Serving Tier 1–3 automotive suppliers

Industrial IT & Information Security

TISAX readiness and NIS2 compliance for automotive suppliers, from people who have sat on both sides of the audit.

SourceGround is an independent industrial IT and information security consultancy for Tier 1–3 automotive manufacturing suppliers. Scope: TISAX / ISA readiness, NIS2 compliance, and MES, ERP and plant network security.

01

Assessment

Scope the assessment level, sites and systems in scope.

Review current controls against ISA / NIS2 requirements.

Interviews with IT, security and plant management.

01

Assessment

Scope the assessment level, sites and systems in scope.

Review current controls against ISA / NIS2 requirements.

Interviews with IT, security and plant management.

02

Gap Analysis

Control-by-control gap report with maturity ratings.

Findings prioritised by audit risk and effort.

Evidence inventory: what exists, what is missing.

03

Remediation Roadmap

Sequenced plan with owners, milestones and budgets.

Policies, procedures and technical controls specified.

Network segmentation and OT hardening where required.

04

Audit Support

Evidence package prepared for the assessor.

Pre-assessment walkthrough with your team.

On-call during the assessment and corrective actions.

ROADMAP

GAP ANALYSIS

ASSESS

AUDIT SUPPORT

ROADMAP

GAP ANALYSIS

ASSESS

AUDIT SUPPORT

Overview

SourceGround works with automotive suppliers that need to pass a TISAX assessment, meet NIS2 obligations, or secure plant IT and OT systems. The founder has held IT Team Lead and Local Information Security Officer roles at a Tier-1 supplier, and a lead IATF 16949 auditor covers quality-system scope. The advice reflects what assessors actually check.

Tier-1, AL2 → AL3

Illustrative

01

Assessment, 2 weeks

02

Gap report, 42 findings

03

Remediation, 5 months

04

Assessment passed

TISAX

Took a Tier-1 supplier site through AL3 assessment as its LISO.

IATF 16949

Quality system context for every security control.

LISO

Local Information Security Officer credential, held in role.

01

Capabilities

Capabilities

Three service lines for audit-critical scope

Each engagement is scoped against the standard your customers audit you on. Full detail on the Capabilities page.

TISAX / ISA Readiness

001

Gap assessment, remediation and evidence preparation for AL2 and AL3 assessments against the current ISA catalogue.

NIS2 Compliance

002

Scope determination, risk management measures, incident reporting readiness and management accountability under NIS2.

Industrial IT & OT Security

003

Plant network segmentation, MES and ERP hardening, and secure remote access for production environments.

Automation Readiness

After the audit foundation is in place

Once the audit and compliance foundation is in place, we also help automate the ongoing evidence, reporting and questionnaire work behind it. Evidence collection, supplier questionnaires and production or quality reporting are the current scope. Ask about Automation Readiness.

FAQ

Common questions before an engagement

STILL HAVE QUESTIONS?

Send the company, supplier tier and general scope. A written reply follows within two working days.

Do we need TISAX if our customer has not asked for it yet?

Most OEMs and Tier-1 customers request a TISAX label before sharing prototype data or connecting systems. Starting before the request arrives usually saves three to six months. The first step is a short scoping call to determine the likely assessment level.

Which assessment levels do you support?

AL2 and AL3, including the transition from AL2 to AL3 and additional modules for prototype protection and data protection. Scope is agreed against the current ISA catalogue version.

Does NIS2 apply to our plant?

It depends on size, sector and national transposition. Manufacturing of motor vehicles and parts is listed as an important entity sector. We document the applicability decision so it can be shown to management and to customers.

How is client information handled?

Under NDA, on separated systems, with no reuse across clients. Network diagrams and evidence stay within your infrastructure where possible. No client names are published on this site.

How long does a typical engagement take?

An assessment and gap report takes two to four weeks. Remediation depends on the number and depth of findings, typically three to eight months. Audit support covers the assessment window and corrective actions.

What is Automation Readiness?

A secondary service for existing clients. Once controls and evidence are in place, recurring work such as evidence collection, supplier questionnaires and quality reporting can be automated. It follows the audit work and is quoted separately.

Do we need TISAX if our customer has not asked for it yet?

Most OEMs and Tier-1 customers request a TISAX label before sharing prototype data or connecting systems. Starting before the request arrives usually saves three to six months. The first step is a short scoping call to determine the likely assessment level.

Which assessment levels do you support?

AL2 and AL3, including the transition from AL2 to AL3 and additional modules for prototype protection and data protection. Scope is agreed against the current ISA catalogue version.

Does NIS2 apply to our plant?

It depends on size, sector and national transposition. Manufacturing of motor vehicles and parts is listed as an important entity sector. We document the applicability decision so it can be shown to management and to customers.

How is client information handled?

Under NDA, on separated systems, with no reuse across clients. Network diagrams and evidence stay within your infrastructure where possible. No client names are published on this site.

How long does a typical engagement take?

An assessment and gap report takes two to four weeks. Remediation depends on the number and depth of findings, typically three to eight months. Audit support covers the assessment window and corrective actions.

What is Automation Readiness?

A secondary service for existing clients. Once controls and evidence are in place, recurring work such as evidence collection, supplier questionnaires and quality reporting can be automated. It follows the audit work and is quoted separately.

Create a free website with Framer, the website builder loved by startups, designers and agencies.