TISAX vs ISO/IEC 27001: What Actually Transfers
The two are often discussed as alternatives. They are different kinds of thing. Here is what each one is, which work transfers between them, and where preparation still differs.
"Should we do TISAX or ISO 27001?" is a question we hear often, and it contains a false premise. They are not competing options — they are different kinds of instrument, and for most automotive suppliers the practical answer is that one substantially serves the other.
What each one is
ISO/IEC 27001 is an international standard specifying requirements for an information security management system. Organisations may choose to be certified against it by an independent certification body. ISO does not itself certify organisations, and accreditation of the certification body is not compulsory — it provides independent confirmation of that body's competence.
TISAX is an assessment and exchange mechanism operated by ENX Association for the automotive industry. Assessments are performed by audit providers approved by ENX Association against the ISA catalogue published by the VDA, and the result can be shared with other participants.
The above describes the publicly documented relationship between these bodies. Verify current details against ENX Association, VDA and ISO documentation before relying on them contractually.
Is TISAX a certification?
Not in the sense that ISO/IEC 27001 is, and the imprecision matters when you write about it in tender responses.
ISO/IEC 27001 produces a certificate. TISAX produces an assessment result that can be shared as a label through the exchange mechanism. Describing yourself as "TISAX certified" is a small error that a well-informed customer will notice.
The correct terms: TISAX assessment, TISAX label, and TISAX audit provider — ENX Association approves audit providers and monitors the quality of their work.
What can usually be reused
How much carries over is not fixed. It depends on scope alignment, how consistently your management system actually operates, what your customer requires, and how well your evidence maps. The following is where reuse is normally available — not a guarantee that it will be available to you:
- Scope definition and the discipline of maintaining it
- Risk method, register, treatment and residual risk acceptance
- Policy set with ownership, approval and review cycles
- Access control, asset inventory and classification
- Incident management and the records it produces
- Supplier and third-party assessment
- Internal audit programme and findings management
- Management review and corrective action
For teams whose management system genuinely operates, the remaining work is often about scope alignment and evidence organisation rather than building anything new. For teams whose certificate covers a different scope, or whose system is newer than the certificate suggests, considerably more remains. The honest test is not whether you hold a certificate but whether you could produce current evidence for the controls behind it.
Where preparation still differs
Scope framing. The two do not necessarily cover the same sites, entities or information. Aligning them deliberately is worth an afternoon and prevents a category of confusing findings.
Automotive-specific expectations. Prototype protection, where it applies, has no direct ISO equivalent. It needs its own preparation, including physical access rules and records, and rules for photography, visitors, transport and disposal.
Data protection. Where a data protection scope applies, it needs to be connected to the security programme — same incident route, same supplier assessment, same access reviews — rather than handled in parallel by a different team with a different process.
Evidence presentation. The same records, consumed differently. Time spent organising evidence by theme rather than by document type pays for itself.
Which should you do first?
There is no universally correct order. It follows from four things:
- What your customers contractually require, and by when. A requirement with a date attached outranks everything else here.
- Your scope. If the sites and information your customers care about are narrower than your whole organisation, a scoped assessment may be reachable far sooner than a certification covering everything.
- Your existing maturity. An operating management system changes the calculation; a documented but unexercised one does not.
- Your wider market. If you also sell into sectors expecting ISO/IEC 27001 certification, building the management system first and treating the automotive assessment as an extension can be more economical — provided the timeline allows a certification cycle.
In our experience the automotive requirement is usually the one with a date on it, which tends to settle the sequence in practice. That is an observation about the organisations we see, not a rule.
Running both as one programme
The economical approach is one management system with two consumption views.
One risk register. One internal audit programme. One management review. One evidence archive. Two ways of presenting the same material, and a mapping table that says which requirement each activity satisfies in each framework.
The alternative — two parallel programmes — reliably produces two risk registers that disagree with each other, which is worse than one imperfect register. It also doubles the maintenance burden at exactly the point where maintenance is what determines whether readiness survives the year.
Our Professional toolkit includes an ISO/IEC 27001 alignment layer with a Statement of Applicability structure for exactly this reason.
A note on what neither one promises
Neither instrument makes an organisation secure. Both are mechanisms for demonstrating that a management system exists and operates. That is genuinely valuable — a supplier that can show what it does is a different proposition from one that cannot — but it is not the same as being resistant to attack, and treating a label as an outcome rather than as evidence of a process is how programmes lose their point.
For the full comparison, see our TISAX vs ISO/IEC 27001 page.
- ISO 27001
- TISAX
- comparison
How ready is your organisation?
The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.
Start Free Assessment