M.Sc. in Internet Security (if(is), Westfälische Hochschule). COO and authorized officer (Prokurist) with expertise in information security consulting and security awareness. Junior professor (Nachwuchsprofessur) for Cyber Security at FOM Hochschule, CISO lecturer at isits AG and doctoral candidate at the Graduierteninstitut NRW.
T.I.S.P. Certificate - Training & Exam 2026
Europe's expert certificate for information security. 5-day online intensive course with DEKRA exam - hosted on German servers, no US-based providers.
What is T.I.S.P.?
The T.I.S.P. (TeleTrusT Information Security Professional) is Europe's counterpart to CISSP - covering the same 20 knowledge domains but with a focus on EU/DACH regulation: GDPR, NIS-2, ISO 27001, and BSI IT-Grundschutz. It is DEKRA-certified and recognised across the DACH region (Germany, Austria, Switzerland).
Next date: 04-08 May 2026 · Places available
T.I.S.P. - Europe's Expert Certificate for Information Security
The T.I.S.P. certificate (TeleTrusT Information Security Professional) is a recognised expert-level certificate in information security designed specifically for the European market. It accounts for the standards, frameworks, and legislation prevalent in Europe - unlike comparable international certifications such as CISSP.
As a T.I.S.P. certificate holder, you demonstrate your qualifications, skills, and knowledge across information security, security management, and IT security. The exam is administered by the independent certification body DEKRA.
Why T.I.S.P. instead of CISSP?
While CISSP (Certified Information Systems Security Professional) is oriented around US standards and legislation, T.I.S.P. covers the same 20 knowledge areas - but with a focus on European and German regulation: GDPR, NIS-2, BSI IT-Grundschutz, and ISO 27001. For professionals working in the DACH region, T.I.S.P. is therefore the more relevant and practice-oriented certification.
Your benefits
- A recognised European expert certificate for information security - backed by the TeleTrusT association
- DEKRA-certified qualification with independent exam administration
- Access to the T.I.S.P. community and the annual TeleTrusT Community Meeting
- 20 modules covering all relevant areas of information security
- European and German legislation (GDPR, NIS-2, IT-SiG 2.0) at the forefront
- Career-boosting: ISO, CISO, security consultant, auditor - T.I.S.P. opens doors
- Optimised group size for maximum learning success (max. 15 participants)
Five modules come from our own practice
AWARE7 holds editorial responsibility for 5 of the 20 modules in the T.I.S.P. curriculum, among them hacking methods, business continuity management and incident & emergency response. We wrote this material, and the same people who wrote it teach it.
What that means for you: in these modules you are not taught from someone else's slide deck, but from the work the content came out of - penetration tests, incident response engagements and emergency drills at client sites.
T.I.S.P. Community Meeting 2026 - Chris Wojzechowski as moderator
10-11 November 2026, NH Collection Berlin-Mitte. Chris Wojzechowski co-moderates the Community Meeting with Nadine Voigt. Silas Borgmeier (AWARE7) delivers a talk: "Breaking Free from Dependence on US Cloud Services". Attendance counts as a mandatory requirement for recertification and as 8 hours towards your continuing education quota. As an AWARE7 graduate, you receive early access to registration and scheduling details.
NIS-2: Demonstrable qualification becomes mandatory
§38 BSIG (Germany's NIS-2 implementation act) obliges management of affected organisations to take personal responsibility for cybersecurity measures. The BSI now supervises around 29,500 organisations in Germany (up from roughly 4,500) - demand for demonstrably qualified ISOs has grown substantially. T.I.S.P. - with legal foundations under German and European law and BSI IT-Grundschutz in the curriculum - documents this qualification credibly and vendor-neutrally.
