
The difference between ISO 27001 and TISAX is rarely googled out of curiosity. Usually a supplier questionnaire is sitting on the table, and it contains a word you do not have. The machine builder with a fresh ISO 27001 certificate gets asked by a German automotive customer for its TISAX result. The electronics supplier with a passed TISAX assessment is expected to present an ISO certificate to an energy utility. Both thought the topic was settled. Both built something solid. It just proves the wrong thing to the wrong customer.
That is the core you need for the decision. ISO 27001 and TISAX are two proofs for two different audiences, not competitors between which you pick the better framework. The better question is: Who is asking you for proof, and which proof do they accept?
The difference: certificate versus shared assessment result
ISO 27001 is an international standard for information security management systems. You define yourself which part of your company falls within the scope, an accredited certification body audits it, and at the end there is a certificate you can show to anyone: customers, insurers or authorities. The certificate runs over three years, with annual surveillance audits in between. It answers the basic question: Do you manage your information security systematically, or does it just happen?
TISAX works differently, starting with its very design. ENX, the organisation behind it, calls it an assessment and exchange mechanism for information security (enx.com/tisax). Translated, that means: At the end there is a standardised assessment result, valid for three years, which you share selectively with registered participants via the ENX platform. There is no certificate to show around. The assessment runs against the VDA ISA catalogue, which according to ENX builds on key aspects of ISO/IEC 27001. The scope is set by the catalogue and your site. And how deep the assessment goes depends on the protection needs your customer specifies.
Because the ISA catalogue builds on the ISO standard, the shorthand «TISAX is just ISO 27001 for the car industry» persists. It is largely true on content, and that is exactly why it misleads: It hides the fact that the two proofs work differently. An ISO certificate is a document. You attach it to an email or include it in a tender. A TISAX result never leaves the ENX platform. Your customer does not get a PDF from you, they get an authorisation and read the standardised report right there. If you only compare the content, you miss the mechanism, and the mechanism decides whether your proof reaches your customer at all.
The reason for this construction is sober: The automotive industry did not want every manufacturer auditing every supplier individually. So it built itself a shared assessment economy. Get assessed once, share the result, done. That is efficient for the industry. For you as a supplier it means: The result lives in this platform and is meant for this ecosystem. A factory badge, valid for exactly one site.
Why one does not replace the other
The expensive mix-up happens in the procurement process, and it happens quietly. If an automotive customer requires a TISAX result and you submit your ISO certificate instead, their procurement team searches the platform for your result. Whether your certificate would be comparable in substance is something nobody there checks. If they find nothing, you are formally not eligible to supply, however good your ISMS is. This filter runs before any human ever speaks to you. The order is lost in a database query, long before it would have come to a negotiation.
The same applies in the other direction. Outside the automotive world, hardly any buyer knows TISAX. Public tenders, financial customers, energy utilities and most enterprise questionnaires ask for ISO 27001. You can explain a TISAX result there, but you explain it anew every time, and a proof that needs explaining is a weak proof in procurement.
Notice what is missing from this whole mechanism: the legislator. No Swiss law requires a supplier to hold ISO 27001 or TISAX. The ISG obliges critical infrastructure operators, the nDSG governs the handling of personal data, but which proof has to sit in your supplier portal is decided by your customer alone. The regulator deciding over your orders here sits in your customer's procurement department rather than in Bern. That makes the matter more honest than it first appears: This decision is about market access, and it therefore belongs with executive management, next to sales and pricing, rather than being treated as a tiresome IT formality.
The good news: The work transfers, even if the proof does not. The ISA catalogue builds on ISO/IEC 27001. If you run a living ISMS, with a sound risk assessment and clear responsibilities, you have most of the distance behind you for both proofs. In our experience, the path from a working ISMS to an additional TISAX result is a follow-on project of manageable size, no second build from scratch. It only gets expensive when a company, out of uncertainty, sets up two separate programmes: two documentation worlds and two audit calendars. That is the same over-regulation we described in our post on ISO 27001 costs, only doubled.
When the questionnaire is here and the proof is missing
The most common moment this question reaches us is the most uncomfortable one: The customer request has arrived, the deadline is running, and the required proof does not exist. The reflex is then a certification sprint at any price, and that produces exactly the kind of paper ISMS that falls apart in the first surveillance audit.
There is a better answer, and it is unspectacular: honesty with a plan. A procurement team asking for proof mostly wants one thing above all: a risk it can gauge. An answer of the form «As of today we have X, the assessment is planned for quarter Y, here is the action plan with an owner» keeps a surprising number of doors open that an empty field in the portal closes immediately. It only works, though, if the plan is real. An invented date is merely a postponed breach of trust with advance notice.
Plan in realistic units. In our experience, companies rarely underestimate the assessment itself, but the lead time before it: A management system has to have been lived for a while before an auditor finds anything auditable. If you quote your customer quarters instead of weeks, you promise less and deliver more.
And before you write that plan, clarify a preliminary question many people skip: whether the requirement is even meant that way. Contract annexes get copied from templates, and more than once we have seen a query back to the customer clarify or soften the requirement. Asking comes across as someone who reads requirements before spending money. In procurement, that is a rare and welcome quality.
Decide by customer portfolio
This makes the decision simpler than the framework debate suggests. You only have to take an honest look at your own customer portfolio. Three situations cover almost all cases.
If your relevant customers hang on the supply chain of the German car manufacturers, TISAX is a given. There is nothing to optimise and nothing to negotiate. That is what proof is called in this industry, and your access to orders depends on it. The protection needs your customer specifies determine the assessment depth, and the requirement has usually long been sitting in a contract annex someone signed years ago.
One detail that is worth real money here: The assessment is site-based. If only one of your three plants supplies the automotive chain, only that one needs the result. We regularly see companies that, out of caution, put the whole company into the assessment scope and buy themselves effort no customer ever asked for. The scope of the proof is a decision, and it deserves to be taken deliberately.
If, on the other hand, you sell broadly, to industry, energy, healthcare, finance or the public sector, then ISO 27001 is the proof that says something everywhere. It opens no door by itself, but it is understood almost everywhere. For Swiss SMEs with a mixed customer base, this is the more common case in our experience.
And if both worlds buy from you: Build a single ISMS and prove it twice: one management system as the foundation, close the ISA-specific gaps on top, and both assessments draw from the same system. Just do not start with the label. Measure where you stand first, then decide what gets built on top. We laid out why this order saves money in our post on the security assessment before ISO 27001, and it applies to TISAX just the same.
That leaves the fourth case, which rarely gets written about: Nobody is asking. Then the right amount of label may well be zero. You can run an ISMS without ever having it certified, and for many companies that is the most sensible level for years. The proof becomes relevant when a customer requires it, and whoever already runs their system retrofits the proof instead of stamping a programme out of the ground under deadline pressure.
If a questionnaire is sitting on your desk right now and you are not sure which proof is the right one for your customer portfolio: Exactly this kind of assessment is what we do in our ISMS programme, before anything gets built. An initial conversation about it comes with no strings attached.
The decision in three sentences
- If you sell into the automotive supply chain, you need TISAX, because procurement there only reads that result.
- If you sell broadly, you are better off with ISO 27001, because the certificate says something to every customer.
- If you need both, build one ISMS and prove it twice, instead of paying for two programmes.
Which leaves one question you can settle today in twenty minutes, and it pre-empts the whole decision: Which proofs do the supplier portals of your five most important customers already require?




