What TISAX Requires Beyond ISO 27001

Updated: Sep 14
An ISO/IEC 27001 certificate is a strong sign that an organisation manages information security in a structured way. For suppliers in the automotive industry, however, it may not be enough to meet an OEM's expectations.
The key difference is simple: TISAX requirements build on information security management, then apply automotive-specific assessment objectives, evidence expectations, and a controlled method for sharing results. ISO 27001 can provide the foundation, but it isn't TISAX certification and doesn't automatically result in a TISAX label.
The right starting point is to understand what sits inside your existing ISMS, then assess what the requested TISAX assessment scope adds.
The short answer: TISAX requirements go beyond an ISO 27001 ISMS
ISO/IEC 27001 is an international management-system standard. It requires organisations to establish, operate, review, and improve an information security management system, known as an ISMS.
TISAX, short for Trusted Information Security Assessment Exchange, is an automotive assessment and information-exchange scheme, rather than an alternative certification standard. The TISAX assessment process is based on the VDA Information Security Assessment catalogue, or VDA ISA, and is governed by the ENX Association.
What ISO 27001 already gives you
A well-implemented ISO 27001 ISMS gives a supplier a useful base for TISAX preparation. It should already include governance, risk assessment, information security policies, asset management, supplier controls, access management, incident response, internal audits, and management reviews.
These are not minor advantages. An ISO-certified organisation often has governance structures, risk records, and security responsibilities already in place. That reduces duplicate work and allows the team to focus on automotive gaps.
For businesses building that foundation, ISO 27001 consultancy services can help align the ISMS with the organisation's operational risks before TISAX-specific controls are added.
What ISO 27001 does not automatically provide
ISO 27001 certification does not confirm that an organisation has been assessed against VDA ISA. It also does not establish the required TISAX assessment objective, assessment level, prototype protection, or selected TISAX data protection objective.
It cannot create a TISAX label, register an assessment scope with ENX, or share a result through the ENX platform. Those steps are part of the TISAX process, which complements rather than replaces an ISMS.
ISO 27001 demonstrates an effective management system. TISAX demonstrates whether a defined automotive scope meets the required VDA ISA assessment objective.
TISAX requirements that ISO 27001 does not cover by itself
The core distinction is not that TISAX ignores ISO 27001 controls. Many controls overlap. A TISAX assessment applies them to automotive information, locations, processes, and customer expectations in greater detail.
Prototype Protection
Prototype Protection is a distinct TISAX assessment objective. It is relevant where an organisation receives, develops, stores, transports, tests, photographs, or disposes of prototype components or vehicles.
An ISO 27001 risk assessment may identify intellectual property as an important asset. TISAX asks for more direct evidence that prototype risks are managed. This can include secure areas, visitor controls, restricted photography, clean-desk arrangements, protected transport, need-to-know access, and disposal processes.
The controls must match the actual work. A design agency holding CAD files has different risks from a logistics provider moving covered prototype vehicles between sites.
Data Protection
TISAX Data Protection is also a separate assessment objective. It complements, rather than replaces, UK GDPR or EU GDPR compliance, and an ISO 27001 certificate doesn’t prove that the Data Protection objective has been assessed.
The scope may include how personal data is classified, accessed, retained, transferred, deleted, and handled by third parties. It should also show clear ownership between information security, legal, HR, and operational teams.
For example, employee records, vehicle test data, customer contacts, and supplier personnel details can follow different systems and retention rules. A general privacy policy won’t be enough if evidence doesn’t show how those rules work in practice.
Automotive assessment objectives and maturity evidence
TISAX assessments are selected according to an assessment objective and the required scope. Common objectives include Information Security, Data Protection, and Prototype Protection.
Before appointing an assessment provider, an organisation can complete a self-assessment against the relevant VDA ISA requirements. This helps identify gaps and prepare suitable evidence.
The VDA ISA catalogue evaluates how consistently controls are implemented. An ISO/IEC 27001 ISMS maturity level may indicate how consistently the management system operates, but it isn’t the same as a TISAX assessment level or proof of a TISAX label.
Don’t assume that every supplier must reach the same maturity score. Target maturity depends on the question, assessment objective, and customer requirement.
The selected assessment level affects the evidence required and whether an on-site audit is needed. An on-site audit isn’t an automatic requirement for every TISAX objective or supplier.
