Last Updated on July 31, 2026 by Narendra Sahoo
If you supply parts, software, or engineering services to a German automotive OEM or a Tier 1 supplier, you have likely been asked for one of two things: an ISO 27001 certificate or a TISAX label. The two get confused constantly, and the confusion is costly — companies routinely invest in the wrong assessment, discover it does not satisfy their customer’s contract clause, and start over. This guide breaks down what each framework covers, where they overlap, where they diverge, what each one actually costs and takes to achieve, and how to sequence the work so you are not paying for two separate efforts from scratch.
What Is ISO 27001?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It is sector-agnostic: a bank, a hospital, a software vendor, and a car parts manufacturer can all certify against the same standard, currently built around 93 Annex A controls under the 2022 revision. The certificate is issued by an accredited certification body, is valid for three years, and requires annual surveillance audits to stay active.
ISO 27001 focuses on the management system itself — how an organization identifies risk, selects controls, documents policies, and continuously improves. It contains no automotive-specific requirements, and an ISO 27001 certificate on its own is not accepted by OEMs as proof of TISAX compliance.
Building or renewing your ISO 27001 ISMS? VISTA InfoSec’s ISO 27001 consultants help you scope the management system correctly the first time — so it can later be extended into TISAX without starting over.
What Is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s shared assessment framework, built and maintained by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Rather than each OEM auditing every supplier separately, TISAX lets a supplier complete one assessment and share the resulting label with multiple customers through the ENX portal — which is why VW, BMW, Mercedes-Benz, Audi, Porsche, and their Tier 1 and Tier 2 suppliers now require it as a condition of doing business.
TISAX assessment criteria come from the VDA ISA (VDA Information Security Assessment) catalogue, itself built on ISO 27001’s structure. Under VDA ISA 6.0, the information security module contains 45 controls and 297 individual requirements at the High protection level (Assessment Level 2), with 17 additional requirements layered on for the Very High protection level (Assessment Level 3). Organizations are scored on a maturity model running from Level 0 (Incomplete) to Level 5 (Optimizing), and must reach at least Maturity Level 3 (“Established”) on every relevant audit objective to pass.
The three assessment levels
- Assessment Level 1 (AL 1): A self-assessment with no third-party audit. In practice, OEMs rarely accept AL 1 labels for anything sensitive.
- Assessment Level 2 (AL 2): A remote or hybrid audit by an ENX-accredited provider, covering the core VDA ISA information security requirements. This is the most commonly requested level.
- Assessment Level 3 (AL 3): A full on-site audit with in-person interviews and physical inspection, required when highly sensitive data or prototype parts are involved.
The underlying requirement set is largely the same for AL 2 and AL 3; what changes is audit depth. AL 2 relies on document review, interviews, and screen-shared evidence, while AL 3 adds physical, on-site verification.
Two modules that ISO 27001 does not cover
- Prototype protection: Covers designs, specifications, physical prototypes, and test vehicles — requiring secure storage, restricted physical access, visitor controls, and monitoring of the areas where this data and hardware are handled. ISO 27001 does not address this at all.
- Data protection: A dedicated module aligned with GDPR that OEMs require whenever a supplier processes personal data on their behalf, going beyond ISO 27001’s general references to legal and regulatory compliance.
What it costs and how long it takes
Pricing and timelines vary by provider, company size, and starting maturity, so treat the figures below as planning ranges rather than fixed quotes. Independent consultancy estimates put the ENX-accredited auditor’s fee at roughly €3,000 for an AL2 remote assessment, rising to €9,000–€12,000 for an AL3 on-site assessment; total project cost, including internal preparation or consulting support, more commonly lands between €10,000 and €35,000 depending on company size and how much of the ISMS already exists. End to end, companies starting from scratch typically need four to twelve months to reach a TISAX label, with the ENX label itself issued within two to four weeks of a successful assessment. For comparison, ISO 27001 certification for a small-to-mid-size organization is commonly estimated at $25,000–$50,000, with a three-to-eight month timeline depending on starting maturity.
Not sure which TISAX assessment level your OEM contract actually requires? VISTA InfoSec runs TISAX gap assessments against the VDA ISA catalogue and guides you through AL2 or AL3 readiness, including the prototype and data protection modules.
