Certifications and standards
Understand security and quality evidence in context.
ISO/IEC 27001, ISO 9001 and TISAX address different organizational requirements. This page explains their aims, scope and assessment context. For a specific supplier review, we help clarify which current documents and information you need.

Information for your enquiry
Evidence is useful when it matches the service being assessed. Relevant details include the organization, sites, activities, validity and assessment procedure covered. The topic profiles explain these relationships. Evidence for a proposed engagement is discussed against your requirements and the current documents actually available.
ISO/IEC 27001: manage information security
The standard defines requirements for an information security management system. Risk assessment, responsibilities, controls and continual improvement form part of that context. A certificate must be assessed against its specific scope.
ISO 9001: organize quality management
ISO 9001 defines requirements for a quality management system. Customer requirements, clear processes and improvement are central. Evidence needs to be read in the context of the organization and activities covered.
TISAX: automotive information security
TISAX provides a process for assessing and exchanging information security assessment results in the automotive sector. Assessment level, objectives and scope must match the request. AL3 describes assessment depth; it is not a universal quality rating.
Clarify the evidence your project needs
Specific documents and information may be required for tenders or supplier evaluations. Specify the standard, scope, deadline and planned service. We clarify the available documents and a suitable exchange route.
How we work together
Specify the requirement precisely
Tell us which standard or assessment objective is required, for which service and scope. Existing questionnaires help clarify the requirement.
Check available documents against the scope
Requested information is compared with the current documents actually available. Validity, scope and any limitations are considered.
Resolve open questions
Any ambiguities are discussed with the responsible persons. The agreed exchange of documents takes into account confidentiality and necessary approvals.
What helps with coordination
- A clear explanation of the three standards and assessment processes.
- A more precise basis for your evidence request.
- An agreed way to clarify scope, documents and open questions.
How we can help
Request evidence
For tenders and supplier reviews: clarify the standard, service, scope and information required.
Send an enquiry: Request evidenceClarify technical requirements
For specific questions: discuss terminology, technical requirements and the relevant contacts.
Send an enquiry: Clarify technical requirementsDiscuss implementation needs
For planned actions: assess the current situation and suitable security, engineering and operational services.
Send an enquiry: Discuss implementation needsQuestions before you decide
Are ISO 27001, ISO 9001 and TISAX the same?
No. ISO/IEC 27001 addresses an information security management system, while ISO 9001 addresses a quality management system. TISAX is an assessment and exchange process in the automotive sector. The evidence needed depends on your specific requirements.
What does the scope of evidence mean?
Scope identifies the organization, sites and activities covered. It needs to be compared with the service being assessed. Naming a standard alone does not establish that coverage.
What does TISAX Assessment Level 3 mean?
AL3 describes an assessment depth within the TISAX process. Assessment objectives and scope also matter. The linked topic profile explains the terms and points to ENX information.
Does the description of a standard prove that SYNEDAT is certified?
The topic descriptions explain the standards and do not replace current evidence. For your specific assessment, we clarify available documents, scope and validity against the requested service.
How do I request documents for a supplier evaluation?
Mention the planned service, required standards, required information and your deadline. An existing questionnaire can facilitate clarification. Confidential documents are handled via a coordinated exchange channel.
Why is some evidence not available as a public download?
Documents may contain confidential information or be subject to specific exchange rules. The material needed, recipients and approvals are therefore agreed for each request. Public explanations and confidential evidence serve different purposes.
Can SYNEDAT help implement security requirements?
Our services can support technical controls, action planning and documentation within an agreed scope. Requirements and responsibilities are coordinated with your organization. Independent certification or assessment is performed by the relevant authorized bodies.
Where can I find the official information about the standards?
The linked topic profiles lead to ISO or ENX. There you will find information on the respective standards and procedures. For a specific project, the current requirements of your organization or client are also decisive.
What evidence does your supplier evaluation need?
Identify the standard, scope and requested service. We help clarify the current information and documents needed for your review.
Get in touch