Current assessments ordered in 2026 use VDA ISA 6.0.3. ENX has confirmed that VDA ISA2027 will apply to assessments ordered from 1 January 2027. Organisations with planned assessments around that date should confirm the applicable catalogue early.
Assessment levels and audit evidence
TISAX assessment levels determine the depth of assurance expected. A TISAX assessment level isn't a measure of organisational size or a simple ranking of security maturity.
Focus on the customer's required objective
The requested Assessment level determines the evidence and assessment method. An ISMS maturity level isn't a substitute for it. Maturity evidence must be interpreted against the relevant VDA ISA assessment objective.
For customer-requested AL2 routes, the assessor may review evidence, conduct expert interviews, and perform a plausibility check of the self-assessment and supporting information. A second plausibility check may be needed where submitted evidence requires clarification.
AL3 has a higher assurance expectation and involves more extensive examination of implementation. This can include an on-site audit, detailed testing, and interviews with relevant personnel.
Prototype Protection for parts and vehicles commonly requires AL3. An applicable AL3 route may therefore include an on-site audit of the prototype environment. Information Security or Data Protection may be assessed at AL2 or AL3, depending on the objective selected by the customer.
You may still see references to AL1 or AL2.5 in older articles and supplier questionnaires. Don't select an assessment approach based on those references alone. Confirm the objective, scope, and assessment level stated by the OEM or partner, then check the current TISAX participant handbook.
Show that controls operate day to day
A policy states an intention. Audit evidence demonstrates that the control is working. For an applicable higher-assurance route, an on-site audit may test whether those controls operate in practice.
For Access control, the assessor may need to see joiner, mover, and leaver records, privileged access approvals, group membership reviews, and examples of accounts being disabled promptly. During an AL3 on-site audit, they may also inspect relevant systems and facilities.
For a secure prototype area, evidence may include visitor records, access logs, security instructions, and incident procedures. Any evidence gaps or Non-conformities should be recorded, assigned, remediated, and tracked through a Corrective action plan agreed with the audit provider.
The same principle applies to outsourced IT, manufacturing systems, and shared services. If the scope says a supplier or platform is critical, the organisation must show how its security is assessed and monitored. An applicable AL3 on-site audit may also examine those arrangements.
Building a practical TISAX readiness plan
A focused readiness plan avoids the common mistake of producing broad documentation without proving how it applies to the automotive contract.
Define the assessment scope before writing policies
Start with the customer requirement. Identify the legal entities, sites, processes, systems, cloud services, departments, and suppliers within the requested assessment scope.
A multi-site supplier should not automatically place every office, warehouse, and business unit into scope. Equally, it should not exclude a location that administers user accounts, hosts engineering data, processes personal data, or coordinates prototype transport.
Supply chain security also depends on critical suppliers being assessed and monitored. This includes managed service providers, shared service teams, logistics partners, and other outsourced services within or connected to the TISAX assessment scope.
Document the data flows. Follow information from receipt through storage, processing, sharing, backup, and deletion. This often identifies hidden scope items such as a shared service desk, HR platform, managed security provider, or overseas development team.
Map ISO controls to the VDA ISA catalogue
Use existing ISO 27001 documents as evidence where they genuinely meet the VDA ISA expectation. Your risk methodology, asset register, supplier due diligence process, incident plan, and internal audit programme may already cover a large part of the required framework.
Then identify the gaps. Typical areas include prototype protection, physical security, customer-information classification, data protection evidence, supplier assurance, and site-specific implementation records.
TISAX and VDA ISA compliance guidance is particularly useful where the business has a mature ISMS but needs a clear route through automotive assessment requirements.
Test high-risk controls before the audit
Before the on-site audit, test high-risk controls where the applicable assessment level and objective require this. Automated identity lifecycle management is a good example.
HR should trigger the approval process, the identity platform should apply the correct role, and departures should remove access without relying on a manual reminder.
For operational technology, separate networks where appropriate, maintain an accurate asset inventory, control remote access, and record responsibility for patching and backups. A factory system may not tolerate the same patching timetable as a standard office device, but that decision needs a documented risk treatment.
Site-specific physical and operational evidence may be sampled during an on-site audit. Use a self-assessment to test the documented scope, data flows, and control implementation before the formal ENX-managed TISAX assessment.