T.I.S.P. compared: the leading IT security certifications
Which certificate suits your situation? This overview helps you decide - especially if you operate in the DACH region.
| Criterion | T.I.S.P. | CISSP | CISM | CompTIA Security+ |
|---|---|---|---|---|
| Focus | Europe / DACH | International / USA | Management | Entry-level |
| Modules / Domains | 20 modules | 8 domains | 4 domains | 6 domains |
| Exam | 180 MC, 3 h, German | 100-150 CAT, 4 h, English | 150 MC, 4 h, English | 90 MC, 1.5 h, English/German |
| Experience required | 3 years | 5 years (or 4 yr. + degree) | 5 years (3 yr. management) | None (2 yr. recommended) |
| Total cost (course + exam) | approx. €3,560 | approx. €3,500-5,000 | approx. €2,500-4,000 | approx. €1,500-2,500 |
| Validity | 3 years + recertification | 3 years + CPE | 3 years + CPE | 3 years + CE |
| Exam language | German | English | English | English / German |
| Relevance for DACH | ★★★★★ | ★★★☆☆ | ★★★★☆ | ★★☆☆☆ |
| Legal framework DE/EU | ✓ Legal foundations | ✗ US-focused | Partially | ✗ Not included |
| BSI IT-Grundschutz | ✓ Integrated | ✗ | ✗ | ✗ |
Curriculum - 5-Day Programme
Foundations, Cryptography & PKI
4 modules · 8 teaching units
Foundations & Cryptography
- ›Security objectives (CIA triad), threats & risks
- ›Symmetric encryption (AES, 3DES)
- ›Asymmetric encryption (RSA, ECC)
- ›Hash functions, digital signatures, post-quantum
Public Key Infrastructure
- ›PKI architecture: CA, RA, trust chains
- ›X.509 certificates, CRL, OCSP
- ›Key management and key lifecycle
- ›Practice: TLS/SSL, S/MIME, code signing
Network & Application Security
4 modules · 8 teaching units
Network Security
- ›TCP/IP security and network protocols
- ›Firewall architectures and IDS/IPS
- ›VPN: IPsec, SSL-VPN, WireGuard
- ›WLAN security (WPA3) & Zero Trust (ZTNA)
Application Security
- ›Attacker methods & OWASP Top 10
- ›SQL injection, XSS, CSRF in depth
- ›Secure Software Development Lifecycle
- ›API security & microservices
Systems, Operations & Cloud Security
4 modules · 8 teaching units
Malware & Operating Systems
- ›Malware, ransomware, APTs - taxonomy
- ›Content security & email security
- ›Windows hardening & Linux security
- ›Patch & vulnerability management, EDR
Virtualisation & Cloud Security
- ›Hypervisor, Docker, Kubernetes
- ›IaaS, PaaS, SaaS - shared responsibility
- ›BSI C5 catalogue & cloud compliance
- ›MDM & BYOD strategies
Security Management & Compliance
4 modules · 8 teaching units
Authentication & Standards
- ›Authentication, authorisation, IAM
- ›MFA & passwordless methods (FIDO2)
- ›ISO 27001/27002, BSI IT-Grundschutz
- ›ISMS setup: policy, risk assessment
BCM, Awareness & Auditing
- ›BCM per ISO 22301 & incident response
- ›SOC - setup and operations
- ›Security awareness & social engineering
- ›Security audits & penetration testing
Law, Physical Security & Exam Preparation
4 modules · 8 units · incl. intensive exam preparation
Law & Physical Security
- ›GDPR: TOMs, NIS-2, IT-SiG 2.0
- ›Sector regulation: KRITIS, DORA, BAIT
- ›Liability & compliance for management
- ›Physical security & data centre protection
Exam Preparation
- ›ROI, TCO & risk management
- ›Current threat landscape and trends
- ›Intensive exam preparation with practice questions
- ›Exam strategy, time management & Q&A
DEKRA exam · Friday of the following week
180 MC questions · 3 hours · 70% pass threshold · conducted entirely in German
Who is this course for?
