Agentic compliance for TISAX®

TISAX®, from the ISA self-assessment to your label.

TISAX® is the automotive industry's assessment and exchange mechanism, run by the ENX Association on the VDA ISA catalogue. It is not a certification: an ENX-accredited audit provider assesses you, and the result is a label your customers can see. Teddy's agents prepare each part on the controls you already run.

Level 3Target maturity, checked per requirement
Assessment levelAL2 or AL3, prepared
3 yearsLabel validity, evidence kept up to date
What TISAX® asks for

Six parts of a TISAX® assessment.
Each one has a home in Teddy.

TISAX® is not a certification. An ENX-accredited audit provider assesses your company against the VDA Information Security Assessment (ISA) catalogue, and the result is shared as a label through the ENX portal. Here is what goes into it and where it lives in Teddy.

Assessment objectivesThe labels you need

Your customer's request decides which objectives apply: confidentiality, availability, prototype protection or data protection. Each objective brings its own ISA requirements.

In TeddyObjectives set from your customer's request
Assessment levelAL2 or AL3

The objectives set the level. AL2 is a plausibility check of documents and evidence, usually remote. AL3 is a thorough review, usually on site.

In TeddyEvidence prepared for the level you need
VDA ISA catalogueRequirements in modules

Information security applies to every assessment. Prototype protection and data protection are added when your objectives require them.

In TeddyMapped onto your existing control set
Maturity levelsLevel 3 as the target

Each control is rated from 0 to 5. Level 3, established, is the usual target: a defined standard process, applied across the scope.

In TeddyMaturity tracked per control, with evidence
Self-assessmentThe ISA workbook

Before the assessment, you rate your own maturity in the ISA workbook. The audit provider uses it as the starting point.

In TeddyDrafted from your controls and evidence
Label and exchangeResults shared through ENX

After the assessment and any corrective actions, you receive the label and decide which partners can see your results. Labels are valid for three years.

In TeddyRenewal and catalogue updates tracked
Step 1RegistrationIn the ENX portal
Step 2Self-assessmentISA workbook, target maturity
Step 3AssessmentBy an ENX-accredited audit provider
Step 4LabelValid for three years
The problem

Your customer wants a label.
The ISA workbook is waiting.

Automotive customers ask for TISAX® before they share drawings, data or prototypes. The catalogue is detailed, the maturity model is unfamiliar, and the deadline comes from the customer.

01A deadline set by your customer

Teddy plans the work backwards from your assessment date.

02How mature each process is

The Gap Audit Agent rates every requirement and shows what is still missing for level 3.

03The TISAX® questionnaire

Teddy drafts the answers from your controls and evidence.

04An ISA workbook, a deadline and an AI chat. Still no label.

Someone fills in the ISA workbook by hand, the customer wants the label by quarter end, and the ISO 27001 evidence sits in another folder. ChatGPT can explain maturity levels, but it cannot see your controls. Teddy prefills the self-assessment from the controls and evidence you already have.

How it works

From the customer's request to your label

Teddy's agents scope the assessment, map the ISA onto your controls and prepare the self-assessment. You decide, and a compliance engineer is there when the audit provider arrives.

01 Certification Agent

Set objectives from your customer's request

Teddy reads what your customer asks for and proposes the assessment objectives and the resulting assessment level. You confirm before anything is booked.

TISAX® scope · Acme Inc.Draft
ConfidentialSelected
High availabilitySelected
Prototype protectionNot requested
Assessment levelAL2
02 Gap Audit Agent

Map the ISA onto your existing controls

Each ISA requirement is mapped onto the controls you already run, with a maturity rating and the evidence behind it.

VDA ISA 6 · information securityGap audit
At maturity level 3 or higherMost controls
Below target9 controls
Not yet covered4 controls
Teddy: Your ISO 27001 evidence counts for most requirements. I flagged where the ISA asks for more.
03 Policy Agent

Fill the gaps, not the whole workbook

The Policy Agent drafts only what is missing, such as a log review procedure or supplier security clauses, so you raise maturity where it counts.