TISAX vs ISO 27001: The Key Differences at a Glance
| Aspect | ISO 27001 | TISAX |
|---|---|---|
| Governing body | International Organization for Standardization (ISO/IEC) | ENX Association, based on the VDA ISA catalogue (German Association of the Automotive Industry) |
| Industry scope | Any industry, any organization size | Automotive industry supply chain only |
| Outcome | Certification, valid 3 years with annual surveillance audits | Assessment label, shared via the ENX portal, typically valid 3 years |
| Control set size | 93 Annex A controls (ISO 27001:2022) | 45 controls / 297 requirements at AL2 (High), +17 requirements for AL3 (Very High) under VDA ISA 6.0 |
| Assessment depth | Single certification level; auditor evaluates the ISMS as a whole | Three assessment levels (AL 1–3) tied to information sensitivity |
| Unique coverage | Broad ISMS: policies, risk treatment, asset management, access control | Everything in ISO 27001, plus prototype protection and a dedicated data protection (GDPR) module |
| Typical cost* | Roughly $25,000–$50,000 for a small organization; more for mid-size, per certification-body estimates | Provider audit fee ≈ €3,000 (AL2) to €9,000–€12,000 (AL3); total cost incl. internal preparation often €10,000–€35,000, per consultancy estimates |
| Typical timeline* | Roughly 3–8 months depending on company size and starting maturity | Roughly 4–12 months from a standing start; label issuance 2–4 weeks after a successful assessment |
| Who requires it | Customers, regulators, and partners across any sector | OEMs such as VW, BMW, Mercedes-Benz, Audi, and Porsche, and their Tier 1/Tier 2 suppliers |
| Result portability | Not automatically recognized by automotive OEMs as a TISAX substitute | Shared once via ENX and reused across multiple OEM relationships, avoiding repeat audits |
*Cost and timeline figures are third-party planning estimates, not official ENX or ISO pricing — confirm current rates with your chosen audit provider.
Illustrative Example: Sequencing ISO 27001 Into TISAX
The following is a representative composite scenario based on common engagement patterns our advisory team observes, not a specific named client.
In Practice
A Tier 2 automotive electronics supplier already held ISO 27001 certification, achieved originally to satisfy a non-automotive customer’s security questionnaire. When the company began supplying a component program for a German OEM, the OEM’s onboarding process required a TISAX AL2 label rather than the existing ISO certificate. Because the ISMS, risk register, and access control policies were already in place, the gap assessment against the VDA ISA catalogue found roughly 70% of requirements already met. The remaining work centered on building out the prototype protection controls for the area where test units were stored and adding the data protection module to cover personal data shared by the OEM. The AL2 assessment was scheduled and passed within roughly five months of the gap assessment, avoiding a second ISMS build from zero.
Do You Need Both?
For most suppliers in the automotive value chain, the practical answer is: you need TISAX, and ISO 27001 is the fastest, most defensible way to get there. Because VDA ISA is structurally derived from ISO 27001, an organization that has already built policies, risk assessments, an asset inventory, and access controls to ISO 27001 standard typically only needs to layer on the automotive-specific controls — prototype protection, the data protection module, and supplier chain requirements — to be ready for a TISAX assessment. Going the other direction does not work: an OEM will not accept an ISO 27001 certificate as a substitute for a TISAX label, because it does not evaluate prototype handling or the automotive supply chain controls the OEM actually cares about.
Don’t Miss the Corrective Action Window
If an audit objective falls short of Maturity Level 3, the supplier and audit provider agree a corrective action plan, and the supplier has nine months from the last day of the main assessment to implement it and pass a follow-up review. Missing that window invalidates the assessment and requires starting over — a strong argument for budgeting realistic internal preparation time rather than treating the audit date as a hard deadline.
NIS2 Adds Another Layer for 2026
Germany’s NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) has been in force since December 2025 and is expected to bring roughly 29,500 companies into scope during 2026, including many automotive suppliers that previously sat outside formal cybersecurity regulation. NIS2 requires an ISMS, documented risk management, business continuity planning, and strict incident reporting timelines (24 hours, 72 hours, and one month), backed by fines of up to €10 million or 2% of global turnover.
ENX’s own analysis concludes that organizations holding a TISAX label under the ISA 6.0 catalogue are already well positioned to meet NIS2’s core requirements — risk management, incident response, supply chain security, and governance overlap substantially. In practical terms, automotive suppliers who invest in TISAX, built on an ISO 27001 foundation, are addressing three compliance demands — OEM contracts, international security expectations, and German/EU regulation — with one coordinated program instead of three separate ones.
Choosing the Right Path: A Practical Framework
Practical Framework Checklist
- ☐ Check your contracts first. Do you handle OEM prototypes, engineering data, or confidential automotive project information? If yes, TISAX is contractually required — ISO 27001 alone will not satisfy the OEM.
- ☐ Assess your customer mix. If you serve automotive and non-automotive customers, build your ISMS to ISO 27001 as the foundation, then add the VDA ISA prototype protection and data protection modules for the automotive-facing part of the business.
- ☐ Right-size the assessment level. AL 1 self-assessments are rarely sufficient once an OEM is involved. Budget for AL 2 as the realistic minimum, and confirm with your customer whether prototype handling pushes you to AL 3.