The T.I.S.P. certificate course is aimed at experienced professionals working in information security, IT security, and security management who wish to validate their expertise through a European-recognised certification:
- Information Security Officers (ISOs) and CISOs - demonstrating professional competence to management and auditors
- Information security consultants - differentiation in a competitive market
- IT administrators with security responsibilities - career step into security
- Data protection officers with an IT security focus - bridging the gap between DPO and ISO roles
- IT auditors and compliance managers - professional foundation for audit activities
- IT managers - demonstrating competent handling of security responsibilities
Prerequisites
- At least 3 years of professional experience in IT security or information security
- Theoretical knowledge of IT or information security - evidenced by training certificates, qualifications, or project references
- Completion of a five-day T.I.S.P. training course at a TeleTrusT-recognized provider such as AWARE7
- Admission requirements are reviewed by DEKRA - we support you with the application process
Certification details
Exam procedure
The T.I.S.P. exam is administered by DEKRA as the independent certification body. DEKRA also reviews admission requirements and issues the certificate.
- Format: 180 multiple-choice questions across all 20 modules
- Duration: 3 hours (180 minutes; approx. 60 seconds per question on average)
- Pass threshold: 70% correct answers (126 out of 180)
- Exam fee: €360 net (not included in the course fee)
- Retake: Once possible for €250 net without repeating the course
- Language: Conducted entirely in German - questions, answers, all exam materials
Exam date at AWARE7
At AWARE7, the exam always takes place on the Friday one week after the final training day. Example: training ends on 12 Jun → exam on 19 Jun. You are not obliged to take this date - on request, we coordinate a later exam date with DEKRA for you. This gives you more preparation time if needed.
Recertification - the complete guide
The T.I.S.P. certificate is valid for 3 years. Recertification extends it by a further 3 years - calculated from the original expiry date, not the application date. No repeat course or exam is required.
Important: observe the deadline
The recertification application must be submitted by the end of the 4th year after the last certification. After this point, renewal is no longer possible - the certificate expires permanently. Plan your recertification well in advance.
Three forms of evidence are required for recertification:
1. Activity record
Description of your professional activities, including the percentage of total working time spent on IT security.
2. Community Meeting
At least one visit to the T.I.S.P. Community Meeting within the last 3 years is mandatory.
The next meeting takes place on 10-11 November 2026 in Berlin - moderated by
Chris Wojzechowski (AWARE7). As an AWARE7 graduate, you receive advance registration details.
3. Continuing education record (average 20 hours per year)
Recognised continuing education includes:
- Seminars, workshops, conferences - 8 hours per event day
- Additional T.I.S.P. Community Meetings - 8 hours each
- Professional publications (articles, books) - up to max. 20 hours
- Development of training concepts - up to max. 20 hours
- Project documentation with at least 50% personal contribution - up to max. 20 hours
Recognised external training providers include: OMNISECURE, ExperTeach, Fraunhofer SIT/Lernlabor, CAST e.V., isits, secorvo, M&H, and AWARE7's own events.
Important change since June 2024: DEKRA vs. PersCert/TÜV
Since mid-June 2024, PersCert/TÜV Rheinland accepts only isits AG graduates for T.I.S.P. exams and recertification. All other training providers - including AWARE7, secorvo, and M&H - submit both initial and recertification applications exclusively to DEKRA. This change regularly causes confusion among candidates. We are happy to assist you with the correct application process.
Career paths with the T.I.S.P. certificate
The T.I.S.P. certificate opens doors to a variety of career directions:
- Information Security Officer (ISO): T.I.S.P. as a recognised qualification - ideal in combination with ISO 27001 Lead Auditor
- Security Consultant: Solid foundation for advisory work - complemented by OSCP or OSCE for technical specialisation
- CISO / Head of IT Security: Demonstrating strategic and technical competence at leadership level
- IT Auditor: T.I.S.P. + ISO 27001 Lead Auditor = the ideal combination for audit work
- Data Protection & Security: T.I.S.P. complements CIPP/E or CDPSE at the intersection of DPO and ISO roles
Salary with T.I.S.P. - market overview
T.I.S.P. certificate holders achieve above-average compensation in the German market. The following overview is based on current salary surveys for IT security roles in the DACH region:
| Career level | Gross annual salary (avg.) |
|---|---|
| ISO / Security Analyst (<3 years) | €50,000 - €60,000 |
| Security Consultant (3-7 years) | €60,000 - €80,000 |
| Senior Consultant / Lead Auditor | €75,000 - €95,000 |
| CISO / Head of IT Security | €90,000 - €130,000 |
Sources: Stepstone salary report and gehalt.de IT security (2026), jobvector salary analysis 2026; own summary. Figures vary by region, industry, and company size.
