VDA ISA Checklist: How to Self-Assess Before Your TISAX Audit
A VDA ISA self-assessment is the first formal step toward a TISAX audit. You work through the VDA ISA questionnaire yourself, chapter by chapter, and rate your own controls on a six-point maturity scale before any outside auditor gets involved. If TISAX itself is still new to you, our overview of what TISAX and the VDA ISA standard are is worth reading first.
Self-assessment isn’t the very first thing that happens, either. Registration on the ENX portal comes first, where you set up an account and define your assessment scope. Once that’s done, you complete the self-assessment. Only after that does the real audit begin, at whatever Assessment Level your business partner requires.
This self-assessment step is officially called Assessment Level 1 (AL1). Here’s the part suppliers get wrong: even if your partner ultimately requires AL2 or AL3, you still complete this same self-assessment first. The higher levels build a verification layer on top of it. They don’t replace it. An AL2 auditor checks your self-assessment for plausibility. An AL3 auditor verifies it on site. Either way, what you write down here is the foundation everything else gets checked against.
That’s exactly why rushing it, or shading your answers to look better than reality, doesn’t make your problems disappear. It just moves them to audit day, where they’re more expensive to fix and a lot more visible.
Key Takeaways
- A VDA ISA self-assessment (AL1) is mandatory groundwork for every TISAX participant, no matter which Assessment Level your partner ultimately requires.
- The self-assessment covers nine VDA ISA chapters, from policy and personnel security through IT operations and data protection.
- MUST requirements need Maturity Level 3 or higher to pass. SHOULD requirements are recommended, but won’t block your label on their own.
- Inflating your self-assessment doesn’t reduce your real gaps. It just means an auditor finds them later, when fixing them costs more.
- You can gauge where you’d land on all nine chapters today with our free TISAX Readiness Check, before committing to an auditor.
Why Rushing the Self-Assessment Backfires
Some suppliers treat the self-assessment as a formality. They answer generously, assume any gaps will surface gently during the audit, and move on.
That’s backwards. The self-assessment sets the audit provider’s starting point. If you rate yourself high on a control you don’t actually have, the auditor doesn’t quietly correct it for you. They flag a mismatch between what you documented and what they observe. That’s worse than an honest gap would have been, because now they’re questioning everything else you reported too.
Here’s what’s actually at stake. A Major Non-Conformity on a MUST requirement blocks your TISAX label until it’s resolved.
Remediation windows for a Major Non-Conformity commonly run up to nine months, and until it’s closed, no label gets issued.
A dishonest self-assessment doesn’t shrink that risk. It just delays when you find out about it, and pushes the fix into a tighter, more expensive window. To see which Assessment Level your honest result is likely to point toward, check our breakdown of TISAX Assessment Levels (AL1, AL2, AL3).
The Checklist: All Nine VDA ISA Chapters
The VDA ISA catalogue organizes every TISAX requirement into nine chapters. This checklist follows VDA ISA 6.0.3, the version required for every assessment commissioned since April 1, 2024. Work through each chapter honestly, using the self-check question as your gut-check before you touch the real questionnaire on the ENX portal.
| Chapter | What It Covers | Self-Check Question |
|---|---|---|
| 1. IS Policies and Organization | A written information security policy that’s owned by someone and actually communicated to staff. | Does your policy live somewhere staff have actually read, not just a file on a shared drive? |
| 2. Organizational Security | Security roles and risk management built into how the business runs, not bolted on once a year. | Is security risk reviewed as part of normal business decisions, or only when a customer asks? |
| 3. Personnel Security | Background screening, confidentiality agreements, security awareness training, and access removal when someone leaves. | When an employee leaves, is their system access cut off the same day? |
| 5. Identity and Access Management | Unique logins, multifactor authentication, least-privilege access, and encryption of sensitive data. | Does every employee log in with their own credentials, protected by MFA? |
| 6. IT Security and Operations | Patch management, change management, system monitoring, and tested backups. | Are patches applied on a set schedule, with a record you could actually produce? |
| 7. Detection and Response to Security Incidents | Incident logging and a documented response procedure your team actually knows. | If a laptop was compromised tomorrow, would your team know the written steps to follow? |
| 8. Business Continuity | Disaster recovery planning, defined recovery time and recovery point objectives, and tested failover. | Have you tested a real backup restore, or only assumed the backup would work? |
| 9. Compliance and Data Protection | Legal adherence and GDPR-aligned controls for any personal data you process on behalf of an automotive partner. | If you’re a GDPR processor for a partner, can you point to the controls that prove it? |
Answer every question honestly, even the ones that sting. A “no” here is cheap. The same “no,” discovered by an auditor at AL2 or AL3, is not.
