Free TISAX Self-Assessment:
See Your Likely Assessment Level and Where the Gaps Are
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive TISAX risk check below to see where your operation actually stands.
Tell it what kind of OEM data you handle, then answer 8 quick questions on VDA-ISA-aligned controls, and get your result in about 2 minutes: your risk level, the likely assessment level (AL1, AL2, or AL3) and scope module your OEM will expect, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What TISAX Actually Covers (the short version)
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s shared information-security assessment framework, run by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). If an OEM or Tier 1 customer handles your company’s data, prototypes, or engineering files, they can require you to register for TISAX and reach a specific result before they’ll keep working with you.
The assessment itself is scored against the VDA ISA catalog, a detailed set of information-security control questions organized by area:
- Security Policy and Organization
- Asset Management and Data Classification
- Access Control
- Physical Security
- Cryptography
- Operations and Communications Security
- Supplier Relationships
- Incident Management
- Business Continuity
Depending on what your OEM’s invitation specifies, your assessment also covers one or more scope modules layered on top of the base Information Security module: Prototype Protection (physical and procedural controls for prototype parts, vehicles, or camouflage components) and Data Protection (controls for personal data, aligned with GDPR-style requirements).
Your OEM’s request determines which modules apply and at what assessment level, not you. The checklist below is organized around the VDA ISA control areas so you can see exactly where you stand.
The Full TISAX Self-Assessment Checklist
- 1. Confirm Your Assessment Level and Module First:
✓ Assessment Level 1 (AL1): a pure self-assessment against the VDA ISA questionnaire, with no external audit and no visible result on the ENX portal. No OEM accepts an AL1 result as proof of anything.
✓Assessment Level 2 (AL2): the level most suppliers land on. An accredited audit provider reviews your documentation and interviews your team, typically by video conference, and issues a result visible on the ENX portal that OEMs will accept.
✓Assessment Level 3 (AL3): the most rigorous level, requiring an on-site audit that verifies your controls are actually implemented and operating, not just documented. Usually required when high-sensitivity or pre-release data is in scope.
✓ Scope Modules: the base Information Security module is always in play. Prototype Protection gets added if you handle prototype parts, vehicles, or confidential engineering data. Data Protection gets added if you process personal data on your OEM’s behalf. Your OEM’s invitation specifies which modules and which level; confirm it before you register rather than guessing. - 2. Information Security Policy and Organization:
✓ A formally documented, management-approved information security policy, reviewed within the last 12 months.
✓ Defined information-security responsibilities and an accountable owner (an ISMS manager or equivalent).
✓ A risk-assessment process that identifies threats to OEM data and tracks them through to remediation. - 3. Asset Management and Data Classification:
✓ A current inventory of everywhere OEM data lives: file shares, PLM/PDM systems, email, laptops, cloud storage.
✓ A written data classification scheme (public / internal / confidential / strictly confidential) applied to OEM-shared drawings, specs, and files.
✓ Defined handling rules per classification level (who can access it, how it can be shared, how it’s disposed of). - 4. Access Control:
✓ A unique login for every user; no shared accounts.
✓ Access to systems and network areas holding OEM data granted on a documented least-privilege basis.
✓ Regular access reviews, with access revoked promptly when someone leaves or changes roles. - 5. Physical Security Including Prototype Areas:
✓ Badge or key access, visitor logs, and monitored entry points for facilities holding OEM data.
✓ For prototype parts, vehicles, or confidential engineering work specifically: a controlled area, an escorted-visitor policy, and a written no-unauthorized-photography rule. This is the core of the Prototype Protection module.
✓ Secure storage or destruction of physical documents and media containing OEM data. - 6. Cryptography and Technical Controls:
✓ OEM data encrypted at rest (laptops, servers, backups) and in transit (email, file transfer, portals).
✓ Restrictions on copying OEM data to removable media or personal/unmanaged cloud accounts.
✓ Multi-factor authentication on systems and remote access to OEM data. - 7. Operations and Communications Security:
✓ Patch management and endpoint protection on systems that touch OEM data.
✓ Network segmentation separating OEM-data systems from general business systems where practical.
✓ Logging and monitoring on systems holding OEM data, with someone actually reviewing the logs. - 8. Supplier Relationships (Your Own Vendors):
✓ A current inventory of every vendor, subcontractor, and cloud provider that can access OEM data.
