About this checklist

TISAX® (Trusted Information Security Assessment Exchange) is an information security assessment scheme used across the automotive industry, based on the VDA Information Security Assessment (ISA) catalogue. It is structured as an assessment rather than a certification. Please note there is no TISAX® certificate issued.

This checklist lets you self-check your organisation's current state against the VDA ISA domains before scheduling a TISAX® assessment. Work through each domain and mark each item Yes, Partial, or No based on your organisation's current practice.

A note on assessment levels

TISAX® assessments are conducted at different assessment levels (AL1–AL3), and the applicable level and test depth depend on the information being shared and the scope agreed with your business partners. Where higher assessment levels apply, on-site or remote auditor verification is typically involved rather than self-assessment alone.

How to use this checklist

  • Assign an owner for each domain (e.g. IT security lead, HR, facilities)
  • Answer each item honestly. “Partial” is a valid and useful answer
  • Use the scoring guide on the last page to identify priority domains
  • Revisit this checklist periodically as your scope or business partner requirements change
TISAX® Readiness Checklist

TISAX® Readiness Checklist

Check your organisation's current state against the VDA ISA domains before scheduling a TISAX® assessment.

32 items · 8 domains · Yes / Partial / No
Your progress 0 of 32 answered
1

Information Security Policy & Organisation

A documented information security policy exists and is approved by management.

Information security responsibilities are formally assigned within the organisation.

The policy is reviewed and updated on a defined cycle.

Information security objectives are linked to business risk, not treated as a standalone IT topic.

2

Human Resources Security & Awareness

Confidentiality obligations are included in employment contracts or equivalent agreements.

New employees receive information security awareness training during onboarding.

Regular refresher training is provided to all staff with access to sensitive information.

A defined process exists for revoking access when employees leave or change roles.

3

Asset Management

An inventory of information assets (data, systems, devices) is maintained and kept current.

Assets are classified according to sensitivity (e.g. public, internal, confidential, strictly confidential).

Rules for handling and labelling classified information are documented and followed.

Removable media and mobile devices are covered by defined handling rules.

4

Physical & Environmental Security

Access to buildings and sensitive areas is controlled (badges, visitor logs, escort rules).

Server rooms and data centres have restricted access separate from general office access.

Clear desk and clear screen practices are defined and observed.

Environmental risks (fire, water, power loss) are addressed for critical infrastructure.

5

IT Security: Access Control & Cryptography

User access follows a least-privilege, need-to-know principle.

Access rights are reviewed on a defined schedule and removed promptly when no longer needed.

Multi-factor authentication is used for remote access and privileged accounts.

Encryption is applied to sensitive data at rest and in transit, aligned with a defined standard.

Patch management and vulnerability handling follow a documented process.

6

Supplier & Third-Party Relationships

Information security requirements are included in supplier and subcontractor agreements.

Third parties with access to sensitive information are assessed before onboarding.

A process exists to monitor supplier compliance with agreed security requirements on an ongoing basis.

7

Incident Management & Business Continuity

A documented process exists for reporting and handling information security incidents.

Roles and escalation paths for incident response are defined and known to relevant staff.

Business continuity and disaster recovery plans exist for critical systems and processes.

Continuity plans are tested or exercised on a defined cycle.

8

Data Protection (Privacy)

A data protection framework aligned with applicable privacy law (e.g. GDPR) is in place.

Processing of personal data is documented, including legal basis and retention periods.

A process exists for handling data subject requests and personal data breaches.

Safeguards are in place for international transfers of personal data (e.g. standard contractual clauses).

Your Readiness Score

0 of 64 points

Results by domain

Next steps

A completed self-check is a good starting point, not the finish line. DQS runs independent TISAX® assessments matched to the level and scope your business partners have asked for. Reach out to pin down the right assessment level and modules for your organization, and get a date on the books.

Talk to us