TISAX® is the automotive industry's assessment and exchange mechanism, run by the ENX Association on the VDA ISA catalogue. It is not a certification: an ENX-accredited audit provider assesses you, and the result is a label your customers can see. Teddy's agents prepare each part on the controls you already run.

TISAX® is not a certification. An ENX-accredited audit provider assesses your company against the VDA Information Security Assessment (ISA) catalogue, and the result is shared as a label through the ENX portal. Here is what goes into it and where it lives in Teddy.
Your customer's request decides which objectives apply: confidentiality, availability, prototype protection or data protection. Each objective brings its own ISA requirements.
The objectives set the level. AL2 is a plausibility check of documents and evidence, usually remote. AL3 is a thorough review, usually on site.
Information security applies to every assessment. Prototype protection and data protection are added when your objectives require them.
Each control is rated from 0 to 5. Level 3, established, is the usual target: a defined standard process, applied across the scope.
Before the assessment, you rate your own maturity in the ISA workbook. The audit provider uses it as the starting point.
After the assessment and any corrective actions, you receive the label and decide which partners can see your results. Labels are valid for three years.
Automotive customers ask for TISAX® before they share drawings, data or prototypes. The catalogue is detailed, the maturity model is unfamiliar, and the deadline comes from the customer.
Teddy plans the work backwards from your assessment date.
The Gap Audit Agent rates every requirement and shows what is still missing for level 3.
Teddy drafts the answers from your controls and evidence.
Someone fills in the ISA workbook by hand, the customer wants the label by quarter end, and the ISO 27001 evidence sits in another folder. ChatGPT can explain maturity levels, but it cannot see your controls. Teddy prefills the self-assessment from the controls and evidence you already have.
Northwind Motors · PurchasingWe need your TISAX® label before the next project phase.
Anna · ComplianceIs this control at maturity 2 or 3? I honestly can’t tell.
Can · EngineeringWe answered this for ISO last year. Why again?
Birgit · CEOWhich audit provider do we book, and when?
Anke · OperationsDo we need prototype protection as well?
Teddy's agents scope the assessment, map the ISA onto your controls and prepare the self-assessment. You decide, and a compliance engineer is there when the audit provider arrives.
Teddy reads what your customer asks for and proposes the assessment objectives and the resulting assessment level. You confirm before anything is booked.
Each ISA requirement is mapped onto the controls you already run, with a maturity rating and the evidence behind it.
The Policy Agent drafts only what is missing, such as a log review procedure or supplier security clauses, so you raise maturity where it counts.
The Evidence Agent collects proof from connected tools and links it to each ISA requirement, so the audit provider sees what supports each rating.
Controls you already run for ISO 27001, NIS2 or SOC 2 count for TISAX® too. Teddy maps every framework onto one control set and shows only what is new.
Ask in plain language which objectives you need or what a maturity level means. Teddy answers from your live program. For the assessment, our compliance engineers are at your side.
Ask TeddyWhich labels do we need? Is this control at level 3? Teddy knows the ISA and your setup.
Agents do the workScope, ISA mapping, missing documents and evidence, each with its source.
Our team backs you upCompliance engineers help you choose an audit provider and join your assessment.
No. TISAX® is an assessment and exchange mechanism. An ENX-accredited audit provider assesses you, and you receive a label instead of a certificate. You decide which partners can see your results in the ENX portal.
Your assessment objectives decide. Confidential and high availability require AL2. Strictly confidential, very high availability and prototype protection require AL3, which usually means an on-site assessment.
A large part of the information security module. The ISA adds maturity ratings, automotive-specific requirements and, where needed, prototype protection and data protection. Teddy shows the difference control by control.
The VDA published ISA2027 in 2026. It applies to assessments ordered from 1 January 2027, and labels that are already valid are not affected. Teddy maps your controls to the catalogue version your next assessment uses.
Start with a gap audit against the VDA ISA.
TISAX® is a registered trademark of the ENX Association. Teddy is not affiliated with ENX.
Reviewed by Sven Moritz, former CISO · October 2026
From kickoff to label. Preparation alone takes 3 to 12 months, depending on how mature your information security already is.
Ready for the assessment. Objectives are clarified up front, the VDA ISA self-assessment is drafted from your existing controls, and evidence is linked per maturity level.
Suppliers register for one set of objectives, and the assessor finds prototype work or locations that were left out. Assessors find this gap more often than most suppliers expect.
It helps, but it does not replace it. The gaps sit in automotive-specific areas, above all physical prototype protection, which many suppliers have never had to show at this level.
The label requires a defined maturity level per control. A written policy alone does not show that a process is established and lived, and that is what the assessor checks.