TISAX vs ISO 27001 is the question almost every automotive supplier asks the first time a German OEM sends a security questionnaire. Both look like information security credentials, both involve an external audit, and both are built on similar controls. Yet they are not interchangeable, and choosing the wrong one first can cost you a quarter of delayed onboarding.
The short version: ISO 27001 certifies that your organization runs an information security management system (ISMS). TISAX is an assessment and exchange mechanism that proves you meet the automotive industry’s VDA ISA requirements at a defined assessment level, and lets you share the result with customers. This guide shows where they overlap, where they differ and how to decide. All figures are typical ranges, not quotes.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What TISAX and ISO 27001 actually are
ISO 27001 is an international standard that specifies the requirements for an ISMS. You define scope, assess risks, select controls from Annex A (93 controls in the 2022 edition), document a Statement of Applicability and operate the system. An accredited certification body audits you and issues a certificate if you conform.
TISAX stands for Trusted Information Security Assessment Exchange. It is run by the ENX Association on behalf of the German automotive industry. You are assessed against the VDA ISA catalogue by an audit provider approved by ENX, and the result is published to a portal where your customers can look it up. See our guide on the TISAX exchange platform for how that sharing works.
The key distinction is purpose. ISO 27001 is a general management system standard. TISAX is a sector-specific assessment that also measures maturity and can cover prototype protection and data protection. That is why the TISAX vs ISO 27001 debate is really a question of who is asking you for proof.
How much do TISAX and ISO 27001 overlap?
Quite a lot. The information security part of the VDA ISA catalogue draws heavily on ISO 27001 and ISO 27002, and recent editions have been aligned with the 2022 versions of both. If you already run a working ISMS, you have probably done a large share of the work TISAX expects: risk assessment, policies, asset management, access control, supplier security, incident handling and internal audit.
Free third-party risk assessment
How much risk does this vendor bring?
Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.
Start the free vendor risk assessment → or View premium report sample
Typical shared building blocks include:
| Aspect | TISAX | ISO 27001 |
|---|---|---|
| Owner | ENX Association, catalogue by VDA | ISO/IEC, certified by accredited bodies |
| What you receive | Assessment result and labels shared on the ENX portal | Certificate of conformity to the standard |
| Basis | VDA ISA catalogue | ISO/IEC 27001 and Annex A |
| Scope focus | Automotive data, prototypes, data protection modules | Any organization, any sector |
| Maturity scoring | Yes, each control is scored by maturity level | No, conformity is pass or fail per requirement |
| Typical validity | Three years | Three years with annual surveillance audits |
| Who asks for it | OEMs and their tier suppliers | Customers in every industry |
- Information security policy and defined roles
- Risk assessment and treatment process
- Asset inventory and classification
- Access control, cryptography and operations security
- Supplier and outsourcing controls
- Incident management and business continuity
- Internal audit and management review
Where TISAX vs ISO 27001 differs in practice
The differences matter more than the overlap when you are budgeting. First, TISAX scores maturity. Each control is rated on a scale, and your customer expects a target level, usually level 3, to be reached. ISO 27001 has no maturity scale; a requirement is met or it is not.
Second, TISAX has optional modules. Prototype protection adds physical and organizational requirements for test vehicles, components and events, and data protection covers personal data handled on behalf of an OEM. ISO 27001 has no equivalent modules. Read our TISAX labels guide to see which ones apply to you.
Third, the assessment levels differ. TISAX defines levels based on how much evidence the auditor collects, from a plausibility check to an on-site audit. Our article on TISAX assessment levels explains AL2 and AL3 in detail.
Fourth, ISO 27001 is scoped by you. TISAX scope is tied to sites and to what the customer needs. An ISO 27001 certificate that covers only your software team will not help if the OEM is sending data to your engineering plant.
Does an ISO 27001 certificate replace TISAX?
Usually no. An ISO 27001 certificate does not produce a TISAX result on the ENX portal, and OEMs that require TISAX generally want the result and the right labels, not a certificate. Some customers will accept ISO 27001 as supporting evidence during onboarding, but you should confirm in writing with your customer.
The reverse also holds. A TISAX result does not make you ISO 27001 certified, because the assessment is not a certification audit of an ISMS against the standard. If your non-automotive customers ask for ISO 27001, you still need that certificate.
What ISO 27001 does give you is a head start. Your existing documentation can be mapped to VDA ISA controls, which is the practical way to cut TISAX effort. Our TISAX self-assessment guide shows how to do that mapping before you book an auditor.
