GRADUM
    FeaturesMaturity ModelsFor CreatorsPricingBlogCompareSupport
    DashboardSign Up Free
    Blog/Compare/TISAX vs EN 1090
    Standards Comparison

    TISAX vs EN 1090

    TISAX

    Mandatory
    2017

    Automotive framework for standardized information security assessments

    VS

    EN 1090

    Mandatory
    2009

    EU standard for execution of steel and aluminium structures

    Quick Verdict

    TISAX ensures information security for automotive supply chains via assessments, while EN 1090 mandates CE marking for structural steel/aluminium through FPC. Automotive firms adopt TISAX for OEM trust; fabricators use EN 1090 for EU market access and legal compliance.

    Cybersecurity

    TISAX

    Trusted Information Security Assessment Exchange (TISAX)

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    12-18 months

    Key Features

    • Centralized ENX portal enables result sharing across OEMs
    • Automotive-specific prototype protection and IP controls
    • Three risk-based assessment levels (AL1-AL3)
    • VDA ISA catalog with maturity scoring (0-5)
    • Three-year valid labels reduce duplicate audits
    Structural Metalwork

    EN 1090

    EN 1090 Execution of steel and aluminium structures

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Risk-based Execution Classes (EXC1-EXC4)
    • Factory Production Control (FPC) certification
    • CE marking and Declaration of Performance
    • Welding quality via ISO 3834 alignment
    • Material traceability and NDT requirements

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    TISAX Details

    What It Is

    TISAX (Trusted Information Security Assessment Exchange) is an industry framework developed by the ENX Association and VDA for the automotive sector. It standardizes assessments of information security, focusing on protecting sensitive data like prototypes and IP in global supply chains. The risk-based approach uses the VDA ISA catalog (version 6.0 and subsequent updates) with three assessment levels (AL1-AL3).

    Key Components

    • Control groups: Policy, organization, personnel, physical security, access, cryptography, operations, supplier relationships (70+ controls).
    • Automotive modules: Prototype protection, data protection.
    • Built on ISO 27001 with maturity levels (0-5 scale).
    • Certification model: Labels valid 3 years, shared via ENX portal.

    Why Organizations Use It

    OEMs mandate TISAX contractually for suppliers, enabling market access and revenue. It mitigates risks like IP theft, reduces duplicate audits (70-90% efficiency), builds trust, and provides competitive edges in €2.5T automotive chain.

    Implementation Overview

    Phased: Preparation/gap analysis (1-3 months), remediation/tabletops (3-9 months), audit/certification (2-4 months), ongoing sustainment. Applies to OEMs, Tier 1/2 suppliers, service providers; scalable for SMEs to multinationals via self-assess or on-site audits.

    EN 1090 Details

    What It Is

    EN 1090 is a harmonized European standard family (EN 1090-1, -2, -3) under the Construction Products Regulation (CPR). It governs the execution and conformity assessment of structural steel and aluminium components/kits for construction works. Primary purpose: ensure controlled fabrication, welding, inspection and CE marking via risk-based Execution Classes (EXC1-EXC4).

    Key Components

    • EN 1090-1: Conformity assessment, Factory Production Control (FPC) certification.
    • EN 1090-2/-3: Technical rules for steel/aluminium (materials, welding per ISO 3834, tolerances, corrosion protection, NDT).
    • Risk-scaled requirements via consequence/service/production categories.
    • Certification model: Notified Body audits FPC, issues certificate for CE/DoP.

    Why Organizations Use It

    • Mandatory for EU market access (CE marking required).
    • Reduces liability, rework; builds trust via traceability.
    • Enables high-risk projects (EXC3/EXC4), competitive bidding.

    Implementation Overview

    Phased: gap analysis, FPC build, welding quals, NB certification (3-12 months). Applies to fabricators in EU/UK; ongoing surveillance.

    Key Differences

    AspectTISAXEN 1090
    ScopeInformation security in automotive supply chainExecution of steel/aluminium structural components
    IndustryAutomotive suppliers, OEMs (mainly Europe)Construction, fabrication (EU/EEA market)
    NatureVoluntary industry certificationMandatory for CE marking under CPR
    TestingMaturity assessments AL1-3 by providersFPC certification, surveillance by Notified Body
    PenaltiesContract loss, no legal finesMarket exclusion, legal enforcement, fines

    Scope

    TISAX
    Information security in automotive supply chain
    EN 1090
    Execution of steel/aluminium structural components

    Industry

    TISAX
    Automotive suppliers, OEMs (mainly Europe)
    EN 1090
    Construction, fabrication (EU/EEA market)

    Nature

    TISAX
    Voluntary industry certification
    EN 1090
    Mandatory for CE marking under CPR

    Testing

    TISAX
    Maturity assessments AL1-3 by providers
    EN 1090
    FPC certification, surveillance by Notified Body

    Penalties

    TISAX
    Contract loss, no legal fines
    EN 1090
    Market exclusion, legal enforcement, fines

    Frequently Asked Questions

    Common questions about TISAX and EN 1090

    TISAX FAQ

    EN 1090 FAQ

    You Might also be Interested in These Articles...

    SOC 2 Audit Survival Guide: Auditor Questions, Red Flags, and Evidence Prep for First-Time Pass

    SOC 2 Audit Survival Guide: Auditor Questions, Red Flags, and Evidence Prep for First-Time Pass

    Ace your SOC 2 audit with predicted auditor questions, model answers, red flags, and evidence checklists from CPA best practices & SignWell's journey. Reduce st

    TISAX Tabletop Exercises for ADAS Suppliers: Simulating Prototype IP Leaks and Ransomware in Hybrid Supply Chains (2025 Edition with Hero Scenario Visual)

    TISAX Tabletop Exercises for ADAS Suppliers: Simulating Prototype IP Leaks and Ransomware in Hybrid Supply Chains (2025 Edition with Hero Scenario Visual)

    Master TISAX 'Very High' tabletop exercises for ADAS suppliers with 2024 breach simulations like CAD leaks and ransomware. Get scripts, AAR templates, hybrid ti

    You Guide on how to Start Implementing NIS2 in Your Organization

    You Guide on how to Start Implementing NIS2 in Your Organization

    Master NIS2 implementation with our detailed guide. Learn requirements, risk assessment, supply chain security, and compliance steps for your organization. Star

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Explore More Comparisons

    See how TISAX and EN 1090 compare against other standards

    Other TISAX Comparisons

    • TISAX vs ISO/IEC 42001:2023
    • TISAX vs U.S. SEC Cybersecurity Rules
    • TISAX vs MLPS 2.0 (Multi-Level Protection Scheme)
    • FISMA vs TISAX
    • TISAX vs ISO 27701

    Other EN 1090 Comparisons

    • EN 1090 vs ISO/IEC 42001:2023
    • EN 1090 vs MLPS 2.0 (Multi-Level Protection Scheme)
    • EN 1090 vs U.S. SEC Cybersecurity Rules
    • IFS Food vs EN 1090
    • AEO vs EN 1090
    GRADUM

    Transform your assessment process with collaborative, AI-powered maturity evaluations that deliver actionable insights.

    Navigation

    FeaturesMaturity ModelsFor CreatorsPricing

    Legal

    Terms and ConditionsPrivacy PolicyImprintCopyright PolicyCookie Policy

    © 2026 Gradum. All Rights Reserved