Creating Information Security & Digital Trust
Creating Information Security & Digital Trust
ABOUT US
With our “NORM X Solutions” we offer a fast, cost-optimized and effective way for your certification according to TISAX®, ISO 27001 or B3S information security standard.
You are not sure yet what you need? Our IX Information Security Concept (IX ISC) includes goal setting, GAP analysis, corrective action planning (CAP) as well as budget planning. Based on the outcome of the concept you and your management team can decide on your individual information security strategy.
Together with our partners, we also offer you cross-industry solutions in the areas of security & backup, data protection, whistleblowing systems, cyber insurance & employee training.
Alle TISAX®, NORM X, IX und Partner-Lösungen lassen sich flexibel miteinander kombinieren!
WHAT DEFINES US
Working with heart & competence
We are successful because we love what we do. Our incentive is to use our expertise to protect your company’s information, ensure your continued success, and use your satisfaction as a benchmark for our working standard.
Striving for quality & innovation
We offer innovative solutions of the highest quality. We are happy to take on even the most complex challenges and master them successfully while we evolve continously.
Human & Technology hand in hand
Together with you, we actively shape the digital transformation and use the technological possibilities to tackle your challenges and achieve your goals. For us, however, people always come first and technology is a means to an end.
SOLUTIONS FOR TISAX®
- On the fast track to TISAX® assessment with NORM X for TISAX®
- Get decision support for the further proceeding in matters of information security IX Concept for TISAX®
MORE IX SOLUTIONS
- IX Information Security Concept
- Supply Chain Protection
Act - IX ESG Concept
- External Chief Information Security Officer CISO)
- Internal Audits
IX PARTNER SOLUTIONS
Benefit from our partner solutions to improve your information security, ESG and competitiveness, increase business value and achieve certifications!
All TISAX®, NORM X, IX and Partner Solutions can be combined in a flexible way!
GET IN
TOUCH
Would you like to benefit from our solutions or do you have any open questions? We are at your disposal.
Information security thrives on partnerships.
TISAX® FAQ
TISAX® stands for Trusted Information Security Assessment Exchange and is a registered trademark of the ENX Association. It is a security standard for the automotive industry – originally initiated by the German Association of the Automotive Industry (VDA) – which is intended to help increase information security in the industry. TISAX® thus serves to review and certify the information security of companies. After successfully passing the audit, companies receive a TISAX® label, which strengthens the trust of customers and partners and can serve as a competitive advantage.
Currently, there is no legal requirement for TISAX® certification. However, there is an unofficial obligation to obtain the label in order to be / remain competitive in the industry. Many OEMs now require a TISAX® label for cooperation with suppliers or partners. If you are a supplier, partner or manufacturer in the automotive industry, it is therefore advisable to obtain certification in order to increase your business opportunities.
The more complex the requirements (assessment level 1 to 3 possible), the higher the costs tend to be. Various factors must be taken into account in order to determine the specific costs: Which assessment level according to TISAX® are you aiming for? Do you already have an ISMS established and is it already ISO 27001 certified? Etc.
The level 1 assessment is a self-assessment that is not audited by a service provider. It is therefore mostly only used for internal purposes. These assessment results are only of limited validity and do not constitute a valid TISAX® label. Most manufacturers therefore require at least Assessment Level 2.
In this case, the self-assessment is audited by an accredited auditor. These assessments are often carried out by telephone. An on-site test is only conducted if you have the “prototype protection” module tested or explicitly request an on-site test.
At Level 3, a comprehensive on-site audit of your self-assessment is carried out by an auditor. This takes 2-3 days on average.
Once you have successfully completed the Level 2 or 3 assessment, you will receive a label summarizing your exam results. The label, together with the information about your assessment, can then be viewed in the ENX portal for authorized participants. In return, you can of course also view the TISAX® labels and results of other participants.
Once you have received your label, it is valid for 3 years. It must then be renewed. The costs for renewal are usually lower than for initial certification because you already have experience and certain established information security processes.
The duration of the assessments can vary significantly and depends on various factors, such as the size of your company and the number of company locations. If the company is of average size, 2-3 days on site are sufficient for the assessment procedure itself. What may take more time, however, is the preparation for the assessment. The assessment or audit should only be carried out if you fulfill the TISAX® requirements from the VDA-ISA questionnaire. Otherwise, you will not pass the audit and will not receive a label. There is a risk that you will have to undergo a follow-up audit, which in turn involves additional costs.
The preparation and examination process can take up to 8 – 12 months. The examination process itself must not take longer than 9 months from registration, otherwise you will not receive a label. Therefore, sufficient preparation for the assessment is crucial!
An already implemented and certified ISMS (information security management system) in compliance with the ISO 27001 standard is not a prerequisite for the TISAX® assessment. For the assessment, you only need to prove that you work with an information security management system and that the corresponding processes and procedures are implemented in the company. However, an existing ISO 27001 certification will provide you with a solid groundwork for the TISAX® certification.
Our scalable NORM X solution guides your company to the TISAX® assessment with the help of an information security officer from our company, automated processes, checklists and instructions. We tailor the service specifically to the needs of your company. In doing so, we enable up to 50% TCO and time savings.