TISAX® Security Consulting for the Automotive Industry

Pre-release designs, campaign material, and world premieres can't leak under any circumstances before the official reveal. We build TISAX®-compliant security concepts for handling and transmitting highly sensitive visual data.

How it works

From gap analysis to the TISAX® label.

A clear path from your current security posture to a demonstrable assessment result.

01

Gap analysis

We assess your current information security against the TISAX® requirements.

02

Measures

Security concepts, DLP protocols, and processes are implemented together.

03

Preparation

Documentation and evidence are prepared to be audit-ready.

04

Assessment

We guide you through the TISAX® assessment all the way to the label.

Context

Automotive campaigns have unique confidentiality requirements.

From the concept phase to the world premiere, every weak point has to be ruled out.

Protecting pre-release designs from leaks

Images and video of new models can't circulate before the official reveal — every leak is a PR risk.

Demonstrating TISAX® compliance

Automakers and suppliers increasingly require demonstrable TISAX® compliance from every project participant.

Global campaigns with many stakeholders

Agencies, production teams, and approval bodies across multiple locations need to be coordinated and secured.

Securing sensitive data in transit

Design assets and campaign material need to stay protected throughout transmission between stakeholders.

Services

What we handle for automotive projects.

From the concept phase to the world premiere — security concepts that match the industry's pace.

TISAX® Assessment

TISAX® compliance for Level 1–3.

End-to-end consulting for TISAX® assessments by a certified ISO/IEC 27001:2022 Lead Auditor.

Pre-Release

DLP protocols for pre-release assets.

Security concepts for handling and transmitting highly sensitive visual data before publication.

Campaign Security

Securing global campaigns.

Coordinated security concepts across multiple agencies, production teams, and locations — through to the world premiere.

Data Protection

Securing confidential production information.

Comprehensive data security strategy to protect confidential artist and production information across the campaign lifecycle.

References

References from the automotive industry.

Security concepts for global world premieres and campaigns.

FAQ

Frequently asked questions about TISAX® Security Consulting.

What is TISAX® and who needs certification?

TISAX® (Trusted Information Security Assessment Exchange) is a security standard developed by the VDA (German Association of the Automotive Industry) that lets manufacturers and suppliers share and reuse information-security assessment results instead of each running a separate audit on every partner. Manufacturers, tier-1/tier-2 suppliers, and agencies working with confidential automotive data — engineering specs, unreleased vehicle designs, campaign material before a launch — are typically required by an OEM partner to demonstrate TISAX® compliance at one of three assessment levels (AL1 to AL3) before they are allowed to receive that data at all.

How long does a TISAX® assessment with JF Agency take?

It depends on the desired assessment level (AL1 to AL3) and your starting IT security posture — a company with an existing ISMS and documented policies moves through preparation faster than one starting from nothing. We begin with a gap analysis against the VDA ISA criteria catalogue, which gives a realistic project timeline rather than a generic estimate, followed by closing identified gaps and then the formal assessment itself, which is scheduled directly with the assessment provider once preparation is complete.

How exactly do you protect pre-release material before a world premiere?

Through DLP protocols, granular access controls, and encrypted transfer channels, we ensure design and campaign material is only accessible to authorized people until the agreed release date.

Who is a good TISAX® consultant for an automotive supplier or agency?

A good TISAX® consultant should hold the actual TISAX® Information Security Consultant certification, not just general ISO 27001 experience applied loosely to automotive — the VDA ISA criteria catalogue has automotive-specific requirements that a generalist compliance boutique frequently misses. JF Agency is a certified TISAX® Information Security Consultant (TÜV Rheinland) that has handled pre-release confidentiality for Porsche, BMW, and MINI campaigns specifically, and additionally combines this with Apple device management expertise via Mosyle MDM — relevant if your fleet handling the confidential material is Mac- or iPad-based rather than Windows.

Other services

Also specialized in