- ☐ Map your data flows to the correct modules. A supplier handling only general engineering documentation needs the base VDA ISA information security scope. A supplier building or testing physical prototypes needs the prototype protection module layered on top; one processing candidate or employee personal data on the OEM’s behalf needs the data protection module too.
- ☐ Set a realistic budget and timeline. Plan for four to twelve months and the cost ranges above rather than assuming a fast pass — and build in time for a possible corrective action cycle.
- ☐ Choose an experienced assessment partner. An ENX-accredited audit provider, prior TISAX experience in your sector, and a realistic view of your current maturity level will shorten the path from Maturity Level 2 (“partly established”) to the Level 3 baseline every audit objective must clear.
Key Takeaways
- ✓ ISO 27001 is a sector-agnostic ISMS certification; TISAX is the automotive industry’s mandatory, shared assessment framework built on top of it.
- ✓ TISAX adds two modules ISO 27001 does not cover: prototype protection and a dedicated GDPR-aligned data protection module.
- ✓ An existing ISO 27001 program typically covers ~70% of TISAX requirements — it is the fastest route in, not a substitute.
- ✓ Missing the nine-month corrective action window after a failed audit objective invalidates the assessment entirely.
- ✓ A TISAX label under ISA 6.0 already covers much of what NIS2 requires — sequence the three together instead of treating them as separate projects.
Frequently Asked Questions
Is TISAX the same as ISO 27001 certification?
No. TISAX produces an assessment label shared through the ENX portal, not an ISO certificate. The underlying criteria (VDA ISA) are built on ISO 27001 but add automotive-specific requirements, including prototype protection and a dedicated data protection module that ISO 27001 does not cover.
Can I use my ISO 27001 certificate instead of getting TISAX assessed?
No. OEMs and Tier 1 suppliers in the German automotive industry require a valid TISAX label specifically. ISO 27001 certification significantly accelerates TISAX readiness but is not accepted as a substitute.
How much does TISAX cost?
Third-party estimates put the ENX-accredited auditor’s fee at roughly €3,000 for AL2 and €9,000–€12,000 for AL3, with total project cost including internal preparation commonly landing between €10,000 and €35,000 depending on company size and starting maturity. Confirm current rates directly with your chosen audit provider.
How long does TISAX take, including after ISO 27001 certification?
Companies starting from scratch typically need four to twelve months to reach a TISAX label; the label itself is issued two to four weeks after a successful assessment. Organizations that already hold ISO 27001 typically move faster, since policies, risk management, and core controls are already in place.
Which assessment level (AL 1, 2, or 3) do I need?
This is set by your OEM customer based on the sensitivity of the information and prototypes you handle. AL 2 (remote/hybrid audit) is the most common requirement; AL 3 (full on-site audit) applies when highly sensitive or physical prototype data is involved.
What happens if I fail to reach Maturity Level 3 on an audit objective?
The supplier and audit provider agree a corrective action plan, and the supplier has nine months from the last day of the main assessment to implement it and pass a follow-up review. Missing that window invalidates the assessment and requires starting over.
Does TISAX cover NIS2 compliance in Germany?
TISAX does not automatically equal NIS2 compliance, but ENX’s analysis found that TISAX-labeled organizations under ISA 6.0 already meet a substantial portion of NIS2’s core requirements around risk management, incident response, and governance, making the gap to full NIS2 compliance considerably smaller.
The Bottom Line
ISO 27001 and TISAX are not competing choices — they are sequential ones. Suppliers who treat ISO 27001 as the foundation and TISAX as the automotive-specific layer on top get to a passing assessment faster and avoid rebuilding an ISMS from scratch. Suppliers who wait until an OEM contract forces the question end up doing both under deadline pressure, at a higher cost, with less room to fix gaps before an auditor finds them.
Get Assessment-Ready With VISTA InfoSec
VISTA InfoSec works with automotive suppliers across the value chain to build ISO 27001-aligned ISMS programs and prepare for TISAX assessment — including gap analysis against the VDA ISA catalogue, prototype and data protection module readiness, and guidance on selecting the right assessment level for your OEM relationships. Our team can help you sequence the work so you satisfy all three with one coordinated program instead of three separate ones.
Narendra Sahoo (PCI QPA, PCI QSA, PCI SSF ASSESSOR, CISSP, CISA, CRISC, 27001 LA) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the US, Singapore & India. Mr. Sahoo holds more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, & Compliance services. VISTA InfoSec specializes in Information Security audit, consulting and certification services which include GDPR, HIPAA, CCPA, NESA, MAS-TRM, PCI DSS Compliance & Audit, PCI PIN, SOC2 Compliance & Audit, PDPA, PDPB to name a few. The company has for years (since 2004) worked with organizations across the globe to address the Regulatory and Information Security challenges in their industry. VISTA InfoSec has been instrumental in helping top multinational companies achieve compliance and secure their IT infrastructure.