Questionnaire standards

TISAX and the VDA ISA catalogue — what it asks and what counts as evidence

VDA ISA is the questionnaire the German automotive industry hands to its suppliers. If you process a manufacturer's development data, prototypes or personal data, you will be asked for it — usually with a deadline, and usually before the contract is signed.

In short

VDA ISA differs from CAIQ, SIG or VSA in one fundamental way: it does not ask whether a control exists, but how mature it is. Every question is rated on a maturity scale and held against a target level. A TISAX label needs maturity level 3 throughout — established, consistently followed and demonstrably tested. A yes without a lived process does not clear that bar.

TISAX / VDA ISA at a glance

Published byThe VDA publishes the ISA catalogue; the ENX Association runs the TISAX process and issues the labels.
Assessment basisVDA ISA 6.0; version 6.0.2 has applied to newly commissioned assessments since 1 April 2024.
ModulesInformation security as the mandatory base module, plus prototype protection and data protection depending on what you handle.
RatingMaturity levels instead of yes/no: 0 Incomplete, 1 Performed, 2 Managed, 3 Established, 4 Predictable, 5 Optimizing.
Assessment levelsAL1 as a self-assessment, AL2 external with a plausibility check, AL3 external with an on-site audit. Manufacturers frequently require AL3.
ValidityA TISAX label is valid for three years; ENX requires an annual self-declaration in between.

How the file is put together

The catalogue arrives as a workbook, and its quirks decide how much work answering it actually is.

Questions are grouped by control area, each with its own number — that number later becomes the shared language with the assessor.
Next to the answer sit columns for maturity level, target level and action plan. The maturity level is the real answer; the free text justifies it.
Prototype protection and data protection sit on their own sheets and drop out when the module is not commissioned.
Extra columns referencing ISO 27001 help reuse existing evidence — they are a mapping aid, not part of the answer.

What Compliance Concierge does with a TISAX / VDA ISA

The question sheet is detected automatically; with multi-module workbooks you can pick the sheet yourself.
Every draft carries its evidence from your uploaded documents — with a maturity rating, that is exactly where an assessor probes.
Where your own documents do not support a maturity level, the answer is held for a human rather than generated. An inflated level surfaces during the assessment and costs more time than an honest gap.
Evidence already gathered for ISO 27001 carries over — the catalogue asks largely the same things in a different order.
Approved answers are written back into the workbook you received, maturity column included.

None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.

This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case. TISAX® and ENX are registered trademarks of ENX Association; VDA ISA is published by the German Association of the Automotive Industry. Compliance Concierge is affiliated with neither organisation and uses both names descriptively only.

The control areas — and the four where suppliers get stuck

The catalogue groups its questions by control area. Four of them cost the most time in practice, because they do not ask for a document but for a process that demonstrably runs.

1

Information security management

What it asks
Whether policies, named roles and a documented ISMS exist — and whether management demonstrably backs them.
What answers it
Information security policy with an approval date, role description with the named holder, minutes of a management review.
Common mistake
Submitting a policy nobody has touched since it was written. Level 3 requires a lived process; a document without a review cycle evidences level 1.
4

Access control

What it asks
About the access concept, the need-to-know principle, and multi-factor authentication requirements.
What answers it
Authorisation concept, proof of recurring recertification, configuration evidence for multi-factor authentication.
Common mistake
Reporting multi-factor authentication as present without saying for which systems. The question is about scope, not existence.
6

IT operations and network security

What it asks
About patch management, network segmentation and backup — each with a cadence and an owner.
What answers it
Patch policy with deadlines by criticality, network diagram showing segment boundaries, backup concept with a documented restore test.
Common mistake
Confirming backups without ever having tested a restore. That test is the difference between level 2 and level 3.
7

Incident management and business continuity

What it asks
About the incident process, reporting paths and recovery plans.
What answers it
Incident process with escalation stages and deadlines, continuity handbook, records from the last exercise or a real incident.
Common mistake
Describing a process that has never been exercised. What is asked for is evidence that it worked when it mattered.

The remaining control areas

  • 2 Personnel security
  • 3 Asset management
  • 5 Cryptography and physical security

From 1 January 2027, newly starting assessments run against VDA ISA 2027. Prototype protection is fully revised, references are aligned with ISO/IEC 27001:2022 and extended with a NIST CSF 2.0 mapping. The change that matters most to suppliers: control 1.2.4 moves to 6.1.3 and thereby into a dedicated supplier management area — the same movement NIS2 sets off. Whoever answers questionnaires today will, from 2027, also be passing them on to their own sub-suppliers.

Frequently asked

What is the difference between TISAX and VDA ISA?+

VDA ISA is the questionnaire; TISAX is the process it is assessed in. The VDA publishes the catalogue, the ENX Association runs the process and issues the labels, and audit providers carry out the assessments. Anyone searching for the TISAX questionnaire means the VDA ISA catalogue.

Is an ISO 27001 certificate enough instead of TISAX?+

As a substitute, generally not — manufacturers ask for the TISAX label. As a foundation, very much so: the overlap is large, and the catalogue carries reference columns to ISO 27001. If you are certified, a substantial share is answerable from existing evidence; what usually has to be added is maturity evidence.

Which maturity level do I need?+

For most assessments, level 3 throughout: the process is established, consistently followed and demonstrably testable. Levels 0 and 1 count as insufficient. Higher levels are possible but rarely demanded.

What separates AL2 from AL3?+

The same catalogue is assessed; the difference is depth. AL2 runs as an external assessment with a plausibility check, AL3 with an on-site audit. Which level applies is set by the manufacturer, not the supplier.

Other assessments we cover: CAIQ v4, SIG & SIG Lite, HECVAT, VSA, DORA, ISO 27001. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.

Answer your TISAX / VDA ISA with evidence

Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.