Notice that the last four chapters, Identity and Access Management, IT Security and Operations, Incident Response, and Business Continuity, are where most first-time automotive suppliers find their weakest answers. They’re also the chapters that lean most heavily on IT infrastructure rather than paperwork, which is a theme worth keeping in mind as you work through your own gaps.
MUST vs. SHOULD: Which Gaps Actually Block You
Not every gap carries the same weight. The VDA ISA catalogue splits requirements into two tiers, MUST and SHOULD, and knowing which tier a gap falls into tells you how urgently to fix it.
| Requirement Type | What a Gap Means | What Happens Next |
|---|---|---|
| MUST | A Major Non-Conformity. Every MUST requirement has to reach Maturity Level 3 or higher to pass. | Remediation is required, commonly within about nine months, before a label can be issued. |
| SHOULD | A Minor Non-Conformity. Recommended, but not mandatory to pass. | Documented in the report, but it doesn’t block the assessment on its own. |
Here’s the practical filter to run on your self-check answers. Sort every “no” or “partial” into one of two piles.
- Is this a MUST requirement? Identity and access management, incident response, and business continuity tend to carry the most of these. If yes, it’s a blocker until you close it.
- Is this a SHOULD requirement? If yes, it’s worth fixing, but it won’t stall your label on its own.
Suppliers who skip this sorting step tend to spread their pre-audit effort evenly across all nine chapters. That’s a mistake. A handful of unresolved MUST gaps will stop your assessment cold. A dozen unresolved SHOULD gaps mostly just get noted and moved past. Find your MUST gaps first, then work down from there.
The Evidence Trap: Why “We Have a Policy” Isn’t Level 3
Here’s where a lot of self-assessments quietly fall apart. A supplier writes “yes, we have an access control policy” and rates themselves Level 3. But having a policy document isn’t the same as running one.
The VDA ISA maturity scale runs from Level 0 to Level 5. Written-but-unused policies land you at Level 1, not Level 3.
| Level | Name | What It Actually Means |
|---|---|---|
| 0 | Incomplete | No suitable process exists, or nobody follows the one you have. |
| 1 | Performed | Something informal happens, with a little evidence it works, but it’s barely documented. |
| 2 | Managed | A documented process runs, with real evidence someone implements it. |
| 3 | Established | The process is standard and built into how the business actually runs. |
| 4 | Predictable | The process is measured and controlled with data. |
| 5 | Optimizing | The process keeps improving, tied to real business goals. |
Every MUST requirement needs Level 3 or higher to pass. That’s a specific bar: documented, followed, and integrated into your management system, not written down once and filed away.
Ask yourself a harder version of each self-check question. Not “do we have a backup policy,” but “if I pulled a random employee off the floor, could they describe the process without looking it up?” That’s the gap between a Level 1 policy and a Level 3 one, and it’s exactly where first-time suppliers overrate themselves.
The Most Common Gaps First-Time Suppliers Hit
Four chapters cause most of the trouble. All four lean on IT infrastructure rather than paperwork, which is why they trip up suppliers who’ve handled the policy-writing but not the technical build-out.

- Chapter 5, Identity and Access Management. Shared logins instead of unique credentials. No MFA on remote access. Departing employees who keep system access for days or weeks after their last day.
- Chapter 6, IT Security and Operations. Patches applied whenever someone remembers, with no schedule and no record. Changes pushed to production with no approval trail.
