The Information Security Assessment (ISA) is the assessment catalogue that forms the foundation of TISAX. It is developed and maintained by the ENX Working Group ISA. It is published by the VDA as VDA ISA.
The ISA provides a standardized set of information and cyber security requirements used throughout the automotive industry to assess and improve the maturity of information and cybersecurity management systems of companies. The catalogue is maintained by industry experts within the ENX Working Group ISA and serves as the common baseline for TISAX assessments worldwide.
Today, the ISA is used by thousands of organizations and audit providers to establish a common and mutually recognized understanding of information security across the automotive ecosystem.
Related Links
The automotive industry depends on the exchange of highly sensitive information between manufacturers, suppliers, service providers, software developers and engineering partners.
Without a common security baseline, every customer would need to define, assess and monitor information security requirements individually.
The ISA was created to solve exactly this challenge.
It provides:
As a result, organizations can demonstrate information security once and share assessment results with multiple business partners through TISAX via the ENX portal.

The ISA forms the basis for all TISAX assessments. From 2027 onwards, assessments, ordered within a year through an audit provider, will be conducted against the ISA version of that year. The final date to open an initial assessment under the former version is March.
With ISA updates now being released annually, the framework continues to evolve in line with changing information security requirements and industry needs.