The Definitive Guide to VDA ISA 6.0 and TISAX Compliance: Scoping, Maturity, and Audit Readiness
In the highly integrated global automotive supply chain, information security is not merely a technical checkbox; it is a critical prerequisite for business operations. Managed by the ENX Association, TISAX® (Trusted Information Security Assessment Exchange) is an assessment and exchange mechanism based on the VDA ISA (Verband der Automobilindustrie Information Security Assessment) framework. Any tier-1 or tier-2 partner—from software design vendors and cloud hosters to prototype metal-stamping factories—wishing to contract with major European automotive manufacturers must secure specific TISAX compliance labels.
1. Understanding the Difference: VDA ISA vs. TISAX
Many vendors confuse the VDA ISA with TISAX itself. The VDA ISAis the actual catalog of requirements, standardizing core components of information security, data protection, and prototype security. TISAX is the exchange portal. An organization schedules an audit with an ENX-accredited provider, who tests the organization's posture against the VDA ISA standard. Once successfully completed, the audit results are registered as standardized TISAX Labels on the ENX portal, allowing automotive clients to instantly verify your security status.
The framework transitioned to VDA ISA Version 6.0, streamlining criteria and adapting the Information Security questionnaire to map directly against modernized cloud environments and advanced cyber threat intelligence matrices.
2. Decoding TISAX Assessment Levels
TISAX categorizes audits into three separate Assessment Levels (AL) based on the sensitivity of the data you process on behalf of your automotive clients:
- Assessment Level 1 (AL1): Purely internal self-assessment. No verification by an independent third-party auditor is required. Excellent for scoping and initial baseline analysis, but AL1 results are not published on the TISAX portal and do not grant official TISAX customer labels.
- Assessment Level 2 (AL2): Plausibility review. Accredited auditors test the self-assessment responses, checking evidentiary documentation and conducting interviews. This process is usually performed remotely and is suitable for moderate-risk data.
- Assessment Level 3 (AL3): Full physical verification. Auditors perform exhaustive document reviews, comprehensive technical systems testing, and thorough on-site inspections of physical buildings and server installations. This is mandatory for high-risk data, secret prototype components, and high-security testing environments.
3. The VDA ISA 6.0 Maturity Model Explained
VDA ISA 6.0 grades each control group using a Capability Maturity Model Integration (CMMI) scale from 0 to 5. To secure a successful TISAX label, the minimum target for all active controls is strictly **3.0 (Established)**.
| Maturity Level | Definition | Requirements |
|---|---|---|
| 0 - Incomplete | Process absent or failing | Missing documentation, informal execution, or complete structural gap. |
| 1 - Performed | Ad-hoc execution | Controls exist in response to crises, but lack standardized frameworks. |
| 2 - Managed | Documented process | Written procedures and responsibility assignments exist. (Minor Deficit) |
| 3 - Established | Company-wide integration | Standardized process embedded into operations and regularly audited. (Target) |
| 4 - Predictable | Quantitatively measured | Process metrics are continuously collected, monitored, and analyzed. |
| 5 - Optimizing | Continuous improvement | Self-healing mechanisms and proactive external threat models in place. |
4. Overcoming Non-Conformities: Major vs. Minor Deficits
If your assessor detects controls that fail to meet the target maturity 3.0 during an audit, they are classified as deficits:
- Major Non-Conformity (Major Deficit): Appears when a control group is graded at maturity 0 or 1. This is a critical showstopper that blocks the ENX exchange registry from issuing any TISAX label. It indicates a severe gap in core structural security.
- Minor Non-Conformity (Minor Deficit): Appears when a control group is graded at maturity 2.0 (e.g., you have excellent documented processes but lack independent auditing history). You can resolve this without blocking your business by submitting a verified Corrective Action Plan (CAP). An approved CAP secures a temporary conditional TISAX label, granting a grace period to resolve the findings.
5. Practical Step-by-Step Roadmap to TISAX Labels
To successfully prepare, audit, and exchange your TISAX credentials, follow this proven sequential methodology:
- Registration: Register your company as a Participant on the ENX Association platform. You will receive standard Participant and Scope IDs.
- Internal Self-Assessment: Complete the VDA ISA 6.0 spreadsheet self-audit. Utilize this interactive online calculator to quickly score your maturity baseline, identify deficits, and estimate audit fees.
- Remediation: Address any major gaps and minor deficits. Ensure all scoped controls are raised to at least maturity level 2.0 (ideally 3.0).
- Assessor Contracting: Secure a contract with an ENX-accredited audit provider (e.g., TÜV SÜD, DEKRA, or SGS).
- Formal Assessment: Undergo the AL2 (remote document review) or AL3 (on-site physical and technical network checks) audit.
- Result Exchange: Upon successful assessment, your audit results are uploaded to the ENX portal. Approve sharing with target automotive OEMs to unlock critical sales pipelines.