TISAX Penetration Testing Providers

Trusted Information Security Assessment Exchange · Europe

TISAX is the information security assessment standard for the European automotive industry, based on ISO 27001 and the VDA Information Security Assessment (ISA) catalogue. Managed by the ENX Association, TISAX is required by major automotive manufacturers including Volkswagen, BMW, Mercedes-Benz, and their tier-1 suppliers.

TISAX assessments evaluate information security maturity across areas including access control, cryptography, operations security, and supplier relationships. Penetration testing is a key component of demonstrating security maturity at higher TISAX assessment levels, particularly for organisations handling prototypes, unreleased vehicle designs, and sensitive R&D data.

Organisations seeking TISAX certification at Level 3 (highest) must demonstrate robust security testing practices including regular penetration testing of systems handling sensitive automotive data. TISAX certification is valid for three years, and organisations must maintain their security posture throughout this period, including regular security testing and vulnerability management.

Particularly relevant for Manufacturing pen testing providers.

4 providers
Frankfurt, Germany · Checked Sept 2026

Frankfurt-based European payment security specialist holding the full set of PCI credentials (QSA, PFI, ASV, P2PE). Manual-first penetration testing for fintechs, acquirers, and regulated enterprises.

Accreditations: PCI QSA, PCI PFI, PCI ASV, ISO 27001
Services: Web Application, Network, Cloud, API +5
Vienna, Austria · Checked Sept 2026

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.

Accreditations: ISO 27001
Services: Web Application, Network, Mobile App, IoT +7
Berlin, Germany · Checked Sept 2026

Berlin-headquartered German cybersecurity consultancy with 30+ years of BSI IT-Grundschutz experience. Trusted by federal agencies, DAX corporations, and critical infrastructure operators.

Accreditations: BSI Certified, ISO 27001, ISO 9001
Services: Web Application, Network, Cloud, API +7

PCA Cyber Security

Embedded Security Specialist
Munich, Germany · Checked Sept 2026

Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.

Services: IoT, Network, Source Code Review, API +11

TISAX FAQs

Is TISAX only for automotive companies?+

TISAX is primarily required by automotive manufacturers and their supply chain, including IT service providers, engineering firms, and logistics companies that handle sensitive automotive data.

Does TISAX require penetration testing?+

At higher assessment levels, TISAX requires evidence of regular security testing. Penetration testing demonstrates security maturity and is expected for Level 3 assessments covering highly sensitive data.

How does TISAX relate to ISO 27001?+

TISAX is based on ISO 27001 with automotive-specific additions from the VDA ISA catalogue. Having ISO 27001 certification helps but does not automatically satisfy TISAX requirements.