VERGLEICHE
CISSP or TISP? One Builds, the Other Governs
Both are considered heavyweights for experienced security professionals, yet they target different kinds of work: the CISSP centres on designing and building secure systems, the T.I.S.P. on oversight, assessment, and governance within the German regulatory framework.
By Daniel Thomas HeesselLast updated: July 30, 20267 min read
"CISSP or T.I.S.P." is the question asked by security professionals who work in the German market and are deciding between a global classic and a German certification. Unlike a comparison of two international certifications, this is not about nuances in profile but about a fundamental fork in the road: international visibility or anchoring in the German regulatory and public-sector environment.
At first glance they look comparable: both are demanding exams for experienced practitioners, both cover a broad field of information security. But they are built for different markets. The CISSP is a globally recognised generalist credential, the T.I.S.P. a German certification that plays virtually no role outside the DACH region but sets a clear quality signal within the German market.
What the two stand for
The CISSP (Certified Information Systems Security Professional) from ISC2 is the internationally best-known generalist certification in information security. Its eight domains range from security architecture through network and identity management to software development security. It appears in job postings worldwide, especially in large corporations, in the cloud space, and wherever international teams and clients come together.
The T.I.S.P. (TeleTrusT Information Security Professional) is run by the Bundesverband IT-Sicherheit (TeleTrusT, the German IT security association) and examined exclusively in German. Its content centres on the German regulatory and legal framework: ISO 27001, BSI IT-Grundschutz, GDPR, and NIS-2. It targets people who work in public authorities, in the KRITIS (critical infrastructure) environment, or in German security consulting and want to demonstrate exactly that grounding.
The numbers side by side
| Provider | ISC2 | TeleTrusT |
|---|---|---|
| Acquisition cost (exam, EUR) | €689 | €3,860 |
| Total cost over 5 years (EUR)i | €17,310 | €12,070 |
| Prerequisites | 5 years cumulative work experience in at least 2 of the 8 CISSP domains. 1 year may be substituted by a college degree or approved certification. Without experience: Associate of ISC2 possible. | Five-day preparation course at an accredited training provider (e.g., Fraunhofer SIT, secuvera) is mandatory admission requirement. |
| Exam format | CAT-based, 100–150 questions, 3 hours, proctored via Pearson VUE. Passing score: 700/1000 points. | 180 multiple-choice questions, 4 hours, closed-book, passing score 70% (126 of 180). Examination by DEKRA Certification GmbH. |
| Validity | 3 years | 3 years |
| CPE effort | 40 hrs/year | 20 hrs/year |
| CertMap scoreHow we score → | 11 / 12Market strength 6/6 Substance5/6 | 7 / 12Market strength 3/6 Substance4/6 |
Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.
NICE work role coverage
17 work roles mapped against the NICE framework. Overlap: 3.

CISSP
7 unique
In both
3 shared

T.I.S.P.
7 unique
Shared roles (3)
Cybersecurity Architecture
NICE role: Cybersecurity Architecture.Typical job titles: Security Architect, Sicherheitsarchitekt, Cybersecurity Architect, IT-Sicherheitsarchitekt
Executive Cybersecurity Leadership
NICE role: Executive Cybersecurity Leadership.Typical job titles: CISO, Chief Information Security Officer, Head of Security, IT-Sicherheitschef, Leiter Informationssicherheit
Systems Security Management
NICE role: Systems Security Management.Typical job titles: Informationssicherheitsbeauftragter, ISB, IT-Sicherheitsbeauftragter, Information Security Officer, Security Manager, ISSM
Grey boxes appear in both. Each box = 1 work role, hover shows the name.
Source: curated CertMap mapping against the NICE framework (NIST SP 800-181). Applied uniformly to both certifications, as not all are listed in the C3 crosswalk.
Two patterns stand out in the table that no marketing copy mentions:
- On money, the picture flips with the time horizon. The T.I.S.P. starts out considerably more expensive because the five-day preparation course is mandatory. Over five years this reverses: the CISSP demands twice as many continuing-education hours per year, and that working time costs money. In the end the T.I.S.P. comes out ahead. Anyone comparing exam prices alone sees none of this.
- Reach and language are a criterion in themselves. The CISSP is multilingual and recognised worldwide, the T.I.S.P. German-language and limited to the DACH region. For an international career that is a hard difference; in the German public sector it hardly matters.
The most important difference, however, is not in the cost rows but in the fields of work. The role mapping below the table shows it: the CISSP's centre of gravity lies in designing and developing secure systems, the T.I.S.P.'s in oversight, assessment, and governance. The overlap is small.
