RoutineMetric
Cybersecurity & Data Privacy

VDA ISA & TISAX Maturity & Compliance Assessment Tool

Structure your automotive information security audit under the VDA ISA 6.0 framework. Assess maturity levels, estimate ENX assessment costs, and determine your readiness for a successful TISAX registration.

1. Audit Scoping Parameters

Required for normal-risk supply lines. Features document reviews and remote interview audits.

Information Security (IS)Mandatory

Core operational security, networks, cryptography, access controls, physical spaces, and HR security.

Prototype Protection (PP)

Required if you handle physical prototypes, components, test tracks, or secret design schematics.

Data Protection (DP)

Required if you process personal data as a controller or processor (e.g., outsourced CRM or HR tools).

Quick Scoring Presets:

2. Cost & Complexity Estimates

Audit Duration3 daysAuditor active hours
Estimated Fees$5,500 - $8,500Registrar + audit costs
Audit Type Strategy:Remote plausibility check of self-assessment by accredited auditor
2.44AVG Maturity

Overall Audit Score

Target maturity: 3.0 (Established) on all active control categories.

Readiness LabelNot Ready (Gaps Detected)
0Major DeficitsMaturity < 2.0
5Minor DeficitsMaturity === 2.0
4Compliant ControlsMaturity ≥ 3.0
🛑 Assessment blocker detected: You have 0 Major Deficits (maturity below 2.0) or your average is below 2.7. Gaps scored 0 or 1 represent missing basic controls. You must remediate these to at least level 2.0/3.0 before registering with an ENX auditor.

Required Remediation Roadmap (5 issues to resolve)

The following VDA ISA 6.0 chapters are below the mandatory target maturity level of 3.0. Implement the recommended operational controls to achieve TISAX labels:

Minor Deficit (2)IS 1.2: Human Resources SecurityModule: IS

Currently: "Managed: Written NDAs are signed at hire; basic security training is mandated and recorded."

Required Actions to reach Target Maturity 3:
  • Develop comprehensive organizational procedures and policies for human resources security.
  • Establish clear, documentable roles, operational responsibilities, and systematic metrics.
  • Ensure the processes are fully implemented, communicated, and audited internally on a schedule.
Minor Deficit (2)IS 1.4: Identity & Access Management (IAM)Module: IS

Currently: "Managed: Centralized SSO, strong password policies, and manual MFA on administrative accounts only."

Required Actions to reach Target Maturity 3:
  • Develop comprehensive organizational procedures and policies for identity & access management (iam).
  • Establish clear, documentable roles, operational responsibilities, and systematic metrics.
  • Ensure the processes are fully implemented, communicated, and audited internally on a schedule.
Minor Deficit (2)IS 1.6: IT Operations & Cyber DefenseModule: IS

Currently: "Managed: Centralized patch schedule, weekly backup routines, and antivirus deployed on all endpoints."

Required Actions to reach Target Maturity 3:
  • Develop comprehensive organizational procedures and policies for it operations & cyber defense.
  • Establish clear, documentable roles, operational responsibilities, and systematic metrics.
  • Ensure the processes are fully implemented, communicated, and audited internally on a schedule.
Minor Deficit (2)IS 1.8: Vulnerability & Incident ResponseModule: IS

Currently: "Managed: Annual external penetration test; basic written Incident Response Plan (IRP) exists."

Required Actions to reach Target Maturity 3:
  • Develop comprehensive organizational procedures and policies for vulnerability & incident response.
  • Establish clear, documentable roles, operational responsibilities, and systematic metrics.
  • Ensure the processes are fully implemented, communicated, and audited internally on a schedule.
Minor Deficit (2)IS 1.9: Supplier & Third-Party SecurityModule: IS

Currently: "Managed: Core vendors complete security questionnaires; standard confidentiality agreements are kept on record."

Required Actions to reach Target Maturity 3:
  • Develop comprehensive organizational procedures and policies for supplier & third-party security.
  • Establish clear, documentable roles, operational responsibilities, and systematic metrics.
  • Ensure the processes are fully implemented, communicated, and audited internally on a schedule.

