Europe's automotive supply chain has spent a decade tightening its grip on data security, and the next milestone has a hard date attached to it. Mercedes-Benz has confirmed that its dealer and supplier network must demonstrate a certified information security programme — either ISO 27001 or TISAX Level 2 — by September 30, 2026. For anyone connected to the Mercedes-Benz ecosystem, this is no longer a "nice to have." It is a contractual condition of staying in business with one of the world's most recognisable car makers.
If that sentence made your compliance team sit up a little straighter, good. It should. Let's unpack exactly what is changing, why it matters so much to European suppliers and dealers, and how to get certification-ready before the clock runs out.
Why Mercedes-Benz Is Tightening the Screws on Cybersecurity
The automotive industry has learned some hard lessons about supply chain risk. The 2024 CDK Global ransomware incident, which knocked more than 15,000 dealerships offline across North America, is the case study every OEM security team now references. Attackers rarely go straight for a manufacturer's own network — they look for the weakest link, often a smaller partner with looser controls, and use that as a launchpad into the parent company's systems.
Mercedes-Benz's response mirrors what German OEMs have been doing for years through TISAX (Trusted Information Security Assessment Exchange), the automotive industry's shared assessment framework built by the VDA (German Association of the Automotive Industry) and operated by the ENX Association. TISAX already underpins security expectations across Volkswagen Group, BMW, Audi, Porsche and their extended supplier base, and Mercedes-Benz is now applying that same logic — verified, independent proof of security — to its own network rather than accepting self-attestations.
What the September 30, 2026 Requirement Actually Says
Mercedes-Benz is not mandating a single rigid path. Organisations in scope can satisfy the requirement in one of two recognised ways:
- ISO/IEC 27001 certification — the internationally recognised standard for building and operating an Information Security Management System (ISMS), applicable across any industry.
- TISAX Assessment Level 2 (AL2) — the automotive-specific assessment run through the ENX portal, built on the VDA-ISA control catalogue, which itself draws heavily on ISO 27001/27002 principles with automotive-specific additions such as prototype protection and connected-vehicle data handling.
Either path counts as evidence of a "qualified information security programme." What no longer counts is a checklist, a vendor questionnaire filled out by an internal team, or software that claims compliance without an independent audit trail. The deadline applies at an organisational level, and Mercedes-Benz — like Stellantis, which has set an identical September 30, 2026 deadline for its own supplier base — expects the certificate or TISAX label to be in hand, not "in progress," by that date.
Why This Matters More for European Suppliers Than It Might Seem
It's tempting to read "Mercedes-Benz dealer network" and assume this is a North American story. It isn't, not really. TISAX itself is a distinctly European mechanism, born in Germany and already deeply embedded in the operations of Mercedes-Benz, BMW, Volkswagen, Audi and Porsche's European supply chains. What is happening now is the same discipline being extended further down the chain and applied with a hard, enforced deadline rather than a soft recommendation.
For European Tier 1 and Tier 2 suppliers, marketing agencies handling prototype imagery, logistics partners, and IT service providers touching Mercedes-Benz data anywhere in the value chain, this is a signal worth reading closely: the era of "we'll get to it eventually" is over. Contracts are increasingly being written with certification as a condition precedent, not a follow-up item.
Quick fact: TISAX was established by the VDA in 2017 and is operated by the ENX Association, letting a supplier complete a single assessment and reuse the resulting label across multiple OEM relationships — instead of repeating the audit for every customer.
ISO 27001 or TISAX — Which Should You Choose?
This is the question every compliance lead is currently wrestling with, and the honest answer is: it depends on who you sell to.
- If your relationships extend beyond the automotive sector — to finance, healthcare, SaaS customers, or public sector contracts — ISO 27001 gives you a globally recognised certificate that opens doors well beyond Mercedes-Benz.
- If your business is automotive-specific and you already work with, or hope to work with, multiple German OEMs, TISAX lets you complete one assessment and share the resulting label across Mercedes-Benz, BMW, VW Group and others through the ENX portal — avoiding repeated audits for each relationship.
- Many organisations that already hold ISO 27001 find that TISAX readiness moves noticeably faster, since the risk assessment methodology, policies and core Annex A controls are already built and operating.
Timelines matter here too. Starting from scratch, most organisations need anywhere from four to twelve months to reach a TISAX label or ISO 27001 certificate, with the assessment itself typically booked weeks in advance. With September 30, 2026 on the calendar, the realistic window to start a programme from zero and still land the certification comfortably before the deadline is closing fast.
Getting Certification-Ready Without the Guesswork
The path to either certification generally follows the same shape: a gap assessment against the relevant control catalogue (ISO 27001 Annex A or VDA-ISA), remediation of the gaps that surface, implementation of documented policies and evidence trails, and finally the formal audit through an accredited certification body or an ENX-accredited TISAX audit provider.
Organisations that try to run this entirely in-house often underestimate how much evidence collection and internal alignment it takes to pass a Stage 1/Stage 2 ISO 27001 audit, or a TISAX AL2 assessment, on the first attempt. That is exactly the gap that specialist advisory firms exist to close. VISTA InfoSec's ISO 27001 Advisory & Certification service works alongside internal teams to design the ISMS, run the risk assessment, and prepare for Stage 1 and Stage 2 audits without forcing a generic template onto your business. For organisations that sell specifically into the German and European automotive supply chain, VISTA InfoSec's TISAX Audit & Certification practice in Germany runs VDA-ISA gap assessments, scopes the correct assessment level, and manages ENX portal registration end to end.
If you're still weighing which certification actually fits your business model, this detailed breakdown of TISAX vs ISO 27001 for automotive suppliers is a useful next read — it compares governing bodies, scope, cost drivers and typical timelines side by side.
The Bottom Line
September 30, 2026 is not a soft target — it's a contractual deadline set by one of the automotive world's most demanding customers, echoed almost identically by Stellantis. Whether your organisation ultimately pursues ISO 27001 or TISAX Level 2, the underlying message from Mercedes-Benz is the same one German OEMs have been sending their supply chains for years: prove it, don't just promise it. Suppliers and dealers who start their gap assessment now will spend 2026 building a defensible security programme. Those who wait may find themselves racing an audit calendar that has already filled up.
Need to know exactly where your organisation stands before September 30, 2026?
Top comments (0)