Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Supply chain security compared: ISO 28000 for goods and TISAX for automotive information security

Supply Chain Security: 2 Essential Assurance Routes

Ask two companies how they prove supply chain security and you will get two unrelated answers. One will describe physical controls over goods in transit; the other will describe how it protects a customer’s designs on its own network. Both are supply chain security, and they are covered by different standards. This guide explains ISO 28000 and TISAX, and which one your customers are actually asking about.

Both sit on the same foundations as ISO 27001, so an existing ISMS shortens either route considerably.

Two routes at a glance

  Protects Asked for by Result
ISO 28000 Goods, sites and transport Logistics, freight and manufacturing partners Certification
TISAX Information, prototypes and designs Automotive OEMs and their suppliers Shared assessment label

ISO 28000: securing the physical chain

ISO 28000 treats the supply chain as a system to be secured rather than a series of sites. It asks organisations that move, store or handle goods to identify threats along the chain — theft, tampering, diversion, unauthorised access — and manage them through a security management system with the familiar plan, do, check, act rhythm.

It suits freight forwarders, warehouse operators, port and terminal businesses and manufacturers with exposed inbound or outbound logistics. Our ISO 28000 Supply Chain Security Toolkit provides 29 templates covering the security management system manual and policy, risk assessment and treatment procedures, operational planning, physical security, and the supporting procedure set.

TISAX: the automotive answer to repeated audits

TISAX exists because automotive suppliers were being audited on information security repeatedly by different OEMs, each with its own questionnaire. Built on the VDA ISA catalogue and administered through ENX, it produces one assessment result that participants mutually recognise.

Two things surprise firms new to it. First, it is not a certification in the ISO sense — you receive a label shared through the ENX platform with the partners you choose. Second, the scope reaches beyond conventional information security into prototype protection: physical security of pre-release vehicles and parts, and controls on photography and filming.

Our TISAX Documentation Toolkit provides 39 templates covering the ISMS policy and manual, scope definition and implementation roadmap, and the assessment-specific documents including the prototype protection and photo and film policies.

Which one applies to you

The question is what your customer is worried about. If they are concerned that goods could be stolen, tampered with or diverted, that is ISO 28000. If they are worried about their intellectual property leaking from your network or their unreleased model appearing in a photograph, that is TISAX — and if you supply the automotive industry, you will be told which assessment level you need.

Firms that do both — a logistics provider handling automotive parts, for instance — will find the management-system layer common and only the technical controls diverging.

Frequently asked questions

Is TISAX a certification?

Not formally. TISAX produces an assessment result and label shared through the ENX platform with partners you nominate, rather than a publicly issued certificate.

Does ISO 27001 cover TISAX requirements?

It covers a substantial part of the information security baseline, but not all of it. TISAX adds automotive-specific requirements, most notably prototype protection, which ISO 27001 does not address.

Who needs ISO 28000?

Organisations whose customers care about the physical integrity of goods in the chain — logistics operators, warehousing, ports and terminals, and manufacturers with high-value or high-risk shipments.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.