3. Detailed VDA ISA 6.0 Control Self-Assessment

Adjust sliders to set your current maturity levels (0 - 5)
IS 1.1

Security Policies & Organization

Maturity 3/5

Scope and structure of your Information Security Management System (ISMS), defined roles, management reviews, and internal security audits.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Established: Full ISMS is standardized company-wide, integrated into workflows, and regularly audited. (TISAX Standard)
IS 1.2

Human Resources Security

Maturity 2/5

Security checks, onboarding NDAs, regular security awareness training, and offboarding access revocation protocols.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Managed: Written NDAs are signed at hire; basic security training is mandated and recorded.
IS 1.3

Physical Security & Asset Management

Maturity 3/5

Secure perimeter access controls, visitor logs, clean desk policies, asset registers, and secure data media disposal.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Established: Secure internal zones, logged visitor escorts, clean desk policy, and certified secure media destruction. (TISAX Standard)
IS 1.4

Identity & Access Management (IAM)

Maturity 2/5

Role-Based Access Control (RBAC), multi-factor authentication (MFA), password complexity, and periodic access reviews.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Managed: Centralized SSO, strong password policies, and manual MFA on administrative accounts only.
IS 1.5

Cryptography & Key Management

Maturity 3/5

Encryption standards for data-at-rest (AES-256), transit (TLS 1.3), and secure storage/rotation of cryptographic keys.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Established: TLS 1.3 enforced, full storage encryption, keys managed securely via hardware modules (HSM) or cloud KMS. (TISAX Standard)
IS 1.6

IT Operations & Cyber Defense

Maturity 2/5

System patch management SLAs, immutable backup routines, endpoint detection & response (EDR), and log aggregation.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Managed: Centralized patch schedule, weekly backup routines, and antivirus deployed on all endpoints.
IS 1.7

Network & Remote Access Security

Maturity 3/5

Network segmentation, enterprise firewalls, secure Wi-Fi protocols, and Secure Access Service Edge (SASE) for remote work.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Established: Next-Gen Firewalls (NGFW), WPA3 enterprise authentication, strict VLAN segregation, and SASE/VPN posture checks. (TISAX Standard)
IS 1.8

Vulnerability & Incident Response

Maturity 2/5

Vulnerability scanning schedules, external penetration testing, incident response planning, and tabletop drills.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Managed: Annual external penetration test; basic written Incident Response Plan (IRP) exists.
IS 1.9

Supplier & Third-Party Security

Maturity 2/5

Vetting vendor security postures during procurement, enforcing security SLAs, and conducting third-party audits.

0: Incomplete3: Target5: Optimizing
012345
Current Assessment:Managed: Core vendors complete security questionnaires; standard confidentiality agreements are kept on record.
Advertisement
Bottom Banner Ad (728x90)

The Definitive Guide to VDA ISA 6.0 and TISAX Compliance: Scoping, Maturity, and Audit Readiness

In the highly integrated global automotive supply chain, information security is not merely a technical checkbox; it is a critical prerequisite for business operations. Managed by the ENX Association, TISAX® (Trusted Information Security Assessment Exchange) is an assessment and exchange mechanism based on the VDA ISA (Verband der Automobilindustrie Information Security Assessment) framework. Any tier-1 or tier-2 partner—from software design vendors and cloud hosters to prototype metal-stamping factories—wishing to contract with major European automotive manufacturers must secure specific TISAX compliance labels.

1. Understanding the Difference: VDA ISA vs. TISAX

Many vendors confuse the VDA ISA with TISAX itself. The VDA ISAis the actual catalog of requirements, standardizing core components of information security, data protection, and prototype security. TISAX is the exchange portal. An organization schedules an audit with an ENX-accredited provider, who tests the organization's posture against the VDA ISA standard. Once successfully completed, the audit results are registered as standardized TISAX Labels on the ENX portal, allowing automotive clients to instantly verify your security status.