Open itemsTo reach level 3
Security event log reviewDraft
Supplier security clausesDraft
Mobile device rulesApproved
04 Evidence Agent

Evidence the audit provider can follow

The Evidence Agent collects proof from connected tools and links it to each ISA requirement, so the audit provider sees what supports each rating.

EvidenceLinked to the ISA
Entra ID MFA reportCurrent
AWS logging configurationCurrent
Visitor management recordsMissing
05 Gap Audit Agent

Map once, comply many

Controls you already run for ISO 27001, NIS2 or SOC 2 count for TISAX® too. Teddy maps every framework onto one control set and shows only what is new.

Shared controlsOne control set
ISA requirements covered by ISO 2700176%
Evidence reused168 items
New for TISAX® onlyMaturity ratings
Teddy: The ISA asks how mature a control is, not only whether it exists. I linked evidence for each rating.
Never stuck

Ask Teddy which objectives your OEM really needs.

Ask in plain language which objectives you need or what a maturity level means. Teddy answers from your live program. For the assessment, our compliance engineers are at your side.

1

Ask TeddyWhich labels do we need? Is this control at level 3? Teddy knows the ISA and your setup.

2

Agents do the workScope, ISA mapping, missing documents and evidence, each with its source.

3

Our team backs you upCompliance engineers help you choose an audit provider and join your assessment.

TeddyAcme Inc. · TISAX®
Do we need prototype protection?
Only if you handle prototype parts, vehicles or events for your customer. Northwind's request lists confidentiality and availability.
  • ConfidentialRequested
  • High availabilityRequested
  • Prototype protectionNot requested
Shall I confirm the objectives with Northwind before you book the assessment?
Draft confirmationAsk our team
CEYour compliance engineer helps you choose an audit provider and joins the assessment.
FAQ

Questions about TISAX®

Is TISAX® a certification?

No. TISAX® is an assessment and exchange mechanism. An ENX-accredited audit provider assesses you, and you receive a label instead of a certificate. You decide which partners can see your results in the ENX portal.

AL2 or AL3?

Your assessment objectives decide. Confidential and high availability require AL2. Strictly confidential, very high availability and prototype protection require AL3, which usually means an on-site assessment.

We have ISO 27001. How much counts?

A large part of the information security module. The ISA adds maturity ratings, automotive-specific requirements and, where needed, prototype protection and data protection. Teddy shows the difference control by control.

What changes with ISA2027?

The VDA published ISA2027 in 2026. It applies to assessments ordered from 1 January 2027, and labels that are already valid are not affected. Teddy maps your controls to the catalogue version your next assessment uses.

Your TISAX® label, prepared on the controls you already run.

Start with a gap audit against the VDA ISA.

TISAX® is a registered trademark of the ENX Association. Teddy is not affiliated with ENX.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long TISAX® takes, and how Teddy cuts the preparation to weeks

Typical4 to 9 months

From kickoff to label. Preparation alone takes 3 to 12 months, depending on how mature your information security already is.

With TeddyWithin weeks

Ready for the assessment. Objectives are clarified up front, the VDA ISA self-assessment is drafted from your existing controls, and evidence is linked per maturity level.

  • Ten assessment objectives: ENX currently lists ten. Your OEM defines which ones you need, and the objective sets the assessment level.
  • Participant ID: ENX issues it within three to five days after approving your registration.
  • What stays fixed: the audit provider's dates. If the assessment finds deficiencies, you have nine months to fix them and secure the label through a follow-up assessment.
  • Your report stays yours: by default only you receive the detailed report. Your customers see the label.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

What trips suppliers up in TISAX®

  1. The scope registered is not the scope that exists.

    Suppliers register for one set of objectives, and the assessor finds prototype work or locations that were left out. Assessors find this gap more often than most suppliers expect.

  2. “We have ISO 27001, so TISAX is easy.”

    It helps, but it does not replace it. The gaps sit in automotive-specific areas, above all physical prototype protection, which many suppliers have never had to show at this level.

  3. The self-assessment is filled in with documents, not practice.

    The label requires a defined maturity level per control. A written policy alone does not show that a process is established and lived, and that is what the assessor checks.