Cost and timeline: TISAX vs ISO 27001
Budgets depend on size, number of sites and readiness. As a typical range, small and mid-size suppliers spend several thousand to tens of thousands of euros on an external assessment, and the same scale of company spends a comparable amount on an ISO 27001 certification audit. Consulting and internal time often exceed the audit fee for both.
Timelines are similar. Ten to fourteen weeks is common if you already have policies and evidence; six to nine months is common if you are starting from scratch. The real time sink is evidence collection, not the audit itself. For a budget breakdown, see TISAX certification cost.
One honest caveat: doing both from zero is cheaper than doing them separately. A single control set with a mapping to both frameworks avoids duplicate policies, duplicate risk assessments and duplicate audit prep.
Which one should you do first?
Use the customer as your tiebreaker. If an OEM has told you in writing that TISAX is required to receive confidential data or prototypes, do TISAX first. If you sell into many industries and only some customers are automotive, ISO 27001 gives you broader reach and TISAX can follow.
A simple decision path:
- Customer contract or questionnaire names TISAX: start with TISAX
- Customers in several sectors ask for certification: start with ISO 27001
- You already hold ISO 27001: map it to VDA ISA and add the TISAX scope and labels
- You handle prototypes: plan for the prototype protection module early
Preparing for both with one control set
The efficient approach is a single ISMS documentation set built around ISO 27001 and extended with VDA ISA-specific evidence. Start with scope and risk, write policies once, and keep a mapping table showing which document answers which VDA ISA control and which Annex A control.
A ready-made package saves the most time on the writing. The TISAX Toolkit includes templates aligned to the VDA ISA catalogue, so you can edit rather than draft. Whatever you use, have your evidence reviewed before the audit; our TISAX audit checklist lists what auditors typically ask to see.
For background on the standard itself, the ISO/IEC 27001 standard page describes the current edition and its scope. Always check the current VDA ISA version with ENX, since the catalogue is updated regularly; our note on ISA2027 covers the newest release.
A practical example of TISAX vs ISO 27001 in a supplier project
Consider a 120-person machining supplier with one plant and an ISO 9001 certificate but no security credential. A German OEM asks for TISAX with the high protection label before sharing drawings. The team is tempted to certify to ISO 27001 first because a consultant recommended it. Here the TISAX vs ISO 27001 choice is simple: the customer named TISAX, so the assessment comes first, and the ISMS built along the way can later be extended into an ISO 27001 certificate if other customers ask.
In practice the team writes one set of policies, runs one risk assessment, completes the self-assessment against the VDA ISA catalogue, fixes the gaps it finds and only then books the auditor. The same evidence folder later supports a certification audit. The lesson from this kind of project is that the order matters less than avoiding duplicated work, and that the customer’s written requirement should always decide the order. Example figures and team sizes here are illustrative only.
Common mistakes when comparing TISAX vs ISO 27001
Suppliers lose time on a few avoidable errors. They assume the ISO certificate satisfies the OEM without asking. They scope TISAX to the wrong site, so the label does not cover the plant that receives the data. They treat maturity scoring as an afterthought and arrive at the audit with policies but no operating evidence.
Another frequent mistake is starting the self-assessment too late. Auditors expect a completed self-assessment before the on-site work, and gaps discovered then extend the project. Finally, teams underestimate supplier obligations: if you pass OEM data to subcontractors, you must flow the requirements down.
TISAX vs ISO 27001 FAQ
Is TISAX the same as ISO 27001?
No. ISO 27001 is an international management system standard with a certificate. TISAX is an automotive assessment and exchange mechanism based on the VDA ISA catalogue with results shared on the ENX portal.
Can I use ISO 27001 instead of TISAX?
Generally not if your OEM requires TISAX. Some customers accept ISO 27001 as supporting evidence, but confirm in writing before relying on it.
Does ISO 27001 make TISAX easier?
Yes. Much of the VDA ISA information security content overlaps with ISO 27001 and ISO 27002, so existing policies, risk assessments and audit records can be reused after mapping.
How long are TISAX and ISO 27001 valid?
TISAX results are typically valid for three years. ISO 27001 certificates run three years with annual surveillance audits. Check the current rules with your provider.
Which costs more, TISAX or ISO 27001?
They are usually in a similar range for the same company size. The bigger cost is internal effort and consulting, which a shared control set reduces.