The framework transitioned to VDA ISA Version 6.0, streamlining criteria and adapting the Information Security questionnaire to map directly against modernized cloud environments and advanced cyber threat intelligence matrices.

2. Decoding TISAX Assessment Levels

TISAX categorizes audits into three separate Assessment Levels (AL) based on the sensitivity of the data you process on behalf of your automotive clients:

  • Assessment Level 1 (AL1): Purely internal self-assessment. No verification by an independent third-party auditor is required. Excellent for scoping and initial baseline analysis, but AL1 results are not published on the TISAX portal and do not grant official TISAX customer labels.
  • Assessment Level 2 (AL2): Plausibility review. Accredited auditors test the self-assessment responses, checking evidentiary documentation and conducting interviews. This process is usually performed remotely and is suitable for moderate-risk data.
  • Assessment Level 3 (AL3): Full physical verification. Auditors perform exhaustive document reviews, comprehensive technical systems testing, and thorough on-site inspections of physical buildings and server installations. This is mandatory for high-risk data, secret prototype components, and high-security testing environments.

3. The VDA ISA 6.0 Maturity Model Explained

VDA ISA 6.0 grades each control group using a Capability Maturity Model Integration (CMMI) scale from 0 to 5. To secure a successful TISAX label, the minimum target for all active controls is strictly **3.0 (Established)**.

Maturity LevelDefinitionRequirements
0 - IncompleteProcess absent or failingMissing documentation, informal execution, or complete structural gap.
1 - PerformedAd-hoc executionControls exist in response to crises, but lack standardized frameworks.
2 - ManagedDocumented processWritten procedures and responsibility assignments exist. (Minor Deficit)
3 - EstablishedCompany-wide integrationStandardized process embedded into operations and regularly audited. (Target)
4 - PredictableQuantitatively measuredProcess metrics are continuously collected, monitored, and analyzed.
5 - OptimizingContinuous improvementSelf-healing mechanisms and proactive external threat models in place.

4. Overcoming Non-Conformities: Major vs. Minor Deficits

If your assessor detects controls that fail to meet the target maturity 3.0 during an audit, they are classified as deficits:

  • Major Non-Conformity (Major Deficit): Appears when a control group is graded at maturity 0 or 1. This is a critical showstopper that blocks the ENX exchange registry from issuing any TISAX label. It indicates a severe gap in core structural security.
  • Minor Non-Conformity (Minor Deficit): Appears when a control group is graded at maturity 2.0 (e.g., you have excellent documented processes but lack independent auditing history). You can resolve this without blocking your business by submitting a verified Corrective Action Plan (CAP). An approved CAP secures a temporary conditional TISAX label, granting a grace period to resolve the findings.

5. Practical Step-by-Step Roadmap to TISAX Labels

To successfully prepare, audit, and exchange your TISAX credentials, follow this proven sequential methodology:

  1. Registration: Register your company as a Participant on the ENX Association platform. You will receive standard Participant and Scope IDs.
  2. Internal Self-Assessment: Complete the VDA ISA 6.0 spreadsheet self-audit. Utilize this interactive online calculator to quickly score your maturity baseline, identify deficits, and estimate audit fees.
  3. Remediation: Address any major gaps and minor deficits. Ensure all scoped controls are raised to at least maturity level 2.0 (ideally 3.0).
  4. Assessor Contracting: Secure a contract with an ENX-accredited audit provider (e.g., TÜV SÜD, DEKRA, or SGS).
  5. Formal Assessment: Undergo the AL2 (remote document review) or AL3 (on-site physical and technical network checks) audit.
  6. Result Exchange: Upon successful assessment, your audit results are uploaded to the ENX portal. Approve sharing with target automotive OEMs to unlock critical sales pipelines.
GustoVerified Payroll Partner
Payroll & S-Corp
3 Months Free + $100 Visa Card

Run IRS-Compliant S-Corp & Small Business Payroll

Automate officer reasonable compensation, federal tax withholdings, and quarterly W-2/941 filings with zero manual paperwork.

Discussion & Comments

Join the conversation, ask questions, or share feedback.

Advertisement