Grundschutz, ISO 27001 and custom catalogs in one system: no media breaks, no duplicate maintenance. The fuentis TISAX® page cites automated documentation and continuous audit readiness in the automotive supply chain. More on the Catalog Manager can be found on the product page.

According to its own TISAX page, DataGuard is based in Munich. According to the vendor, the platform automates up to 75% of documentation. Experts provide support as needed, from the initial analysis through audit preparation to the long-term maintenance of the ISMS.

secjur GmbH, based in Hamburg (according to its legal notice), states on the secjur homepage that it helps implement compliance standards such as NIS2, ISO 27001 or TISAX® effectively. According to the secjur blog, the Digital Compliance Office manages policies, risk assessments and evidence in one place instead of in Excel spreadsheets.

On the Secfix website, Secfix names TISAX alongside ISO 27001 and SOC 2 and lists offices in Berlin and Munich.

verinice is published by SerNet GmbH. The website has a dedicated VDA ISA page. There is a client and the verinice.PRO Server, available as an evaluation or full version via verinice.SHOP. According to the vendor, the license is open source; it is operated in the cloud (verinice.cloud) or on-premise (verinice.onprem).

The author's view on how the choice plays out:

A piece of evidence, such as an approved policy, answers one question in the VDA ISA and a control in ISO 27001 at the same time. Those who maintain it only once and link it in both places do not have to reassemble it for the assessment. Whether a tool delivers this matters more than catalog size.

Srdan Manasijevic, CEO fuentis

Which TISAX Tool Fits Which Situation?

What matters: the assessment level required by the client, scope and number of locations, operating model (SaaS, private cloud, on-premise) and need for support. Level and audit provider are set not by the tool but by the client together with ENX.

Our own assessment, based solely on the vendors' statements:

  1. Operating model: fuentis names SaaS, private cloud or on-premise; verinice also names cloud or on-premise.
  2. Support: DataGuard names expert support from analysis to audit preparation.
  3. Multiple standards: secjur (NIS2, ISO 27001) and Secfix (ISO 27001, SOC 2) name TISAX alongside other standards. In the Catalog Manager, fuentis manages TISAX®, BSI and ISO 27001 in one system.
  4. License model: according to the vendor, verinice names an open-source license and offers an evaluation version for testing.

Which standard your company actually needs is covered in ISO 27001 or TISAX®: Which Standard Fits?. For a broader overview, see the comparison of ISMS tools from Germany.

First clarify the required assessment level and your scope with your client. How the fuentis Suite maps TISAX in the Catalog Manager, we will show you in a demo.

TISAX® is a registered trademark of the ENX Association. fuentis has no business affiliation with the ENX Association and is not an audit provider approved by ENX. The fuentis Suite supports preparation for TISAX® assessments.

Srdan Manasijevic

CEO, fuentis AG

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI standards and modern risk-analysis methods.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.