After the course
- Access to the T.I.S.P. community and the annual TeleTrusT Community Meeting
- Listing in the TeleTrusT certificate register as proof of quality
- Right to use the T.I.S.P. logo in line with TeleTrusT guidelines (e.g. on your personal website)
- Post-course materials and exam simulations from AWARE7
- Invitations to Community Meetings and AWARE7 events for recertification credits
Frequently Asked Questions
Who is T.I.S.P. suitable for?
What are the entry requirements?
How does the exam work?
What is the exam fee?
How long is the certificate valid?
What distinguishes T.I.S.P. from CISSP?
Can I combine T.I.S.P. and CISSP?
How is the online course delivered?
What is the pass rate?
What is the total cost of T.I.S.P. certification?
How does T.I.S.P. recertification work?
Which T.I.S.P. training providers exist in Germany?
Does T.I.S.P. meet NIS-2 requirements for management training?
What is the T.I.S.P. Community Meeting?
Your Instructors
Experienced experts from research and practice guide you through the certificate course.
Course Details
- Duration
- 5 days / 40 h
- Format
- Online (live)
- Max. participants
- 15
- Course fee
- €3,200 net
- Exam fee (DEKRA)
- €360 net
- Certificate
- T.I.S.P. (DEKRA)
- Exam language
- German
Upcoming Dates
- 04-08 May 2026 Online
- 12-16 Oct 2026 Online
- 14-18 Dec 2026 Online
All dates online · Contact us for in-house training
What sets us apart
- Five curriculum modules written and taught by AWARE7
- Above-average pass rate through intensive exam preparation
- Max. 15 participants for focused, interactive learning
- GDPR-compliant platform on German servers
- Community Meeting access & recertification support
"Thanks to the preparatory training, I had the opportunity to refresh my existing knowledge and pass the exam."
Michael Leinich, IT Security Consultant, Konica Minolta
Sources
Official documents & sources
The binding regulations for T.I.S.P. certification are published by TeleTrusT and DEKRA in their current versions on their own websites - including the Examination and Certification Regulations (PZO) for TSP personnel, the fee schedule, the exam registration form with admission requirements, and the recertification application.
- TeleTrusT: Certification documents PZO, fee schedule, exam registration, and recertification application as PDF downloads (in German)
- TeleTrusT: Recertification Requirements and recognized continuing education
- TeleTrusT: Training providers and dates All recognized providers with current course dates
- TeleTrusT: T.I.S.P. Community Meeting Dates of the annual meeting required for recertification
- DEKRA Certification: Personnel certification IT The independent examination and certification body
All information on this page follows the DEKRA Examination and Certification Regulations for TSP personnel (Rev. 02/02/26) and the TeleTrusT fee schedule (2024). The current version of the linked original documents always prevails.
Aus dem Blog
Weiterführende Artikel
IT-Sicherheits-Zertifizierungen im Vergleich (2026)
IT-Sicherheits-Zertifizierungen: T.I.S.P., CISSP, CISM, CompTIA Security+ und ISO 27001 Lead Auditor im Vergleich - Kosten und Karrierechancen.
IT-Zertifizierungen: ISO 27001, TISAX, T.I.S.P. und OSCP im Vergleich
Zertifizierungsvergleich: ISO 27001, TISAX, T.I.S.P., OSCP, CEH und CISSP - mit Nutzen, Anforderungen und Vergleichstabelle für Karriere und Unternehmen.
NIS2-Richtlinie: Der komplette Guide für Unternehmen in Deutschland
NIS2: Betroffenheit prüfen, alle 10 Sicherheitsanforderungen nach Art. 21, Meldepflichten und Bußgelder - Schritt-für-Schritt-Umsetzungsguide.