Serving Tier 1–3 automotive suppliers
Industrial IT & Information Security
TISAX readiness and NIS2 compliance for automotive suppliers, from people who have sat on both sides of the audit.
SourceGround is an independent industrial IT and information security consultancy for Tier 1–3 automotive manufacturing suppliers. Scope: TISAX / ISA readiness, NIS2 compliance, and MES, ERP and plant network security.
01
Assessment
Scope the assessment level, sites and systems in scope.
Review current controls against ISA / NIS2 requirements.
Interviews with IT, security and plant management.
01
Assessment
Scope the assessment level, sites and systems in scope.
Review current controls against ISA / NIS2 requirements.
Interviews with IT, security and plant management.
02
Gap Analysis
Control-by-control gap report with maturity ratings.
Findings prioritised by audit risk and effort.
Evidence inventory: what exists, what is missing.
03
Remediation Roadmap
Sequenced plan with owners, milestones and budgets.
Policies, procedures and technical controls specified.
Network segmentation and OT hardening where required.
04
Audit Support
Evidence package prepared for the assessor.
Pre-assessment walkthrough with your team.
On-call during the assessment and corrective actions.
ROADMAP
GAP ANALYSIS
ASSESS
AUDIT SUPPORT
ROADMAP
GAP ANALYSIS
ASSESS
AUDIT SUPPORT
Overview
SourceGround works with automotive suppliers that need to pass a TISAX assessment, meet NIS2 obligations, or secure plant IT and OT systems. The founder has held IT Team Lead and Local Information Security Officer roles at a Tier-1 supplier, and a lead IATF 16949 auditor covers quality-system scope. The advice reflects what assessors actually check.
Tier-1, AL2 → AL3
Illustrative
01
Assessment, 2 weeks
02
Gap report, 42 findings
03
Remediation, 5 months
04
Assessment passed
TISAX
Took a Tier-1 supplier site through AL3 assessment as its LISO.
IATF 16949
Quality system context for every security control.
LISO
Local Information Security Officer credential, held in role.
01
Capabilities
Capabilities
Three service lines for audit-critical scope
Each engagement is scoped against the standard your customers audit you on. Full detail on the Capabilities page.
TISAX / ISA Readiness
001
Gap assessment, remediation and evidence preparation for AL2 and AL3 assessments against the current ISA catalogue.
NIS2 Compliance
002
Scope determination, risk management measures, incident reporting readiness and management accountability under NIS2.
Industrial IT & OT Security
003
Plant network segmentation, MES and ERP hardening, and secure remote access for production environments.
Automation Readiness
After the audit foundation is in place
Once the audit and compliance foundation is in place, we also help automate the ongoing evidence, reporting and questionnaire work behind it. Evidence collection, supplier questionnaires and production or quality reporting are the current scope. Ask about Automation Readiness.
FAQ
Common questions before an engagement
STILL HAVE QUESTIONS?
Send the company, supplier tier and general scope. A written reply follows within two working days.
Do we need TISAX if our customer has not asked for it yet?
Most OEMs and Tier-1 customers request a TISAX label before sharing prototype data or connecting systems. Starting before the request arrives usually saves three to six months. The first step is a short scoping call to determine the likely assessment level.
Which assessment levels do you support?
AL2 and AL3, including the transition from AL2 to AL3 and additional modules for prototype protection and data protection. Scope is agreed against the current ISA catalogue version.
Does NIS2 apply to our plant?
It depends on size, sector and national transposition. Manufacturing of motor vehicles and parts is listed as an important entity sector. We document the applicability decision so it can be shown to management and to customers.
How is client information handled?
Under NDA, on separated systems, with no reuse across clients. Network diagrams and evidence stay within your infrastructure where possible. No client names are published on this site.
How long does a typical engagement take?
An assessment and gap report takes two to four weeks. Remediation depends on the number and depth of findings, typically three to eight months. Audit support covers the assessment window and corrective actions.
What is Automation Readiness?
A secondary service for existing clients. Once controls and evidence are in place, recurring work such as evidence collection, supplier questionnaires and quality reporting can be automated. It follows the audit work and is quoted separately.
Do we need TISAX if our customer has not asked for it yet?
Most OEMs and Tier-1 customers request a TISAX label before sharing prototype data or connecting systems. Starting before the request arrives usually saves three to six months. The first step is a short scoping call to determine the likely assessment level.
Which assessment levels do you support?
AL2 and AL3, including the transition from AL2 to AL3 and additional modules for prototype protection and data protection. Scope is agreed against the current ISA catalogue version.
Does NIS2 apply to our plant?
It depends on size, sector and national transposition. Manufacturing of motor vehicles and parts is listed as an important entity sector. We document the applicability decision so it can be shown to management and to customers.
How is client information handled?
Under NDA, on separated systems, with no reuse across clients. Network diagrams and evidence stay within your infrastructure where possible. No client names are published on this site.
How long does a typical engagement take?
An assessment and gap report takes two to four weeks. Remediation depends on the number and depth of findings, typically three to eight months. Audit support covers the assessment window and corrective actions.
What is Automation Readiness?
A secondary service for existing clients. Once controls and evidence are in place, recurring work such as evidence collection, supplier questionnaires and quality reporting can be automated. It follows the audit work and is quoted separately.