- Chapter 7, Detection and Response to Security Incidents. An incident response plan that exists as a document nobody on the team has actually walked through. No real log of past incidents, however minor.
- Chapter 8, Business Continuity. A backup that runs nightly but has never been test-restored. No defined recovery time objective or recovery point objective, so nobody actually knows how much data or downtime a real outage would cost.
Notice the pattern. Every one of these is a control that’s easy to claim on paper and hard to fake in an interview. That’s exactly what AL2 and AL3 auditors are trained to probe.
Turning Your Self-Assessment Into an Audit-Ready Evidence Package
A finished self-check tells you where your gaps are. It doesn’t close them. Here’s how to move from “we know what’s wrong” to a package an auditor can actually verify.
- Pull every MUST gap from your self-check into one list, sorted by chapter.
- Attach real evidence for each one. The actual policy document, not a description of it.
- Add proof the process runs day to day: system logs, configuration screenshots, onboarding and offboarding records, ticket history.
- Prepare the people, not just the paperwork. Process owners should be ready to explain their own controls in plain language, since both AL2 and AL3 include interviews.
- Set a remediation timeline for anything still below Level 3, ideally before you register your assessment scope.
Once that package is solid, you’re ready for the next stage: the actual TISAX certification process, where an accredited third-party auditor verifies what you’ve built.
This is also where most first-time suppliers realize the real work isn’t paperwork at all. It’s infrastructure. Chapters 5 through 8 (identity and access, patching and change control, incident response, and business continuity) are technical controls, and building them to a documented, evidence-backed Level 3 is exactly what LeadingIT’s IT compliance services are built to help with. LeadingIT doesn’t perform your TISAX audit and isn’t an ENX-accredited audit provider. What it does is get the technical foundation underneath your self-assessment solid before an outside auditor ever looks at it.
See Where You Stand
Skip the spreadsheet. Take the free 2-minute TISAX Readiness Check. It walks the same nine VDA ISA chapters as this checklist as an interactive tool, scores where you’d land on the 0-5 maturity scale today, and hands you a prioritized gap list before you spend a dollar on an auditor.
Take the free 2-minute TISAX Readiness Check
Related Guides
- What Is TISAX? The VDA ISA Standard Explained for Automotive Suppliers
- The TISAX Certification Process: Step by Step
- TISAX Assessment Levels (AL1, AL2, AL3) and Maturity Levels Explained
Frequently Asked Questions
It’s the first formal step in the TISAX process, officially called Assessment Level 1. You work through the VDA ISA questionnaire yourself and rate your own controls across nine chapters on a six-point maturity scale, before any outside auditor gets involved.
Yes. Every TISAX participant completes the AL1 self-assessment first, no matter which Assessment Level their business partner ultimately requires. AL2 and AL3 add a third-party verification layer on top of it, they don’t replace it.
There’s no standard timeline. ENX Association, which operates TISAX, has said publicly it can’t forecast this reliably because it depends on your scope, your audit provider’s availability, and how many gaps you’re starting with. Suppliers with more MUST-requirement gaps should expect a longer runway.
An unresolved MUST-requirement gap is a Major Non-Conformity, and it blocks your TISAX label from being issued. Remediation windows commonly run up to about nine months, and the label doesn’t come through until the gap is closed.
No. The self-assessment (AL1) carries a low trust level on its own and isn’t accepted for exchange within TISAX by itself. You need an accredited third-party audit provider to verify it at AL2 or AL3 before a usable label is issued.
No. TISAX audits are only performed by third-party audit providers accredited by ENX Association, and LeadingIT is not one of them. LeadingIT helps automotive suppliers build the underlying IT controls, documentation, and evidence an accredited auditor will actually check.
Three years. After that, you repeat the full registration, assessment, and exchange process to renew your label, which is part of why getting your self-assessment right the first time matters.
Get Your IT Foundation Audit-Ready
A clean self-assessment is only as good as the infrastructure behind it. If your gaps cluster around access management, patching, incident response, or backups, that’s a technical build-out, not a paperwork exercise, and it’s where LeadingIT’s IT compliance services come in.
Ready to talk through your specific gaps?
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
