TISAX assessment levels decide how hard the audit provider looks. Level 1 is a self-assessment nobody checks; level 2 is a plausibility check of your self-assessment by web conference with evidence sampled; level 3 is the full on-site assessment with interviews, inspection and document review. Which level applies is not your choice — it follows from the assessment objectives your customer asks for, which in turn follow from the protection needs of the information you handle for them.
Most suppliers misread this in one of two directions: they register for a lower level than the objective requires and have to start again, or they assume level 3 is “the real TISAX” and pay for on-site days no customer asked for. This guide explains the three levels as the ENX participant handbook defines them, the objective-to-level mapping, the “AL 2.5” variant, and what each level means for preparation, cost and evidence.

Where TISAX assessment levels come from
TISAX is built on the VDA ISA catalogue and operated by ENX Association. A customer who requires TISAX names one or more assessment objectives — the twelve currently available run from “Confidential” and “High availability” through the prototype objectives to “Data” and “Special data” — and each objective carries protection needs that the ISA classifies as normal, high or very high.
The participant handbook is explicit: “The higher the protection needs, the more your partner is interested in making sure that it is safe to let you handle their information. Therefore, TISAX differentiates three assessment levels.” The assessment level “defines which assessment method the audit provider has to apply”, and a higher level “increases the effort that goes into the assessment”. Our guide to TISAX labels and the twelve assessment objectives covers what each objective requires; this post covers how each is assessed.
The three TISAX assessment levels
| Level | Method (ENX participant handbook) | Evidence checked | Used in TISAX? |
|---|---|---|---|
| AL 1 | An auditor checks that a completed self-assessment exists; does not assess its content; requires no further evidence | None | No — results have a low trust level and are not used in TISAX; a partner may request one outside TISAX |
| AL 2 | Plausibility check of your self-assessment for all locations in scope, supported by checking evidence and an interview with the person in charge of information security, generally by web conference | Sampled evidence; interview | Yes — for high protection needs |
| AL 2.5 (variant) | A full remote assessment instead of the plausibility check: the auditor verifies whether the ISMS fulfils the applicable requirements, without the on-site activities of AL 3 | Full verification, remotely | Yes — an alternative method for AL 2 objectives |
| AL 3 | Comprehensive verification: the AL 2 activities plus on-site inspection of locations, interviews with process owners and staff, and inspection of the physical environment | Full verification, on site | Yes — for very high protection needs and prototype objectives |
AL 1
The handbook is candid that AL 1 exists “mainly for internal purposes in the true sense of a self-assessment”. No TISAX label is issued from it. Its practical role is the first step of every TISAX journey: the self-assessment against the ISA that AL 2 and AL 3 then test. Our guide to the TISAX self-assessment covers how to complete it and read the score.
AL 2
The audit provider takes your self-assessment as the starting point and checks whether it is plausible: evidence is requested and reviewed, and the person responsible for information security is interviewed, normally by web conference. Two options exist. You can request the interview in person, and if you hold evidence you do not want to send — “for your eyes only” material — you can request an on-site inspection so the auditor can still check it. AL 2 applies to the “high” protection-need objectives: Confidential, High availability, Test vehicles, Proto events and Data.
AL 2.5
Not a formal level but a recognized method: the audit provider conducts a full remote assessment rather than a plausibility check, verifying fulfilment of each applicable requirement as at AL 3 but without visiting. Formally the result is an AL 2 assessment. Some audit providers offer it as their standard AL 2 approach; ask before signing, because the effort on your side is closer to AL 3.
AL 3
The full assessment. On top of the AL 2 activities, the audit provider comes on site to inspect locations, interviews process owners and selected staff, and examines the physical environment — which for the prototype objectives means the workshops, test tracks and storage areas themselves. AL 3 applies to the “very high” protection-need objectives: Strictly confidential, Very high availability, Proto parts, Proto vehicles and Special data. Our guide to TISAX prototype protection covers the AL 3 prototype assessments specifically.
