Bottom Line Up Front:
Mercedes-Benz now requires every dealership to meet a recognized security standard such as ISO 27001 or TISAX Level 2 by September 30, 2026. You are free to choose either path, and ITS has built a tool to help you decide which one is the better fit for your dealership.
This article explains:
You’ll get simple guidance, complete information, and a direct path forward.
Mercedes expects dealerships to implement a qualified information security program, such as ISO 27001 or TISAX Level 2. Their Cyber Security Guideline outlines several controls that must be implemented, monitored, and proven with documented evidence.
Here is what Mercedes expects:
Dealerships must be able to:
If you do not have continuous monitoring, Mercedes expects an annual penetration test performed by a certified professional (OSCP/OSCE).
Dealerships must review and maintain:
Dealers must maintain:
These requirements apply whether you choose ISO 27001 or TISAX. Evidence will be required in both cases.
Mercedes accepts either ISO 27001 or TISAX Level 2. The question becomes which path is more realistic for your dealership.
ISO 27001 is a global certification that proves you run a formal, documented information security program year-round.
You will need to:
TISAX is an automotive-specific assessment used across many OEMs.
At Level 2, you:
Most dealerships choose TISAX Level 2 because it is a lighter lift.
However, some choose ISO 27001 if they work with partners outside automotive or want a broader certification.
For most dealerships, the cost comes in three main categories: external assessments, remediation, and internal labor. Below is a complete breakdown so you can budget realistically.
This is where dealerships spend the most time and money. Typical ranges:
| Dealership Type | Remediation Range |
|---|---|
| Single rooftop, modern IT | $25,000–$50,000+ |
| Multi rooftop, legacy systems | $50,000–$100,000+ |
| Large group with fragmented IT | $100,000+ |
Expect to spend time on:
Step 1
Step 2
Step 3
Step 4
Talk with your compliance partner to confirm:
Output: A clear decision and a scoped plan you can execute without guessing.
A real gap analysis checks you against:
It should produce:
Output: A prioritized remediation roadmap with proof requirements.
Most dealerships need 8–12 months to be ready, so build:
Output: A realistic plan with no surprise costs or last-minute panic.
Execute remediation based on Mercedes priorities:
Output: You pass the assessment and stay compliant without restarting the project every year.
ITS has more than 20 years supporting dealerships with cybersecurity, compliance, and technology. We understand dealership operations, DMS systems, vendor environments, and OEM expectations.
ITS helps you:
Our focus is to make compliance practical, clear, and achievable for busy dealerships.
Use ITS’ Mercedes Compliance Framework Selector to see whether ISO 27001 or TISAX Level 2 is the better fit for your dealership:
If you want help completing the steps above or need guidance interpreting your Mercedes requirements, ITS can walk you through every part of the process.