Skip to content

TISAX Readiness Self-Assessment

An indicative view of where your organisation stands across 14 readiness themes — governance, policies, risk, access, assets, awareness, incidents, suppliers, continuity, evidence, internal audit, management review and data protection.

A little context first

This shapes which questions you are asked and how we interpret the result. Everything on this step is optional and none of it identifies you — we do not ask for your name or email until you have seen your result.

Only used on your report. Leave blank if you prefer.

32 questions · around 10 minutes · progress saved in this browser

Common questions

Is this an official TISAX assessment?
No. It is an ISAREADY self-assessment that gives an indicative readiness view. It is not conducted by a TISAX audit provider, it does not produce a TISAX label, and it does not predict or guarantee an assessment result.
Do the questions come from the official questionnaire?
No. Every question is original ISAREADY wording. They cover information security management themes that are common across management-system practice, but they do not reproduce, paraphrase or renumber any official assessment catalogue.
How long does it take?
Around ten minutes for roughly thirty questions. Your progress is saved in your browser, so you can close the tab and come back to it.
Do I have to give my email address?
Not to take the assessment. We ask for a name, company and work email at the end, because the detailed report and its PDF are sent by email. Nothing is stored on our side until you complete the questions.
How is the readiness indicator calculated?
Each answer carries points — implemented 4, partially implemented 2.5, planned 1, not implemented 0. Anything you mark not applicable is removed from both the earned points and the maximum, so declaring something out of scope neither helps nor penalises you. The indicator is earned points divided by maximum applicable points.
What happens to my answers?
Answers stay in your browser until you finish. On completion they are stored against an anonymous session so your report can be regenerated. If you provide an email address, it is linked to that record. You can ask us to delete it at any time.