Objective to level: the mapping
| Assessment objective | Protection needs | Assessment level |
|---|---|---|
| Confidential | High | AL 2 |
| Strictly confidential | Very high | AL 3 |
| High availability | High | AL 2 |
| Very high availability | Very high | AL 3 |
| Proto parts | Very high | AL 3 |
| Proto vehicles | Very high | AL 3 |
| Test vehicles | High | AL 2 |
| Proto events | High | AL 2 |
| Data | High | AL 2 |
| Special data | Very high | AL 3 |
| Info high (legacy, selectable until 31 March 2024) | High | AL 2 |
| Info very high (legacy) | Very high | AL 3 |
Two consequences follow from the way TISAX assessment levels are assigned. If a customer asks for one AL 3 objective and one AL 2 objective in the same scope, the assessment runs at AL 3 for everything the objectives share, because the auditor is on site anyway. And the level cannot be traded down: a supplier that offers to “do AL 3 at AL 2 cost” is offering AL 2.5, which is a method, not a lower level.
What each level means for preparation and cost
- Preparation is the same at every one of the TISAX assessment levels. The ISA self-assessment must be complete with target maturity levels met on every applicable question; AL 2 and AL 3 differ in how thoroughly that claim is tested, not in what is required. A supplier that treats AL 2 as “lighter requirements” fails the plausibility check.
- Evidence handling differs. At AL 2 you send evidence; organize it per control question before the audit, because the auditor samples and the interview is short. At AL 3 you show it; the auditor decides what to look at on site.
- Effort and cost scale with the level and the locations. AL 3 adds travel and on-site days per location in scope. Our guide to TISAX certification cost gives the ranges; the assessment level is the largest single driver after the number of sites.
- Labels are the same across TISAX assessment levels. An AL 2 label and an AL 3 label are both TISAX labels, valid three years, exchanged on the ENX platform. The level is recorded with the result, and a partner requiring AL 3 will see an AL 2 result as insufficient.
ISA2027 — the catalogue for every assessment ordered from 1 January 2027 — changes control text and maturity requirements, not the assessment levels or their mapping to objectives. Our guide to VDA ISA2027 covers what did change.
Frequently asked questions
What are the TISAX assessment levels?
AL 1, a self-assessment whose existence is checked but whose content is not (not used for TISAX labels); AL 2, a plausibility check of the self-assessment with sampled evidence and a web-conference interview; AL 3, a full on-site assessment with inspection and interviews. AL 2.5 is a full remote assessment used as an alternative AL 2 method.
Who decides the assessment level?
The assessment objective does. Objectives with high protection needs (Confidential, High availability, Test vehicles, Proto events, Data) are assessed at AL 2; those with very high protection needs (Strictly confidential, Very high availability, Proto parts, Proto vehicles, Special data) at AL 3.
Can we choose AL 2 to save money if the customer asked for AL 3?
No. The level follows the objective, and a partner requiring an AL 3 objective will not accept an AL 2 result. AL 2.5 is a remote method for AL 2 objectives, not a discount on AL 3.
Is the on-site visit mandatory at AL 3?
Yes. AL 3 comprises the AL 2 activities plus on-site inspection, interviews and examination of the physical environment at the locations in scope.
Do the levels change under ISA2027?
No. ISA2027 changes control requirements and maturity levels; the three assessment levels and the objective-to-level mapping are unchanged.
Where this leaves you
Start from the objective your customer named, read the level off the mapping, and prepare to the same standard whichever it is — the self-assessment must be true at every level. Then organize evidence for the method: a per-question evidence pack for AL 2’s sampling and interview, and site readiness for AL 3’s inspection. The level sets the audit provider’s effort; it never lowers yours.
References
- ENX Association: TISAX Participant Handbook — Sections 4.3.3.5 (protection needs and assessment levels) and 5.4 (assessment process).
- ENX Association: VDA ISA downloads — The ISA catalogue used for the self-assessment.
More on TISAX
- TISAX assessment levels — you are here
- VDA ISA2027: what changed
- TISAX audit checklist: the seven steps
- TISAX labels: the twelve assessment objectives
- The TISAX self-assessment
- TISAX certification cost
The ISMS policy and manual, scope definition, the VDA ISA Statement of Applicability workbook, the internal audit checklist and the implementation roadmap that carry a supplier from self-assessment to AL 2 or AL 3 are in the TISAX Documentation Toolkit, or start with the free templates.