The T.I.S.P. is not the CISSP for Europe. One builds, the other governs. Two professions, not two variants of the same one.
Prerequisites: experience versus mandatory course
The two regulate access in fundamentally different ways:
- CISSP: Five years of cumulative professional experience in at least two of the eight CISSP domains. One year can be substituted by a university degree or a recognised certification. Those who lack the experience can still sit the exam and become an "Associate of ISC2" until they have it.
- T.I.S.P.: No formal years-of-experience requirement, but the five-day preparation course at an accredited training provider (such as Fraunhofer SIT or secuvera) is mandatory before you may sit the exam.
The difference is tangible in practice: the CISSP puts proven hands-on experience first, the T.I.S.P. structured preparation through the mandatory course.
The exams
The CISSP exam is adaptive (CAT): 100 to 150 questions in three hours, difficulty adjusts to your answers, a pass requires 700 of 1000 points; it is offered in several languages, including German. The T.I.S.P. exam is classically linear: 180 multiple-choice questions in four hours, closed book, 70 percent pass mark, exclusively in German, administered by the DAkkS-accredited DEKRA Certification GmbH.
One difference lies in the rhythm, and it rarely comes through in product descriptions: with the T.I.S.P., the exam follows hard on the heels of the mandatory course, in practice Monday to Friday intensive training with the exam on the following Monday. With the CISSP you choose your date freely, can prepare for months, and can reschedule. The T.I.S.P. exam situation is therefore more compressed than the bare format specs suggest.
Our assessment
What our rating says: In the CertMap rating, the CISSP is clearly ahead, and the gap arises almost entirely from market recognition. The reason can be quantified: after more than two decades, the T.I.S.P. counts roughly 2,300 certified holders, the CISSP more than 170,000 worldwide. That is not a statement about the substantive quality of the T.I.S.P., whose curriculum actually maps the German regulatory and legal framework more precisely, but about awareness and reach. Whoever posts an information security job today usually names CISSP or CISM, often simply because the T.I.S.P. is not known. How the rating axes are constructed is explained in the rating methodology.
That the gap turns out this way is no accident. In the US, the CISSP is anchored via DoD Directive 8140 as a mandatory requirement for certain cybersecurity roles. Regulation creates demand, demand creates visibility, and in its wake come the role crosswalks from which our mapping for international certifications is derived (the T.I.S.P. is not listed there, which is why the mapping above rests on our curated assignment for both, uniformly). For the T.I.S.P., the transposition of NIS-2 into German law offered a comparable opportunity: qualification requirements for security officers in critical infrastructures could have anchored it as a reference. That opportunity was not taken. What the T.I.S.P. lacks therefore lies not in the certification itself, but in the market enforcement behind it.
The decision becomes easier when approached from the target market:
- Those working internationally, in large corporations, or in the cloud environment who need a globally legible signal are right with the CISSP. It is the entry ticket for roles where international recognition is assumed.
- Those operating in the German public-sector, KRITIS, or consulting environment who want to demonstrate competence in the German regulatory and legal framework (BSI, GDPR, NIS-2) will find the more fitting credential in the T.I.S.P.
- The two are not mutually exclusive: for professionals with international ambitions and a German centre of work, the combination is a reasonable choice, even though both must be maintained separately.
Why the T.I.S.P. is often described as "the German answer to the CISSP" and what lies behind that framing is covered in the T.I.S.P. profile article.
Frequently asked questions
Is the T.I.S.P. internationally recognised?
No. The T.I.S.P. is a German certification oriented towards the DACH region. Outside Germany it is barely known; anyone who needs international visibility is better served by the CISSP.
Is the T.I.S.P. easier than the CISSP?
The two cannot be compared directly on difficulty because they test different focal points. The CISSP is broader and more technically international in orientation, the T.I.S.P. more strongly oriented towards the German regulatory and legal framework. Both require solid preparation.
Is the T.I.S.P. worth it despite its limited reach?
In the German public sector, in the KRITIS environment, and in German security consulting it is a recognised signal and often a more precise fit there than an international title. Outside that market it quickly loses weight.
Will the T.I.S.P. gain importance in the future?
That depends less on the curriculum than on marketing and regulation. As long as no binding qualification requirements name it as a reference and it barely appears in job postings, its reach will remain limited. Anyone deciding today should therefore start from the current state, not from a hoped-for upgrade.
Read next:T.I.S.P.: Germany's Answer to the CISSP. A Missed Opportunity →TCO Methodology in Portfolio Mode →