What is TISAX?

TISAX ® (Trusted Information Security Assessment Exchange) is an information security standard tailored to the needs of the automotive industry. It is a standard that vehicle manufacturers, automotive suppliers, IT service providers, consultants and third-party software vendors can use to meet their information security requirements for automobile production. TISAX® certification is a compulsory requirement for many automobile manufacturers and suppliers to the (German) automotive industry.

The VDA (Verband der Automobilindustrie) created an Information Security Assessment sheet, which has great resemblance with ISO 27001 and the Annex A controls. However, it adds specific security controls for connection with third parties, prototype protection, and data protection.

ISO 27001 focuses on the organization and its structure (Information security management system) when TISAX® focuses on topics relevant to partners and specific physical locations.

The VDA information Security assessment can be divided in 4 main groups:

  • Information Security
  • Connection to third parties
  • Data protection
  • Prototype protection

The Information Security topic is quite similar on the ISO 27001 standard. The ISO 27001 standard can be used as a guidance as there are a lot of clauses and controls that can be used to meet the necessary TISAX compliance. 

TISAX has 7 chapters on Information security (IS Policies and Organization, Human Resources, Physical Security and Business Continuity, Identity and Access Management, IT Security/Cyber Security, Supplier Relationships and Compliance) that are also handled within the ISO 27001 standard. 

ISO/IEC 27001 manages information security of the organization the same way TISAX manages information security in the automotive supply chain.

The next schematic overview shows the relationship between TISAX compliance and how the ISO 27001 standard can help you with its implementation.

TISAX TopicISO 27001 (ISMS)
TISAX TopicISO 27001 (ISMS)
IS Policies and Organization19 controls + clauses
Human Resources6 controls
Physical Security and Business Continuity8 controls
Identity and Access Management11 controls
IT Security/Cyber Security16 controls
Supplier Relationships4 controls
Compliance5 controls

The controls are  listed in ANNEX A from the ISO 27001 standard.

From the 114 ISMS controls listed in the ANNEX A from the ISO 27001 standard, 69 controls can help/guide you by the implementation of TISAX. The next table shows you the difference in effort for gaining the required certification level.

TopicISO 27001TISAX
ISO 27001 Clauses
4 Context of the organizationMandatoryMandatory
5 LeadershipMandatoryLight
6 PlanningMandatoryLight
7 SupportMandatoryLight
8 OperationMandatoryLight
9 Performance EvaluationMandatoryLight
10 ImprovementMandatoryLight
ISO 27001 ANNEX A Controls11469
ISO 270017 standardNA5
Industry specificData Protection (4)
Prototype Protection (22)

Mandatory: the clause and its subdivisions need to be fully implemented.

Light: some topics of the clause need to be implemented or are helping the organisation by implementing them.

As we can establish from this table, TISAX and ISO 27001 are very closely related. Once your organization finalizes the TISAX-journey, there is only a small effort left for obtaining an ISO 27001 certification as you are already touching all of the requirements and some of the controls. Conversely, the concepts of TISAX are also compatible with ISO 27001 and can help in improving your Information security Management System.

To sum things up, both ISO 27001 and TISAX are compatible: mastering one also allows you to jump to the other quite easily, ultimately improving both your organization’s processes and security controls.

Share
Insights

Access related expert insights

Expert Articles
Expert Articles
21 May 2026
For the past decade, fintechs scaled fast by renting capability - cloud infrastructure, engineering talent, and core systems. It worked. Until it didn’t. The regulatory environment of 2026 has fundamentally closed that window. With the Digital Operational Resilience Act (DORA) now in full force and the EU AI Act raising the bar on AI transparency, the "our vendor handles that" defense is no longer viable. Regulators don't accept it. Auditors don't accept it. And increasingly, your board shouldn't either.
Build-Operate-Transfer Model: Why Fintech’s Future Depends on Owning Your Tech
Build-Operate-Transfer Model: Why Fintech’s Future Depends on Owning Your Tech
Expert Articles
Expert Articles
21 May 2026
yberattacks often begin long before a suspicious login, ransomware note, or phishing email reaches the organization. The starting point may already be outside the company’s control: an employee email, password, session token, or device record circulating through breach dumps, criminal forums, Telegram channels, or infostealer logs...
Dark Web Monitoring: Are Your Employees’ Credentials Already Exposed?
Dark Web Monitoring: Are Your Employees’ Credentials Already Exposed?
Expert Articles
Expert Articles
18 May 2026
Most engineering leaders searching for offshore delivery options start with the same term: offshore development center. It is the right instinct. But the organizations that scale fastest, protect their IP most effectively, and reduce vendor dependency over time tend to take the model further. Understanding what is an offshore development center is the starting point. Understanding why the […]
What is an Offshore Development Center?
What is an Offshore Development Center?