Run an internal audit using real samples. Check a recent leaver, an active supplier, a prototype visitor, a security incident, and a backup restoration record. Close evidence gaps before the on-site audit, if one applies to the assessment level and objective.
Registration, results, fees, and validity
TISAX follows a defined route. The organisation registers as a participant through the ENX portal, defines an assessment scope, and manages its Participant ID and Scope ID. It then appoints an approved or accredited assessment provider where applicable, completes the relevant assessment, addresses findings, and controls access to the result through the ENX system.
A label is not the same as certification
It is common to hear the phrase "TISAX certification", but this is informal shorthand rather than the formal outcome. The organisation receives an assessment result, which can be shared electronically as a TISAX label.
TISAX is a controlled exchange platform for sharing assessment results with authorised partners. Partners can view the label only when the participant grants access through the ENX system.
Depending on the applicable assessment route and level, the assessment provider may perform a plausibility check of submitted information and evidence. Identified non-conformities may require a documented corrective action plan and follow-up before the result is finalised or shared, subject to the provider's process.
A higher-assurance route can involve more detailed examination than a plausibility check, including an on-site audit where applicable. This differs from a document-only route and does not mean that every assessment scope requires an on-site audit.
This shared approach can reduce repetitive customer audits. A single assessment result may be shared with more than one authorised automotive partner, subject to the scope and objectives they require.
The ENX TISAX portal states that TISAX labels are valid for three years. A change in scope, ownership, systems, locations, or customer requirements should still trigger a review before the renewal date.
Budget for the full programme
There is no reliable single audit price. Costs depend on assessment level, locations, scope complexity, readiness, assessment provider, travel, corrective actions, and the work needed to implement missing controls.
Separate the budget into four areas:
ENX participation and assessment-scope fees.
External assessment provider fees, including provider time and travel for an applicable on-site audit.
Internal time for evidence gathering, remediation, and interviews.
Specialist support where a gap analysis, technical change, or urgent audit preparation is required.
ENX publishes the official VDA ISA documents and related fee information in its TISAX downloads area. Obtain a written quotation once the scope and objectives are confirmed.
Key takeaways for automotive suppliers
ISO/IEC 27001 gives you an ISMS foundation, but it does not automatically meet all TISAX requirements.
TISAX adds automotive assessment objectives, including Information Security, Data Protection, and Prototype Protection.
The required assessment level, maturity expectations, and evidence depend on the customer request and assessment scope.
A TISAX label follows an ENX-managed assessment and result-sharing process. ISO certification alone cannot provide it.
Strong preparation combines an ISO control baseline with site-level evidence that the controls operate as intended.
Frequently asked questions
Is ISO 27001 enough for an automotive supplier?
It may be enough for customers that only request ISO 27001 certification. The phrase TISAX certification is commonly used, but ISO 27001 certification doesn't automatically give a supplier a TISAX label.
An ISO 27001 ISMS should reduce preparation effort. The organisation still needs to complete TISAX registration, a provider-led TISAX assessment, any corrective actions, and controlled result-sharing.
Does every organisation need Prototype Protection?
No. Prototype Protection applies when the organisation handles prototype parts, vehicles, or related confidential information within the agreed scope. A supplier that only processes standard production data may not need this objective.
The requirement comes from the customer relationship and the work performed, not the supplier's job title or turnover.
What should we prepare for an AL3 assessment?
Prepare more than policies. AL3 readiness requires evidence that physical, technical, and organisational controls work at the relevant sites.
Expect detailed questions on access management, visitor arrangements, personnel processes, supplier controls, incident handling, asset records, secure areas, and prototype procedures where applicable. AL3 may involve an on-site audit, interviews, and site inspection, depending on the selected assessment objective and current ENX requirements.
Teams responsible for those controls should be ready to explain their role and provide examples.
Using ISO 27001 as the starting point
ISO 27001 is a practical foundation, but it is not TISAX certification and does not itself produce a TISAX label. A mature ISMS gives automotive suppliers the governance, risk management, and control structure needed to prepare with confidence.
Establish or use that ISMS, then map it to the relevant VDA ISA assessment objective. Prepare evidence for the required assessment level and assessment scope, then complete the ENX-managed process for the relevant TISAX label.
If you would like to find out more or require any of our services please Contact Us




Comments