The ISO 27001 vs TISAX question almost always arrives the same way: an automotive customer sends a portal invitation demanding a TISAX label by a fixed date, and someone in your business points out that you already hold an ISO 27001 certificate. The uncomfortable answer is that the certificate does not satisfy the request, even though roughly three quarters of the underlying work is the same.
This guide sets out what actually differs, how much of an existing ISMS carries across, and what changes on 1 January 2027 when the new assessment catalogue becomes mandatory. If you are choosing between the two — or being told to do both — the distinctions below are the ones that affect cost and timeline.
ISO 27001 vs TISAX: The Short Answer
ISO 27001 is an international standard you get certified against by an accredited certification body. TISAX is not a certification at all. It is an assessment and exchange mechanism run by the ENX Association for the automotive industry, and it produces labels that you share with customers through the ENX portal rather than a certificate you publish on your website.
That distinction is not pedantic. It is why there is no automatic equivalence in either direction. An OEM that requires a TISAX label needs an actual assessment against the VDA ISA catalogue by an approved audit provider; your ISO 27001 certificate will not be converted into one. Equally, a TISAX label is not recognised as an ISO 27001 substitute by customers outside the automotive sector.
ISO 27001 vs TISAX at a Glance
| ISO 27001 | TISAX | |
|---|---|---|
| Owner | ISO and IEC | ENX Association, catalogue published by VDA |
| Outcome | Certificate | Label(s) on the ENX Exchange |
| Who it is for | Any sector, worldwide | Automotive supply chain |
| Requirements source | Clauses 4–10 plus 93 Annex A controls in 4 themes | VDA ISA catalogue (ISA 6.0.3, ISA2027 from 2027) |
| Scoring | Conformity — implemented or not | Maturity model, target level 3 per control |
| Scope set by | Your organization | Your customer’s request and required labels |
| Assessment depth | Stage 1 and Stage 2 audit | AL1 self-assessment, AL2 remote, AL3 on-site |
| Validity | 3 years, annual surveillance audits | Up to 3 years, no surveillance audits |
| Results shared | Publicly, at your discretion | Only with partners you grant access to |
| Extra modules | None | Prototype protection, data protection |
Where ISO 27001 vs TISAX Requirements Actually Diverge
Maturity scoring, not conformity
This is the difference that catches certified organizations off guard. ISO 27001 asks whether a control is implemented and effective. The VDA ISA catalogue scores every control on a maturity scale and expects a target level of 3 — meaning a documented, standardised process that is consistently followed, not simply a control that exists and works.
In practice, a company can pass an ISO 27001 Stage 2 audit with controls that are effective but informally run, and still fall short of TISAX maturity expectations on the same controls. If your ISMS relies on a few capable people rather than documented process, budget time for that gap. Our ISO 27001 maturity assessment guide covers how to measure where you actually sit.
Prototype protection
Nothing in ISO 27001 corresponds to this. If you handle pre-series vehicles, components or test parts, the prototype protection module brings physical security requirements — secured areas, camera and photography controls, vehicle transport and test drive rules, visitor management — that a software-oriented ISMS will not have considered. ISA2027 has substantially restructured this module, consolidating five control groups into two domains and adding controls covering traceability of protected parts and their proper disposal, recycling or return.
Data protection
TISAX includes optional data protection labels aligned to GDPR obligations, including a higher tier for special categories of personal data. ISO 27001 addresses privacy only indirectly; that is what ISO 27701 extends. If your customer requests a data protection label, treat it as a separate workstream.
Who decides scope
Under ISO 27001 you define the scope yourself and record what applies in the Statement of Applicability, which clause 6.1.3 makes mandatory. Under TISAX, the customer’s request determines which labels and assessment level you need, and the scope generally attaches to specific locations. You have far less discretion — and much less room to keep an inconvenient site outside the boundary. See our guidance on building a defensible Statement of Applicability.
What Changes Before January 2027
Any ISO 27001 vs TISAX comparison made before mid-2026 is now partly out of date, because the catalogue behind every TISAX assessment is being replaced. VDA ISA 6 was released in October 2023 and applies to assessments ordered from 1 April 2024. On 1 July 2026 the VDA published its successor, ISA2027, which becomes mandatory for all TISAX assessments ordered from 1 January 2027. Assessments ordered during the remainder of 2026 can still run under ISA 6.0.3.
ENX has also moved to year-based version numbers and an annual release cycle, so ISA2028 is expected in summer 2027. Importantly, annual catalogue releases do not shorten label validity — labels remain valid for up to three years, and reassessment frequency is unchanged.
