Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Information security

TISAX vs ISO 27001

Both start from the same security care, but serve different audiences. ISO/IEC 27001 is an international information-security certification, accepted in any industry and issued by an accredited body. TISAX is how the automotive industry assesses suppliers, required by carmakers such as Volkswagen, BMW and Mercedes-Benz. Holding ISO 27001 covers much of TISAX, but doesn't replace it.

See TISAX readinessJump to the comparison

In short

  • ISO 27001 is an information-security certification, accepted in any industry and issued by an accredited body.
  • TISAX is not a certification. It is an assessment: an accredited auditor reviews your security and the result is stored on an automotive-industry platform (ENX). You show that result only to the carmakers and partners you choose.
  • TISAX uses a script that grew out of ISO 27001, but adds its own points: protecting prototypes and controlling the link with third parties.
  • If your carmaker asks for TISAX, ISO 27001 is the shortcut: it reuses almost all the effort, but the TISAX assessment is still mandatory.

Side by side

What separates a certification from an industry assessment

What to compareISO/IEC 27001TISAX
What it isAn international information-security certification.An automotive-industry assessment, run by ENX. Not a certification.
Where the care comes fromA list of 93 controls (2022 version), split into four themes.An automotive-industry script that grew out of ISO 27001 and gained its own points.
Who it applies toAny company, in any industry, that wants to care for and prove its security.Suppliers in the automotive chain who need to exchange information with carmakers and large suppliers.
What you getA public certificate anyone can check, issued by an accredited body.A result stored on the ENX platform, which you show only to the partners you choose.
DepthA single scope, defined by you. An audit to earn the certificate and follow-up visits.Levels AL1 to AL3, according to how much the information needs protecting (normal, high or very high).
What it assessesKeeping information secure, intact and available, in general.Information security, prototype protection and data protection, per what is asked.
Who assessesAn accredited certification body.An ENX-accredited auditor.
How long it lastsThe certificate lasts 3 years, with follow-up visits every year.The result lasts 3 years.

The TISAX script is maintained by the German automotive industry association and follows ISO 27001; that is why the two share most of their security care.

The certification accepted in any industry

ISO/IEC 27001

It is the international information-security standard, accepted in any industry and any country. You organise the company's security (rules, risk analysis, what applies and what doesn't, controls and continual improvement) and an accredited body issues the certificate. It is the proof that big customers, tenders and partners outside the automotive sector recognise right away.

  • International certification, accepted in any industry
  • 93 controls in the 2022 version, split into four themes
  • A public certificate anyone can check
  • A base that covers almost all of the TISAX effort
The automotive passport

TISAX

It is how the European automotive industry arranged not to audit each supplier over and over. You are assessed once, by an ENX-accredited auditor, and the result sits on the platform for the carmakers you authorise. Without that result, many carmakers simply won't close with the supplier.

  • Required by carmakers and large suppliers to onboard whoever serves them
  • Follows its own automotive-industry script
  • Levels AL1 to AL3, according to how much the information needs protecting
  • The result is shared confidentially, on the ENX platform

How they fit together

ISO 27001 is the base; TISAX is the automotive layer

Because the TISAX script grew out of ISO 27001, a company that already holds the certificate reaches TISAX with most of the care in place: rules, risk analysis, access control, incident response and continuity serve both. What TISAX asks on top are the industry's own points (protecting prototypes and controlling the link with third parties) and the maturity level the carmaker requires. Holding ISO 27001 doesn't deliver the TISAX result on its own: the assessment by an accredited auditor is still mandatory, but the path is much shorter.

  • ISO 27001's organisation satisfies most of the TISAX script
  • TISAX adds prototype protection and control of the third-party link
  • The level asked (AL2 or AL3) sets how much proof you will need to gather

Which is your case

Where to start

A carmaker is requiring TISAX to close with you

Go straight to TISAX

It is what unlocks the contract. Confirm with the customer what needs assessing and the level (AL2 or AL3), because that sets the size of the work and the timeline.

You also want to prove security outside automotive

Start with ISO 27001

It is the certification that tenders, banks and customers in any industry recognise. And it becomes the base that shortens TISAX when the automotive demand arrives.

You serve automotive and general customers

ISO 27001 first, TISAX next

The most efficient path. You organise security once and use the same proof for the certificate and the TISAX assessment, with no repeated work.

Numbers that matter

3 years

how long the TISAX result and the ISO 27001 certificate last

AL1 to AL3

TISAX levels, by how much protection is needed

93 controls

in the 2022 version of ISO/IEC 27001

How DM11 helps

TISAX readiness and ISO 27001 certification, with DM11

We organise security with ISO 27001 and prepare for what your carmaker asks in TISAX, at the right level, with a single control and proof effort, through to the assessment with the ENX-accredited auditor.

  • One base serves the certificate and the assessment, with no double work
  • You enter the assessment already knowing you'll pass, with no last-minute surprise
  • We handle the paperwork and evidence; your team stays on production
  • You unlock the carmaker contract on time, without losing your onboarding
Explore TISAX readiness

Frequently asked

What people ask before deciding

Answers anchored in the TISAX script and ISO/IEC 27001:2022.

No, but you have covered most of the path. The TISAX script grew out of ISO 27001, so nearly all of the organising care will already be in place. What's left are the industry's own points (protecting prototypes and controlling the link with third parties) and the assessment by an ENX-accredited auditor, which produces the result. It is an add-on over a ready base, not a project from scratch.

More questions? Talk to DM11

Find the shortest path to the TISAX your carmaker asks for

A short conversation shows what needs assessing, at what level, and how much of ISO 27001 you can already reuse. No commitment.

Talk to a specialistExplore TISAX readiness