In RFQs, requirement specifications, and sales conversations, TISAX® and ISO® 27001 are often treated as if one were simply the automotive variant of the other. Historically, that is not entirely wrong: early versions of the VDA ISA catalog were derived from ISO 27001. Since then, however, the catalog behind TISAX has evolved. Today it defines its own requirements for the information security management system (ISMS). That makes it worth choosing the right standard when building the ISMS — or checking whether both might in fact be relevant for the organization. That is what the following sets out to cover.
Christopher Eller
Consider organizations that supply not only automotive OEMs and Tier-1 customers but also customers in other industries. For them, meeting both standards at once may well be worthwhile.
But even those who only intend to implement TISAX can make later ISO 27001 certification easier by building the ISMS cleanly — simply by structuring it along best-practice principles from the outset and capturing the synergies.
One important distinction upfront, because the terms are easily conflated: both TISAX and ISO 27001 concern the organization’s information security. Cybersecurity in the vehicle itself (governed by ISO/SAE 21434, UN R155, and others) is a separate regulatory domain and stays out of scope here.
Why does the automotive industry require its own proof with TISAX?
Given the intensive exchange of confidential data — via EDI interfaces, for instance, or extending all the way to insight into an OEM’s production processes — the wish to bind contracted suppliers to one’s own security conditions is entirely justified.
Initially, this happened in a decentralized way: each OEM set its own security requirements and vetted its suppliers itself — using individually designed questionnaires and self-run audits. For suppliers serving several manufacturers, this meant considerable overhead: differently worded catalogs, repeated assessments, little comparability.
This pattern was already familiar to the industry from quality assurance, where supplier requirements had been harmonized across the association (ISO 9001 → IATF 16949 / VDA 6.3). The “Information Security” working group within the VDA (German Association of the Automotive Industry) now applied the same approach to information security. Across several development stages, this produced the VDA ISA (Information Security Assessment): a shared catalog of questions built on ISO 27001 and extended with industry-specific modules.
In collaboration with the ENX Association, this became TISAX (Trusted Information Security Assessment Exchange). The idea behind it is already in the name: an assessment conducted once is made available to all authorized partners via a central platform. One proof instead of many individual audits.
There are indeed strong parallels between the automotive requirements and ISO 27001. TISAX’s requirements go further, however, particularly in the area of physical security (access authorizations, insight into prototypes). Beyond that, there are explicit requirements that only translate to the automotive industry (prototype protection).
Consistent with this, it fits the automotive industry’s self-conception to define not only the ISO standard itself but also the assessment procedure independently.
Assessment objectives: what does TISAX actually assess?
TISAX is modular. You do not register for “TISAX as a whole” but for one or more assessment objectives. There are currently twelve, spread across three criteria catalogs.
The core is the “Information Security” catalog with four objectives, tiered by protection need: “Confidential” and “Strictly confidential” for handling confidential or strictly confidential information; “High availability” and “Very high availability” for availability.
The latter concern above all the just-in-time suppliers so critical in the automotive industry, whose failure halts the customer’s production.
Almost every assessment contains at least one of these four objectives. In practice, a newcomer starts with “Confidential.” (A note on this: until March 2024, the confidentiality objectives were called “Info high” and “Info very high.” These older labels can still be found in many documents today.)
What do prototype protection and data protection cover in TISAX?
On top of this come two special catalogs: “Prototype Protection” and “Data Protection.”
The “Prototype Protection” catalog is itself subdivided into four assessment objectives:
- prototype parts,
- prototype vehicles,
- test vehicles,
- and events, including film and photo footage.
This becomes relevant as soon as unreleased components or camouflaged vehicles are in play.
The data protection catalog (“Data” and “Special Data”) applies to processing on behalf of a controller under Art. 28 GDPR and is always used in combination with information security.
Important for planning: defining the assessment objective entails more than just the raw assessment scope. It sets the assessment level, and thereby the assessment method. This determines the preparation effort — and, ultimately, the resulting costs.
Which assessment objectives are required is, in effect, decided by the customer. Not the supplier, and not the audit provider.
It is precisely at this critical point that the most expensive mistakes arise.
Care for an example from practice?
A component manufacturer, acting on a buyer’s verbal say-so, registered “Strictly confidential” as a precaution. Yet only “Confidential” was required. The difference: on-site verification (instead of the plausibility check) demands considerably more preparation — and that for a protection level no one had asked for.
That may sound unspectacular, but getting it right saves real money here. A very simple practical tip is therefore to have the required assessment objectives confirmed in writing before TISAX registration.
Understanding TISAX assessment levels: not a choice, more a consequence
The assessment level then follows from the previously defined assessment objectives. It is thus never chosen directly.
Two levels are relevant:
- AL2 as a plausibility check, in which the audit provider reviews the self-assessment along with its evidence and discusses it with the security officer via web conference.
- AL3 as full on-site verification. Interviews are conducted and the processes as actually lived are observed.
Assessment objectives with high protection need run at AL2, those with very high protection need at AL3.