Two changes matter for anyone mapping from an existing ISMS. References to ISO/IEC 27001:2013 have been removed and mappings to ISO/IEC 27001:2022 refined, so a supplier still running a 2013-era control set has no bridge left. And supplier security requirements have been strengthened: organizations handling information with very high protection needs are now expected to show that their own suppliers demonstrate adequate security through a TISAX label, an equivalent third-party assessment, or a supplier audit. Our ISA2027 breakdown goes through the changes control by control.
ISO 27001 vs TISAX: Which One Do You Need?
The decision is usually made for you, but the logic is worth stating plainly.
- An automotive customer has raised a request. You need TISAX. There is no alternative route, and ISO 27001 will not close the request.
- You sell to enterprise, SaaS, healthcare or public sector buyers. ISO 27001 is the recognised signal. A TISAX label means little outside the automotive ecosystem.
- You sell to both. Do both, and build one ISMS that serves them. Certify to ISO 27001 first if you have the choice — the management system clauses give you the governance backbone that TISAX maturity scoring rewards.
- You are a tier 2 or tier 3 supplier with no request yet. ISA2027’s strengthened supplier requirements make it more likely one is coming. Starting with ISO 27001 is a reasonable hedge.
One caveat worth confirming rather than assuming: some OEMs will accept an ISO/IEC 27001 certificate covering the relevant products and services in place of a label in specific circumstances. That is a decision for the customer who raised the request, not something to plan around.
How Much of Your ISO 27001 Work Carries Over
A good deal — which is the genuinely encouraging part of the ISO 27001 vs TISAX picture. The early ISA versions were explicitly derived from ISO 27001, and although ENX now develops the catalogue independently, alignment with ISO/IEC 27001:2022 is maintained and mapped. Risk assessment and treatment, asset management, access control, supplier management, incident management, business continuity, cryptography, logging, HR security and awareness training all transfer with modest rework.
What does not transfer is the evidence of process maturity, the prototype protection module if it applies to you, and the ENX portal mechanics — registration, scope definition, choosing an approved audit provider, and sharing results. Realistically, a certified organization moving to TISAX should expect three to six months rather than a fresh twelve-month programme. The TISAX audit checklist and our guide to the ENX Exchange process cover the steps that have no ISO 27001 equivalent.
ISO 27001 vs TISAX FAQ
Can I get a TISAX label with my ISO 27001 certificate?
No. The label requires an assessment against the VDA ISA catalogue by an ENX-approved audit provider. Your certificate is useful evidence during that assessment and will shorten preparation, but it does not substitute for it.
Is TISAX harder than ISO 27001?
On the ISO 27001 vs TISAX effort comparison, TISAX is broader in places and narrower in others. TISAX demands a higher bar on process maturity and adds prototype and data protection requirements. ISO 27001 demands a full management system with internal audit, management review and continual improvement obligations that TISAX assesses less directly. Most organizations find the second framework substantially easier than the first, whichever order they take them in.
Which assessment level will my customer ask for?
AL2 is the common baseline for high protection needs and is typically handled remotely through a self-assessment and plausibility check. AL3 involves an on-site assessment and is generally required where information has very high protection needs or where prototypes are involved. The customer’s request specifies it.
Do TISAX labels need annual surveillance audits?
No, and this is a real difference in ongoing cost. ISO 27001 requires surveillance audits in each of the two years following certification, then recertification. TISAX labels run for up to three years with no interim audit, followed by a full reassessment against whichever catalogue is then current.
Should I wait for ISA2027 before starting?
If your assessment will be ordered in 2027 or later, prepare against ISA2027 now — it is published and available. If you have a customer deadline inside 2026, order under ISA 6.0.3 rather than delay; the label remains valid for its full period regardless of later catalogue releases.
Getting the Foundation Right
The organizations that handle ISO 27001 vs TISAX well stop treating them as two projects. One ISMS, documented to a maturity standard that survives scrutiny, satisfies both — with prototype protection bolted on where the parts you handle require it. The ones that struggle build a minimum-viable ISMS for the certificate, then discover the maturity bar is higher when the OEM request lands.
If documentation is where you are starting, the ISO 27001 Toolkit provides the full mandatory document set across 165 auditor-aligned templates for $99, which is the same policy and process backbone a TISAX assessor will ask to see. For the certification route itself, work through our complete ISO 27001 certification guide, and for the underlying standard, ISO publishes ISO/IEC 27001:2022 directly.