TISAX and the VDA ISA catalogue — what it asks and what counts as evidence
VDA ISA is the questionnaire the German automotive industry hands to its suppliers. If you process a manufacturer's development data, prototypes or personal data, you will be asked for it — usually with a deadline, and usually before the contract is signed.
In short
VDA ISA differs from CAIQ, SIG or VSA in one fundamental way: it does not ask whether a control exists, but how mature it is. Every question is rated on a maturity scale and held against a target level. A TISAX label needs maturity level 3 throughout — established, consistently followed and demonstrably tested. A yes without a lived process does not clear that bar.
TISAX / VDA ISA at a glance
| Published by | The VDA publishes the ISA catalogue; the ENX Association runs the TISAX process and issues the labels. |
| Assessment basis | VDA ISA 6.0; version 6.0.2 has applied to newly commissioned assessments since 1 April 2024. |
| Modules | Information security as the mandatory base module, plus prototype protection and data protection depending on what you handle. |
| Rating | Maturity levels instead of yes/no: 0 Incomplete, 1 Performed, 2 Managed, 3 Established, 4 Predictable, 5 Optimizing. |
| Assessment levels | AL1 as a self-assessment, AL2 external with a plausibility check, AL3 external with an on-site audit. Manufacturers frequently require AL3. |
| Validity | A TISAX label is valid for three years; ENX requires an annual self-declaration in between. |
How the file is put together
The catalogue arrives as a workbook, and its quirks decide how much work answering it actually is.
What Compliance Concierge does with a TISAX / VDA ISA
None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.
This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case. TISAX® and ENX are registered trademarks of ENX Association; VDA ISA is published by the German Association of the Automotive Industry. Compliance Concierge is affiliated with neither organisation and uses both names descriptively only.
The control areas — and the four where suppliers get stuck
The catalogue groups its questions by control area. Four of them cost the most time in practice, because they do not ask for a document but for a process that demonstrably runs.
Information security management
- What it asks
- Whether policies, named roles and a documented ISMS exist — and whether management demonstrably backs them.
- What answers it
- Information security policy with an approval date, role description with the named holder, minutes of a management review.
- Common mistake
- Submitting a policy nobody has touched since it was written. Level 3 requires a lived process; a document without a review cycle evidences level 1.
Access control
- What it asks
- About the access concept, the need-to-know principle, and multi-factor authentication requirements.
- What answers it
- Authorisation concept, proof of recurring recertification, configuration evidence for multi-factor authentication.
- Common mistake
- Reporting multi-factor authentication as present without saying for which systems. The question is about scope, not existence.
IT operations and network security
- What it asks
- About patch management, network segmentation and backup — each with a cadence and an owner.
- What answers it
- Patch policy with deadlines by criticality, network diagram showing segment boundaries, backup concept with a documented restore test.
- Common mistake
- Confirming backups without ever having tested a restore. That test is the difference between level 2 and level 3.
Incident management and business continuity
- What it asks
- About the incident process, reporting paths and recovery plans.
- What answers it
- Incident process with escalation stages and deadlines, continuity handbook, records from the last exercise or a real incident.
- Common mistake
- Describing a process that has never been exercised. What is asked for is evidence that it worked when it mattered.
The remaining control areas
- 2 Personnel security
- 3 Asset management
- 5 Cryptography and physical security
From 1 January 2027, newly starting assessments run against VDA ISA 2027. Prototype protection is fully revised, references are aligned with ISO/IEC 27001:2022 and extended with a NIST CSF 2.0 mapping. The change that matters most to suppliers: control 1.2.4 moves to 6.1.3 and thereby into a dedicated supplier management area — the same movement NIS2 sets off. Whoever answers questionnaires today will, from 2027, also be passing them on to their own sub-suppliers.
Frequently asked
What is the difference between TISAX and VDA ISA?+
VDA ISA is the questionnaire; TISAX is the process it is assessed in. The VDA publishes the catalogue, the ENX Association runs the process and issues the labels, and audit providers carry out the assessments. Anyone searching for the TISAX questionnaire means the VDA ISA catalogue.
Is an ISO 27001 certificate enough instead of TISAX?+
As a substitute, generally not — manufacturers ask for the TISAX label. As a foundation, very much so: the overlap is large, and the catalogue carries reference columns to ISO 27001. If you are certified, a substantial share is answerable from existing evidence; what usually has to be added is maturity evidence.
Which maturity level do I need?+
For most assessments, level 3 throughout: the process is established, consistently followed and demonstrably testable. Levels 0 and 1 count as insufficient. Higher levels are possible but rarely demanded.
What separates AL2 from AL3?+
The same catalogue is assessed; the difference is depth. AL2 runs as an external assessment with a plausibility check, AL3 with an on-site audit. Which level applies is set by the manufacturer, not the supplier.
Other assessments we cover: CAIQ v4, SIG & SIG Lite, HECVAT, VSA, DORA, ISO 27001. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.
Answer your TISAX / VDA ISA with evidence
Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.