Framework comparison
TISAX and ISO/IEC 27001: what transfers, and what does not
These are often discussed as alternatives. They are not. One is a certifiable management system standard; the other is an automotive assessment and exchange mechanism. Understanding precisely how they differ tells you how much of your existing work counts — and it is usually more than teams expect.
Last updated 25 August 2026 · ISAREADY Editorial Team
What each one actually is
ISO/IEC 27001 is an international standard specifying requirements for an information security management system. Organisations may choose to be certified against it by an independent certification body. ISO publishes the standard; it does not certify organisations. Accreditation of the certification body is not compulsory — where it exists it provides independent confirmation of that body’s competence.
TISAX is an assessment and exchange mechanism operated by ENX Association for the automotive industry. Assessments are performed by TISAX audit providers approved by ENX Association against the ISA catalogue published by the VDA, and the result can be shared with other participants.
Official framework information The above describes the publicly documented relationship between these bodies and instruments. Verify current details before relying on them contractually.
Side by side
| ISO/IEC 27001 | TISAX | |
|---|---|---|
| Nature | Certifiable management system standard | Assessment and exchange mechanism |
| Owner | ISO / IEC | ENX Association (catalogue published by the VDA) |
| Assessed by | Independent certification body (accreditation optional) | TISAX audit provider approved by ENX Association |
| Result | Certificate with a defined scope | Result shared with participants as a label |
| Audience | Any sector | Automotive supply chain |
| Typical driver | Market expectation, tenders, group policy | A customer requirement in the automotive chain |
What can usually be reused
ISAREADY recommendation How much of an existing management system carries over is not a fixed quantity — it depends on scope alignment, how consistently the system actually operates, what your customer requires, and how well your evidence maps. What follows is where reuse is normally available, not a promise that it will be available to you.
If you operate an ISO/IEC 27001 management system, these disciplines are typically the same work consumed differently rather than work done twice:
- Scope definition and the discipline of maintaining it.
- Risk method, register, treatment and residual risk acceptance.
- Policy set with ownership, approval and review cycles.
- Access control, asset inventory and classification practice.
- Incident management and the records it produces.
- Supplier and third-party assessment.
- Internal audit programme and findings management.
- Management review and corrective action.
For teams whose management system genuinely operates — rather than existing as a document set — the remaining work is often about scope alignment and evidence organisation rather than building anything new. For teams whose certification covers a different scope, or whose system is newer than its certificate suggests, considerably more remains. The honest test is not whether you hold a certificate but whether you could produce current evidence for the controls behind it.
Where preparation still differs
- Scope framing. The two do not necessarily cover the same sites, entities or information. Aligning them deliberately is worth an afternoon.
- Automotive-specific expectations. Prototype protection, where it applies, has no direct ISO equivalent and needs its own preparation.
- Data protection. Where a data protection scope applies, it needs to be connected to the security programme rather than handled in parallel by a different team.
- Evidence presentation. Same records, different consumption. Time spent organising evidence by theme pays for itself.
Our Professional toolkit includes an ISO/IEC 27001 alignment layer with a Statement of Applicability structure, precisely so this work is done once rather than twice.
Running both as one programme
The economical approach is a single management system with two consumption views: one organised for certification, one organised for the automotive assessment. One risk register. One internal audit programme. One management review. Two ways of presenting the same evidence.
The alternative — two parallel programmes — is how organisations end up with two risk registers that disagree, which is worse than having one imperfect register.