✓ Security requirements or contract language in place with each one before they get access.
✓ Your own IT provider included in this review; their access is in scope too. - 9. Incident Management and OEM Notification:
✓ A documented incident-response process covering detection, containment, and recovery.
✓ A defined, specific timeline for notifying your OEM customer if their data is compromised.
✓ A record of past incidents (if any) and how they were handled. - 10. Business Continuity and Backups:
✓ Regular backups of systems that store or process OEM data.
✓ Backups that someone has actually tested by restoring, not just scheduled.
✓ A written business-continuity plan covering those systems.
How to read your gaps?
- 0 – 2 Gaps (0 Critical)
Strong Shape Heading into Registration
- 3 – 6 Gaps (or 1 Critical)
Real, findable issues that an AL2 remote auditor will likely write up as findings, and each one adds time to your remediation timeline.
- 7+ Gaps (Or 2+ Critical)
You’d likely fail an assessment today.
The urgency is highest if you flagged prototype, confidential engineering, or high-sensitivity data on the first question: that’s the profile most likely to pull in the Prototype Protection module and push you toward Assessment Level 3, which takes longer and costs more to prepare for.
Most of the technical items above (access control, encryption, logging, tested backups) live in your IT setup, not a policy binder, which is the half of TISAX a managed IT and cybersecurity partner operates for you.
TISAX FAQ
TISAX is the automotive industry’s shared information-security assessment framework, run by the ENX Association based on the VDA ISA control catalog. Automotive OEMs and Tier 1 suppliers require it from suppliers, engineering partners, and other companies in their supply chain that handle their data, often with a specific registration deadline attached to keep or win the business.
AL1 is a self-assessment with no external audit; no OEM accepts it as proof. AL2 is the level most suppliers use: an accredited audit provider reviews your documentation and interviews your team, typically remotely, and the result posts to the ENX portal. AL3 is an on-site audit, the most rigorous level, generally required when high-sensitivity or pre-release data is involved. Your OEM’s invitation specifies which level you need.
The base Information Security module always applies. Prototype Protection is added if you handle prototype parts, vehicles, or confidential engineering data. Data Protection is added if you process personal data on your OEM’s behalf. Your OEM’s invitation sets the exact combination; the self-assessment above uses what kind of data you handle to point you toward the likely combination, but the invitation is the authoritative source.
It varies widely with scope and company size, so treat any number as a planning range, not a quote. Smaller, single-module assessments commonly run in the low five figures; larger assessments covering multiple modules (especially with Prototype Protection or Data Protection added) commonly run well into five or six figures once consulting and remediation are included. Timelines commonly run several months to under a year from kickoff to a posted result, longer if remediation work is extensive. Get a real quote from an accredited audit provider once you know your level and scope; don’t assume the low end applies to you.
Almost always an OEM or Tier 1 customer mandate, usually delivered with a specific registration or completion date tied to a contract or program. Because the deadline is set by your customer, not by you, the practical move is to confirm your required level and scope module immediately rather than losing weeks to uncertainty.
Possibly, at a lower scope. If your OEM only requires the base Information Security module, you’re not dealing with Prototype Protection’s physical-security requirements, but the core VDA ISA controls (policy, access control, encryption, incident response) still apply. Confirm your required modules with your OEM contact rather than assuming you’re exempt.
Yes. TISAX doesn’t have a small-business exemption; your OEM sets the required level and scope regardless of your headcount. A smaller supplier typically has fewer systems and vendors to bring into scope, which can make remediation faster, but the same controls apply.
Ready to close your gaps?
If your result flagged access control, encryption, physical security for prototype areas, or incident response, that’s technical and process work an IT and cybersecurity partner handles day to day.
LeadingIT helps Chicagoland manufacturers and automotive suppliers get ready for a TISAX assessment: the access controls, encryption, logging, and incident-response documentation an accredited audit provider checks. We deliver this FOR manufacturers; we don’t hold TISAX certification ourselves, and no IT company does; TISAX is a label your OEM’s audit provider issues after assessing you.
Follow the link to see how LeadingIT supports manufacturers, email yourself the full result from the tool above, or book a free 30-minute gap review.