Skip to content
ISO/IEC 270014 min read

TISAX vs ISO/IEC 27001: What Actually Transfers

The two are often discussed as alternatives. They are different kinds of thing. Here is what each one is, which work transfers between them, and where preparation still differs.

ISAREADY Editorial Team

"Should we do TISAX or ISO 27001?" is a question we hear often, and it contains a false premise. They are not competing options — they are different kinds of instrument, and for most automotive suppliers the practical answer is that one substantially serves the other.

What each one is

ISO/IEC 27001 is an international standard specifying requirements for an information security management system. Organisations may choose to be certified against it by an independent certification body. ISO does not itself certify organisations, and accreditation of the certification body is not compulsory — it provides independent confirmation of that body's competence.

TISAX is an assessment and exchange mechanism operated by ENX Association for the automotive industry. Assessments are performed by audit providers approved by ENX Association against the ISA catalogue published by the VDA, and the result can be shared with other participants.

The above describes the publicly documented relationship between these bodies. Verify current details against ENX Association, VDA and ISO documentation before relying on them contractually.

Is TISAX a certification?

Not in the sense that ISO/IEC 27001 is, and the imprecision matters when you write about it in tender responses.

ISO/IEC 27001 produces a certificate. TISAX produces an assessment result that can be shared as a label through the exchange mechanism. Describing yourself as "TISAX certified" is a small error that a well-informed customer will notice.

The correct terms: TISAX assessment, TISAX label, and TISAX audit provider — ENX Association approves audit providers and monitors the quality of their work.

What can usually be reused

How much carries over is not fixed. It depends on scope alignment, how consistently your management system actually operates, what your customer requires, and how well your evidence maps. The following is where reuse is normally available — not a guarantee that it will be available to you:

  • Scope definition and the discipline of maintaining it
  • Risk method, register, treatment and residual risk acceptance
  • Policy set with ownership, approval and review cycles
  • Access control, asset inventory and classification
  • Incident management and the records it produces
  • Supplier and third-party assessment
  • Internal audit programme and findings management
  • Management review and corrective action

For teams whose management system genuinely operates, the remaining work is often about scope alignment and evidence organisation rather than building anything new. For teams whose certificate covers a different scope, or whose system is newer than the certificate suggests, considerably more remains. The honest test is not whether you hold a certificate but whether you could produce current evidence for the controls behind it.

Where preparation still differs

Scope framing. The two do not necessarily cover the same sites, entities or information. Aligning them deliberately is worth an afternoon and prevents a category of confusing findings.

Automotive-specific expectations. Prototype protection, where it applies, has no direct ISO equivalent. It needs its own preparation, including physical access rules and records, and rules for photography, visitors, transport and disposal.

Data protection. Where a data protection scope applies, it needs to be connected to the security programme — same incident route, same supplier assessment, same access reviews — rather than handled in parallel by a different team with a different process.

Evidence presentation. The same records, consumed differently. Time spent organising evidence by theme rather than by document type pays for itself.

Which should you do first?

There is no universally correct order. It follows from four things:

  1. What your customers contractually require, and by when. A requirement with a date attached outranks everything else here.
  2. Your scope. If the sites and information your customers care about are narrower than your whole organisation, a scoped assessment may be reachable far sooner than a certification covering everything.
  3. Your existing maturity. An operating management system changes the calculation; a documented but unexercised one does not.
  4. Your wider market. If you also sell into sectors expecting ISO/IEC 27001 certification, building the management system first and treating the automotive assessment as an extension can be more economical — provided the timeline allows a certification cycle.

In our experience the automotive requirement is usually the one with a date on it, which tends to settle the sequence in practice. That is an observation about the organisations we see, not a rule.

Running both as one programme

The economical approach is one management system with two consumption views.

One risk register. One internal audit programme. One management review. One evidence archive. Two ways of presenting the same material, and a mapping table that says which requirement each activity satisfies in each framework.

The alternative — two parallel programmes — reliably produces two risk registers that disagree with each other, which is worse than one imperfect register. It also doubles the maintenance burden at exactly the point where maintenance is what determines whether readiness survives the year.

Our Professional toolkit includes an ISO/IEC 27001 alignment layer with a Statement of Applicability structure for exactly this reason.

A note on what neither one promises

Neither instrument makes an organisation secure. Both are mechanisms for demonstrating that a management system exists and operates. That is genuinely valuable — a supplier that can show what it does is a different proposition from one that cannot — but it is not the same as being resistant to attack, and treating a label as an outcome rather than as evidence of a process is how programmes lose their point.

For the full comparison, see our TISAX vs ISO/IEC 27001 page.

  • ISO 27001
  • TISAX
  • comparison
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

How ready is your organisation?

The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.

Start Free Assessment

Continue reading

ISA20274 min read

ISA 6 to ISA2027: Preparing for the Transition

A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.

Read
TISAX Readiness5 min read

How to Prepare for a TISAX Assessment

A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.

Read

From requirements to real readiness

The toolkit turns the guidance in these articles into a working programme: gap assessment, risk treatment, evidence, internal audit and management review as one connected system.