AL2, however, does not automatically mean less work, even if the assessment depth is lower. Because the plausibility check stands or falls with a consistently substantiated self-assessment, the effort shifts inward. Every statement made needs evidence that holds up under critical review.
At a manufacturing operation with around 100 employees, “Confidential” can thus end up requiring a good 40 policies and well over 100 pieces of evidence. It is important to be clear that the assessor sees none of this on site. The documentation alone has to convince.
Anyone planning AL2 as “TISAX light,” then, underestimates exactly this underlying effort.
Where ISO 27001 ends and TISAX goes further
Despite the decoupling described at the outset, there is strong overlap in the ISMS core — risk management, policies, and control governance — between ISO 27001 and TISAX.
A mature ISO 27001 ISMS thus covers a substantial share of the ISA requirements.
Still, the fact that the two standards overlap does not make one proof a substitute for the other.
The OEM wants to see the label mentioned above in the ENX portal, and the assessment runs in full against the ISA catalog. An existing ISO 27001 certificate — or the work of building one — typically shortens the preparation time, but not the assessment time.
The reverse is equally part of the truth: outside the automotive industry and vehicle development, a TISAX label carries little weight.
More telling, then, is the question of where ISO-certified companies actually “get stuck” in the TISAX assessment. Rarely the core controls, but often the specifics around prototype protection — which a generic ISMS simply does not know — as well as the scoring logic.
ISO 27001 asks about conformity in binary terms. The ISA catalog, by contrast, rates every requirement on maturity levels from 0 to 5 against a target maturity that is, as a rule, 3.
In practice, the following picture often emerges: in an ISO-certified organization’s first self-assessment, maturity levels of 4 are reached almost across the board. After critical review, however, the achieved average often falls below the target maturity. Not because processes are missing, but because no one measures their effectiveness.
ISO 27001 vs. TISAX: one system, two proofs
The simple rule of thumb: whoever demands the proof decides the path.
Automotive OEMs and tier suppliers (in Europe) generally accept only TISAX, whereas ISO 27001 counts across industries.
Companies serving both worlds therefore need both proofs sooner or later.
Logically, only one ISMS is still set up — but with two assessments and their own cycles.
Since several months pass anyway between registration and the achieved TISAX label, an early look at the right sequencing pays off.
Practical insights when ISO 27001 and TISAX are on the table: one first, or the other?
A typical example shows how this plays out in practice: a system house with OEM customers wants to implement ISO 27001 as well over the medium term.
So which first?
Almost always TISAX.
The label brings immediate benefit in the automotive business. At the same time, the catalog is somewhat leaner and the assessment cheaper than a certification audit.
What matters, though, is the “how.”
For anyone who has both on the agenda and starts with TISAX in order to reach ISO 27001, this works only if the system has not been trimmed for maximum leanness.
Concretely: a TISAX ISMS that is not based on the ISMS standard diverges so strongly in structure and terminology that even the TISAX assessors struggle with it.
It is therefore advisable to design the ISMS so that it aligns roughly 80 percent with ISO 27001. This is not mandatory. But since TISAX assessors generally come from the ISO 27001 world, they inevitably expect its patterns.
Anyone who stays in the familiar wording speaks the assessors’ language. Templates and training materials can then be found for practically every document. When the ISO 27001 audit is added later, it usually leaves only 10 to 20 percent of residual effort — plus, of course, the ISO 27001 audit itself.
The reverse path — full ISO 27001 first, then TISAX — is, by practical observation, the more demanding one. The transition from ISO 27001 to TISAX is possible; essentially, only the TISAX-specific evidence still has to be produced.
Recommended actions when ISO 27001 and TISAX lie ahead
The guideline we generally recommend is therefore: build close to the standard, even if ISO 27001 should never come.
This adds hardly any cost during setup, and the option stays open.
A look at the costs of TISAX
What costs come with TISAX? First, the fixed items:
- the ENX® registration per site,
- the audit provider’s fee (the smaller, more predictable part).
The decisive factor is usually the internal setup. That is where it is decided whether a TISAX project lands in the four- or five-figure range.
The real challenge here is rarely a lack of knowledge, but governance. There are dozens of requirements, distributed responsibilities, and a self-assessment that has to stay consistent over months.
On a side note, the use of platforms for governance is worth recommending here. With Valiido, for example, policies, controls, and evidence can be structured along the catalogs. The self-assessment thus comes out audit-ready and does not have to be laboriously pieced together at the end.
Sum Up
TISAX and ISO 27001 are not competitors. Rather, they should be understood as two assessments of the same system for different audiences. The foundation of both proofs, however, is always the same: an ISMS that is built and lived systematically.
The synergies mentioned above arise already during setup, not only at the audit.
For a first self-check on the question “ISO 27001 first or TISAX first?”, three questions suffice:
- Who demands the proof? An OEM, the broader market, or foreseeably both?
- Which assessment objectives does the customer actually require — and is that available in writing?
- Is the ISMS structured so that a second assessment could build on it?
Anyone who answers these questions before starting builds their ISMS from the outset so that the described synergies actually materialize.
The rule: it almost never gets expensive because of the assessments themselves — but because of what was set up wrong beforehand.



