Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TISAX self-assessment explained

TISAX Self-Assessment: 6 Proven Steps to a Clean Audit (2026)

The TISAX self-assessment is the first thing every audit provider asks for and the document the whole assessment is built on. It is the VDA ISA catalogue — an Excel workbook — completed by the participant, with a maturity level from 0 to 5 entered against every applicable control question and a result score computed against the target. At assessment level 2 the auditor checks whether it is plausible; at level 3 the auditor verifies it on site; at either level, a self-assessment whose result score is below the maximum is a self-assessment that tells you not to book the audit yet. This guide explains how the ISA workbook is structured, what the six maturity levels mean, how the target and result scores are computed and read, the “cutback” that stops over-claiming from helping, and how to turn the completed self-assessment into a corrective plan and an evidence pack.

TISAX self-assessment: six maturity levels, one target score
Every applicable control question is rated 0–5; the result with cutback to target must reach the maximum score before the assessment is booked.

What the TISAX self-assessment is

ENX’s participant handbook describes the process in three steps: register, get assessed, exchange the result. The assessment step begins with the self-assessment “based on the ISA” — download the current ISA document from ENX, understand its criteria catalogues, chapters, control questions and requirements, rate the maturity level per question, then interpret the result. The workbook has three criteria catalogues: Information Security (46 controls in both ISA 6 and ISA2027), Prototype Protection (22 controls in ISA 6, 20 in ISA2027) and Data Protection (12). Which catalogues and which questions apply follows from the assessment objectives the customer named. Our guide to TISAX labels and the twelve objectives covers that selection.

The six maturity levels

The ISA rates each control question in the TISAX self-assessment on a maturity scale rather than a pass/fail. The handbook quotes the informal descriptions:

Level In one word Description (ISA)
0 Incomplete A process is not available, not followed or not suitable for achieving the objective
1 Performed An undocumented or incompletely documented process is followed and indicators exist that it achieves its objective
2 Managed A process achieving its objectives is followed; process documentation and implementation evidence are available
3 Established A standard process integrated into the overall system is followed; dependencies on other processes are documented and interfaces created; evidence exists that the process has been used sustainably and actively over an extended period
4 Predictable An established process is followed; its effectiveness is continually monitored by collecting key figures; limit values are defined at which the process is considered insufficiently effective (KPIs)
5 Optimizing A predictable process with continual improvement as a major objective is followed; improvement is actively advanced by dedicated resources

Level 3 is the target for the great majority of questions, and the distinction that trips participants up is between 2 and 3: a documented process with evidence is level 2; level 3 needs the process integrated with its neighbours — the interfaces documented — and evidence that it has run “sustainably and actively over an extended period”. A policy approved last month with one completed record is level 2 however well written.

How the score works

Target maturity level, per question

Each control question in the TISAX self-assessment carries a target maturity level, normally 3. Your rating is compared to the target question by question; a rating below target on any applicable question is a gap the auditor will find.

Maximum result score

The ISA defines a “maximum result score”: in theory the average of all target levels, which is 3.0 if every question applies. The handbook notes it is 3.0 “only if all questions apply to your situation” — mark a question not applicable and the maximum changes with it. This is the number your result is measured against, not a fixed 3.0.

Result with cutback to target

Your result score is the average of your ratings — but with a cutback: any rating above the target counts only as the target. Rating yourself 5 on ten questions does not lift a 2 on an eleventh. The handbook’s reading rule is direct: if the result with cutback is below the maximum, then “at least for one question your maturity level” is below target, and you can expect that to become a finding. The self-assessment is ready when result equals maximum.

Reading What it means Action
Result = maximum Every applicable question at or above target Book the assessment; build the evidence pack
Result slightly below maximum One or a few questions below target Find them in the results sheet; close them; re-rate
Result well below maximum Systemic gaps, usually the level 2 → 3 integration and ‘extended period’ evidence Treat as a gap analysis; plan three to six months
Many ‘n.a.’ entries Scope may be under-declared Check each exclusion against the objective’s applicability; auditors challenge n.a.

Completing the TISAX self-assessment honestly

  1. Rate against the definitions, not against effort. The question is whether the evidence for level 3 exists — documented process, documented interfaces, sustained use — not whether the team worked hard on it.
  2. Attach the evidence reference as you rate. The ISA has a column for it. A rating with no reference is the first thing an AL 2 plausibility check pulls on.
  3. Use n.a. only where the objective’s applicability table says so. The handbook points to the applicability table (Table 8 in the handbook; the ISA’s own applicability columns) for which questions apply to which objective. “We don’t do that” is not n.a.; it is level 0.
  4. Rate the whole scope. Every location in scope is assessed at AL 2 and AL 3. A rating true at headquarters and false at the second site is false.
  5. Have someone else sample it. Ten questions, evidence produced. The ISA’s own compliance and internal-audit control questions are the natural mechanism.
  6. Re-rate after closing gaps. The result must be recomputed from the workbook, not adjusted by hand.

From self-assessment to assessment

A completed self-assessment at the maximum score is the entry ticket; the audit provider’s job at AL 2 is to test whether it is plausible, and at AL 3 to verify it. Two things make the transition smooth. Organize evidence by control question in the order the ISA lists them, so that the AL 2 interview and the AL 3 walkthrough follow the auditor’s own sequence. And keep the self-assessment current: the label is valid three years, ISA versions change annually, and a self-assessment refreshed each year against the current catalogue is what makes the renewal assessment a repeat rather than a restart. Our guides to TISAX assessment levels and the TISAX audit checklist cover what happens next.

One version note: every TISAX assessment ordered from 1 January 2027 is assessed against ISA2027. If your self-assessment is on ISA 6 and the assessment will be ordered after that date, re-rate on ISA2027 — the Information Security control count is unchanged but requirement text and maturity expectations moved, and every prototype-protection control number changed meaning. Our guide to VDA ISA2027 lists the changes.

Frequently asked questions

What is the TISAX self-assessment?
The VDA ISA workbook completed by the participant, rating each applicable control question on a 0–5 maturity scale, producing a result score compared with the maximum. It is the basis of every TISAX assessment: checked for plausibility at AL 2 and verified on site at AL 3.

What score do we need?
A result with cutback to target equal to the maximum result score, which is 3.0 when every question applies and lower when some are not applicable. Any result below the maximum means at least one question is below its target and will become a finding.

What is the cutback?
Ratings above a question’s target count only as the target when the result is averaged, so over-rating some questions cannot compensate for under-performing on others.

Is level 3 always the target?
It is the target for most questions; the ISA sets the target per question and the maximum result score is the average of the applicable targets.

Can we submit the self-assessment as the TISAX result?
No. A self-assessment alone is assessment level 1, which is not used in TISAX. Labels are issued only after an AL 2 or AL 3 assessment by an ENX-accredited audit provider.

Where this leaves you

Treat the TISAX self-assessment as the assessment: rate every applicable question against the maturity definitions with an evidence reference beside it, respect the cutback, use n.a. only where the applicability table allows, and book the audit provider only when result equals maximum. A self-assessment done that way is what AL 2 confirms and AL 3 verifies — and what makes the renewal three years later a re-rating rather than a rebuild.

References

More on TISAX

The VDA ISA Statement of Applicability workbook, the internal audit checklist, the KPI dashboard that evidences level 4 and the policy set behind the Information Security catalogue are in the TISAX Documentation Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.