Ask two companies how they prove supply chain security and you will get two unrelated answers. One will describe physical controls over goods in transit; the other will describe how it protects a customer’s designs on its own network. Both are supply chain security, and they are covered by different standards. This guide explains ISO 28000 and TISAX, and which one your customers are actually asking about.
Both sit on the same foundations as ISO 27001, so an existing ISMS shortens either route considerably.
Two routes at a glance
| Protects | Asked for by | Result | |
|---|---|---|---|
| ISO 28000 | Goods, sites and transport | Logistics, freight and manufacturing partners | Certification |
| TISAX | Information, prototypes and designs | Automotive OEMs and their suppliers | Shared assessment label |
ISO 28000: securing the physical chain
ISO 28000 treats the supply chain as a system to be secured rather than a series of sites. It asks organisations that move, store or handle goods to identify threats along the chain — theft, tampering, diversion, unauthorised access — and manage them through a security management system with the familiar plan, do, check, act rhythm.
It suits freight forwarders, warehouse operators, port and terminal businesses and manufacturers with exposed inbound or outbound logistics. Our ISO 28000 Supply Chain Security Toolkit provides 29 templates covering the security management system manual and policy, risk assessment and treatment procedures, operational planning, physical security, and the supporting procedure set.
TISAX: the automotive answer to repeated audits
TISAX exists because automotive suppliers were being audited on information security repeatedly by different OEMs, each with its own questionnaire. Built on the VDA ISA catalogue and administered through ENX, it produces one assessment result that participants mutually recognise.
Two things surprise firms new to it. First, it is not a certification in the ISO sense — you receive a label shared through the ENX platform with the partners you choose. Second, the scope reaches beyond conventional information security into prototype protection: physical security of pre-release vehicles and parts, and controls on photography and filming.
Our TISAX Documentation Toolkit provides 39 templates covering the ISMS policy and manual, scope definition and implementation roadmap, and the assessment-specific documents including the prototype protection and photo and film policies.
Which one applies to you
The question is what your customer is worried about. If they are concerned that goods could be stolen, tampered with or diverted, that is ISO 28000. If they are worried about their intellectual property leaking from your network or their unreleased model appearing in a photograph, that is TISAX — and if you supply the automotive industry, you will be told which assessment level you need.
Firms that do both — a logistics provider handling automotive parts, for instance — will find the management-system layer common and only the technical controls diverging.
Frequently asked questions
Is TISAX a certification?
Not formally. TISAX produces an assessment result and label shared through the ENX platform with partners you nominate, rather than a publicly issued certificate.
Does ISO 27001 cover TISAX requirements?
It covers a substantial part of the information security baseline, but not all of it. TISAX adds automotive-specific requirements, most notably prototype protection, which ISO 27001 does not address.
Who needs ISO 28000?
Organisations whose customers care about the physical integrity of goods in the chain — logistics operators, warehousing, ports and terminals, and manufacturers with high-value or high-risk shipments.