Your Expert for Questions:
Foto Tobias Franz Langkau
Tobias F. Langkau

Senior Manager

+49 1515 6424574

The standard for information security, tailored to the automotive industry

Information Security in the Automotive Industry In today’s automotive industry, secure data exchange is essential for protecting intellectual property, effectively countering cyber threats, and keeping production running. This involves not only the traditional goals of information security, such as confidentiality, integrity, and availability of information, but also ensuring a continuous supply chain and the permanent availability of goods and services.

To meet these requirements, a test catalog was developed. PwC played a key role in its design and development, and PwC Certification Services GmbH has established itself as a recognized TISAX® testing provider from the outset, drawing on experience.

TISAX® stands for “Trusted Information Security Assessment Exchange” and was launched in 2017 by the German Association of the Automotive Industry (VDA). This process is revolutionizing the assessment of information security in the automotive industry by establishing a uniform benchmark for assessing the level of maturity. It offers suppliers, in particular, a precise tool for verifying and ensuring the integrity of their data and production processes.

Based on the ISO/IEC 27001 standards, the VDA has developed a comprehensive questionnaire to ensure the highest level of information security.

Mit TISAX® zur Automobilbranche:
Unabdingbar und Ihr Schlüssel zum Erfolg!

Your advantages of TISAX at a Glance

Building Trust

As a dependable business partner, you strengthen the bond with your manufacturers and simplify contract signing.

Recognition

Strengthening existing alliances and fostering new business relationships.

Consistency

TISAX® creates an industry-wide standard for information security.

Awareness

Increase your employees’ awareness of information security.

Review of Maturity Level

Clear criteria and transparent assessments create trust.

Cost Reduction

Through standardized processes and avoidance of redundancies.

Why choose PwC as an audit provider?

We are more than just a service provider – we are your partner for sustainable success. At PwC, we are enthusiastic about developing tailored solutions for our clients and unlocking their full potential. This makes us valuable partners for your company. Why?

International network

Our global resources allow us to be there for you, no matter where you are located. The worldwide PwC network stands for quality, efficiency, and a consistent service approach.

Unified governance

We offer you a midway point of contact for all your needs – from quality control to global responsibilities.

Qualified auditors

Our experienced auditors are at the heart of our service. They are flexible, adapt to regional and local requirements, and ensure you always receive the best resources.

We’re happy to answer your questions about the TISAX® label.

Contact our experts

Your advantages of PwC as a partner briefly

Our team: The Heart of Our Expertise.

With over 600 IT and cyber risk specialists, we are not only experienced but also versatile. We address every challenge with a targeted approach to provide you with clear, valuable solutions.

Technology: Our eye for detail

As independent experts, we bring a fresh perspective to your operating models. Our expertise in information security assessment guarantees you in-depth and objective analysis.

Adaptive Methods: Flexible and Targeted

Rigidity is outdated. Our proven methods are robust and adaptable – always in line with the specific requirements of your company. With a deep database and a proven framework, we are always ready.

Sharing knowledge: Your Path to Excellence

We define your path together with you. Our team of experts in Germany, supported by the global PwC network, helps you identify and close security gaps. Because your success is our goal.

Trust: The Core of Every Relationship

Our customer loyalty speaks for itself: We focus on close, long-term partnerships. Why? Because trust matters. And because our customers know they can rely on us – today, tomorrow, always.

Need For Action?

  1. What do I need?
    TISAX® offers different assessment levels, modules, and assessment objectives. It is essential to choose the right one to ensure both OEM requirements and economic efficiency.
  2. Is TISAX relevant to me?
    Is your company involved in the supply chain or in projects with automotive manufacturers? Then you need TISAX®.
  3. Am I on the right track?
    Self-assessment is a start, but external experts can provide you with deeper insight into your security practices and any vulnerabilities. An objective review can make all the difference.
  4. How do I prepare my company?
    A comprehensive action plan that considers both technical and organizational measures is crucial. This also includes process adjustments and technical implementations.
  5. Do I need support?
    If you are unsure about any of these steps or need support, PwC is here to help. With our experience in TISAX® and the automotive industry, we offer solutions for your specific challenges.

FAQ – Frequently Asked Questions

Frequent questions about the TISAX® label

Does every company have to be TISAX® labeled?

When collaborating with leading original equipment manufacturers (OEMs) in the automotive industry, the TISAX® label is crucial. It confirms that your company meets the industry’s specific information security requirements.

Is TISAX® a certificate?

Although “TISAX® certificate” is often entered into search engines, the term “certificate” is technically incorrect. If you successfully pass the TISAX® assessment, you will receive a label, not a physical certificate.

Is TISAX® the same as NIST, SOC, or ISO/IEC 27001?

Although all these standards focus on information security, they differ in their core areas and requirements. TISAX® was designed specifically for the automotive industry.

Do I need TISAX® if I already have IATF®?

IATF® and TISAX have contrasting functions. While IATF® focuses on quality management in the automotive industry, TISAX® focuses on information security.

How long is a TISAX® label valid? 

A TISAX® label remains valid for three years. After this period, renewal is required unless significant changes have been made to the company or its organizational structure.

Questions about the TISAX® assessment

Which areas of my company are affected by the assessment?

The TISAX® assessment takes a comprehensive look at your entire company. This includes all processes, departments, systems, and resources within the company that are relevant to the protected object. The TISAX® assessment considers the entire site.

How much time and resources does preparation for a TISAX® assessment require?

Preparation for a TISAX® assessment depends heavily on the current state of your information security management system (ISMS). If your ISMS is already well established, the preparation time is significantly reduced. A key preparation step is completing the self-assessment and providing the relevant supporting documents. Since every company is unique, the required preparation time varies.

How long does an assessment take?

A TISAX® assessment extends from the kick-off meeting to the final report over a period of several days to several weeks. This depends heavily on the size and complexity of your company, the number of sites to be assessed, and the selected assessment objectives or modules.

What happens if my company fails a TISAX® assessment?

If you fail, you will receive a report on the identified vulnerabilities. It is recommended that you resolve these and retake the assessment to receive the TISAX® label. We would be happy to assist you with this.

How much does a TISAX® assessment cost?

The cost structure of a TISAX® assessment is variable and depends on several factors, in particular the number of sites to be assessed, and the specific TISAX® assessment objectives relevant to your company.

Questions about using the TISAX® label

Am I allowed to use the TISAX® label for advertising purposes?

The TISAX® label is primarily a verification for other participants in the ENX network and may not be used publicly for advertising purposes without ENX approval.

How can I share my label with others after the audit?

Your TISAX® label will be registered on the ENX platform. You can use this platform to grant business partners access to your results and your label. We would be happy to assist you with this.

What happens if the company changes its name, relocates its location, or undergoes other major changes?

In the event of significant changes such as a change of name or relocation, the audit provider must be informed of the change. We can then discuss and implement the necessary steps together.

Further information

You might also be interested in

Contact us
Joachim Mohs
Joachim Mohs

Managing Director, PwC Certification Services GmbH

Tel.: +49 170 5789544

Foto Tobias Franz Langkau
Tobias F. Langkau

Senior Manager

+49 1515 6424574