About this checklist
TISAX® (Trusted Information Security Assessment Exchange) is an information security assessment scheme used across the automotive industry, based on the VDA Information Security Assessment (ISA) catalogue. It is structured as an assessment rather than a certification. Please note there is no TISAX® certificate issued.
This checklist lets you self-check your organisation's current state against the VDA ISA domains before scheduling a TISAX® assessment. Work through each domain and mark each item Yes, Partial, or No based on your organisation's current practice.
A note on assessment levels
TISAX® assessments are conducted at different assessment levels (AL1–AL3), and the applicable level and test depth depend on the information being shared and the scope agreed with your business partners. Where higher assessment levels apply, on-site or remote auditor verification is typically involved rather than self-assessment alone.
How to use this checklist
- Assign an owner for each domain (e.g. IT security lead, HR, facilities)
- Answer each item honestly. “Partial” is a valid and useful answer
- Use the scoring guide on the last page to identify priority domains
- Revisit this checklist periodically as your scope or business partner requirements change
TISAX® Readiness Checklist
Check your organisation's current state against the VDA ISA domains before scheduling a TISAX® assessment.
Your Readiness Score
Results by domain
Next steps
A completed self-check is a good starting point, not the finish line. DQS runs independent TISAX® assessments matched to the level and scope your business partners have asked for. Reach out to pin down the right assessment level and modules for your organization, and get a date on the books.