Back to the blog
    Certified, but secure? What ISO 27001 & TISAX truly mean for insurance IT service providers
    15.07.2026Sasha Justmann5 min read

    Certified, but secure? What ISO 27001 & TISAX truly mean for insurance IT service providers

    An article on IT security and certification in German insurance IT

    Certificates as door openers – but for what exactly?

    Any IT service provider operating in the insurance sector can hardly avoid security certifications. Tenders demand them, clients set them as a contractual prerequisite, and board members often refer to them as proof of "audited security". However, in practice, there is often confusion about which certificate is actually relevant for which purpose – and what a certificate can achieve, but also what it cannot. In particular, the confusion between ISO 27001 and TISAX regularly leads to misunderstandings in the insurance industry.

    ISO 27001: The industry-independent cornerstone

    ISO 27001 is the internationally recognised standard for an Information Security Management System (ISMS). The standard defines requirements for the establishment, operation, monitoring, and continuous improvement of such a system and can be applied independently of the industry – whether financial service providers, healthcare, or IT service providers, the standard works everywhere. The current version ISO/IEC 27001:2022 defines 93 controls in four categories: organisational, people, physical, and technological. Certification is carried out by accredited certification bodies such as TÜV, DEKRA, or Bureau Veritas and is recognised worldwide.

    For insurers and their IT service providers, this is relevant for several reasons: The supervisory requirements of BaFin (Federal Financial Supervisory Authority) – formerly the insurance-specific circular VAIT, now largely absorbed into DORA – are strongly based on ISO 27001 in terms of content. An ISMS according to ISO 27001 thus already covers large parts of the requirements from DORA (Digital Operational Resilience Act) and GDPR (General Data Protection Regulation), instead of starting from scratch for each regulatory standard separately.

    TISAX: A persistent misunderstanding

    Contrary to common assumption, TISAX is not a general security standard for regulated industries, but an industry label specifically for the automotive industry. TISAX was developed in 2017 by the VDA (German Association of the Automotive Industry) and is aimed at suppliers, service providers, and partners who handle sensitive data from automobile manufacturers – such as development information or prototypes. The audit is not carried out by a classic certification body, but by audit service providers accredited by the ENX Association, and the result is strictly speaking not a certificate, but a TISAX label with a validity period of three years.

    For IT service providers who operate exclusively in the insurance sector, TISAX is generally not relevant – unless the company also serves customers from the automotive industry in parallel. Anyone who nevertheless puts TISAX forward as a general "security proof" to insurers should be aware that this is more likely to cause confusion than build trust among knowledgeable clients.

    Why the confusion still happens

    The imprecision has an understandable reason: TISAX is largely based on ISO 27001 and ISO 27002 in terms of content, so there are significant overlaps. Anyone who has already established an ISMS according to ISO 27001 has thus already done most of the preparatory work for TISAX. The VDA ISA (Information Security Assessment) audit catalogue merely supplements the ISO 27001 basis with automotive-specific additional requirements such as prototype protection and an independent GDPR module. This proximity sometimes leads to both certifications being presented as largely interchangeable in communication – however, this is technically imprecise.

    What actually matters for insurance IT service providers

    For IT service providers who are active or want to become active in the German insurance market, the relevant proofs can be sorted more clearly:

    • ISO 27001 as the baseline layer. A certified ISMS according to ISO 27001 is the internationally recognised proof that insurers and their clients most frequently require in tenders and contract negotiations.
    • DORA as a sector-specific addition. For financial and insurance service providers, EU regulations such as the Digital Operational Resilience Act (DORA) as well as the corresponding BaFin requirements oblige financial institutions and their IT service providers to highly standardised security controls that build directly on ISO 27001. An ISO 27001 certificate does not completely replace DORA requirements, but it forms a solid basis for them.
    • TISAX only with an actual automotive connection. TISAX only becomes relevant for insurance IT service providers if contracts from the automotive industry are also served in parallel – for example, for service providers who support both motor insurers and automotive suppliers.
    • BSI IT-Grundschutz as a German-language alternative. For companies with close ties to German authorities or critical infrastructures, the free, German-language BSI IT-Grundschutz (IT Baseline Protection) can be a useful starting point or supplement, especially since it is also recognised as NIS2 proof.

    What a certificate achieves – and what it does not

    An ISO 27001 certificate is an effective tool to avoid recurring, individual security audits by customers: Without a certificate, clients often demand their own security checks, each costing weeks of internal preparation. With a recognised certificate, many of these customer-specific checks are no longer necessary, because the standard is considered generally recognised proof.

    What a certificate does not achieve, however, is a guarantee of actual security in everyday life. Certification and audit check whether a management system meets the standard requirements and is operated in a transparent and documented manner – they are proof of processes and structures, not a free pass against security incidents. Regular surveillance audits only ensure that the ISMS remains fundamentally effective, but do not replace a lived, daily security culture in the company.

    Practical recommendations

    • Align certification needs with the actual customer portfolio. Before investing in an additional label such as TISAX, it should be checked whether automotive-related orders exist or are planned at all.
    • Consistently use ISO 27001 as the basis for DORA compliance. Since the supervisory requirements are closely based on ISO 27001 in terms of content, it is worthwhile to build the ISMS from the outset in such a way that it serves as a basis for further regulatory proofs.
    • Precisely classify certificates in communication. Towards insurers and their clients, it should be clearly communicated which certificate covers which specific application area – blanket references to "certifications" without differentiation appear unprofessional to knowledgeable contacts.
    • Understand certification as a starting point, not a goal. The actual added value is created not by the certificate itself, but by the underlying, continuously lived security management.

    Conclusion

    ISO 27001 and TISAX solve different problems for different industries – their close content similarity may lead to confusion, but does not justify it. For IT service providers in the German insurance industry, ISO 27001 remains the central, cross-industry relevant proof, while TISAX only plays a role if there is a genuine automotive connection. Making this distinction clearly not only avoids unnecessary certification costs but also positions the company as a technically competent partner to insurers.