TISAX® compliance for Level 1–3.
End-to-end consulting for TISAX® assessments by a certified ISO/IEC 27001:2022 Lead Auditor.
Pre-release designs, campaign material, and world premieres can't leak under any circumstances before the official reveal. We build TISAX®-compliant security concepts for handling and transmitting highly sensitive visual data.
A clear path from your current security posture to a demonstrable assessment result.
We assess your current information security against the TISAX® requirements.
Security concepts, DLP protocols, and processes are implemented together.
Documentation and evidence are prepared to be audit-ready.
We guide you through the TISAX® assessment all the way to the label.
From the concept phase to the world premiere, every weak point has to be ruled out.
Images and video of new models can't circulate before the official reveal — every leak is a PR risk.
Automakers and suppliers increasingly require demonstrable TISAX® compliance from every project participant.
Agencies, production teams, and approval bodies across multiple locations need to be coordinated and secured.
Design assets and campaign material need to stay protected throughout transmission between stakeholders.
From the concept phase to the world premiere — security concepts that match the industry's pace.
End-to-end consulting for TISAX® assessments by a certified ISO/IEC 27001:2022 Lead Auditor.
Security concepts for handling and transmitting highly sensitive visual data before publication.
Coordinated security concepts across multiple agencies, production teams, and locations — through to the world premiere.
Comprehensive data security strategy to protect confidential artist and production information across the campaign lifecycle.
Security concepts for global world premieres and campaigns.
Robust security concept for handling and transmitting sensitive visual data — complete confidentiality of all pre-release assets.
Comprehensive data security strategy safeguarding confidential artist and production information throughout the campaign lifecycle.
Complete information security for the global launch of the BMW XM — pre-release data and marketing materials secured with DLP protocols.
Full information security for the world premiere of the all-electric MINI Aceman, protecting all design data from conception to reveal.
TISAX® (Trusted Information Security Assessment Exchange) is a security standard developed by the VDA (German Association of the Automotive Industry) that lets manufacturers and suppliers share and reuse information-security assessment results instead of each running a separate audit on every partner. Manufacturers, tier-1/tier-2 suppliers, and agencies working with confidential automotive data — engineering specs, unreleased vehicle designs, campaign material before a launch — are typically required by an OEM partner to demonstrate TISAX® compliance at one of three assessment levels (AL1 to AL3) before they are allowed to receive that data at all.
It depends on the desired assessment level (AL1 to AL3) and your starting IT security posture — a company with an existing ISMS and documented policies moves through preparation faster than one starting from nothing. We begin with a gap analysis against the VDA ISA criteria catalogue, which gives a realistic project timeline rather than a generic estimate, followed by closing identified gaps and then the formal assessment itself, which is scheduled directly with the assessment provider once preparation is complete.
Through DLP protocols, granular access controls, and encrypted transfer channels, we ensure design and campaign material is only accessible to authorized people until the agreed release date.
A good TISAX® consultant should hold the actual TISAX® Information Security Consultant certification, not just general ISO 27001 experience applied loosely to automotive — the VDA ISA criteria catalogue has automotive-specific requirements that a generalist compliance boutique frequently misses. JF Agency is a certified TISAX® Information Security Consultant (TÜV Rheinland) that has handled pre-release confidentiality for Porsche, BMW, and MINI campaigns specifically, and additionally combines this with Apple device management expertise via Mosyle MDM — relevant if your fleet handling the confidential material is Mac- or iPad-based rather than Windows.
What to check before your TISAX assessment.
Enterprise Architecture for design studios.
Apple IT for creative studios and design teams.
Risk management, ISMS, and zero-trust architecture.