Three core service lines. One audit-critical scope.
Every engagement is structured the same way: what the service is, who it is for, what a finished deliverable looks like, and what is needed from your side to start. TISAX applies to the automotive supply chain. NIS2 and industrial IT and OT security cover manufacturers in other sectors on the same terms. Automation Readiness follows as a secondary line for clients whose foundation is in place.
01 / CORE
TISAX / ISA Readiness
Preparation for a TISAX assessment at AL2 or AL3 against the current ISA catalogue. The work covers the information security management system, the technical controls at site level and the evidence an assessor expects to see. Includes AL2 to AL3 transitions and additional modules for prototype protection.
WHO IT IS FOR
Tier 1–3 suppliers with an OEM or customer request for a TISAX label, typically single or multi-site plants between 100 and 2,000 employees.
WHAT DONE LOOKS LIKE
Control-by-control gap report, remediation plan with owners and dates, a complete evidence package mapped to the ISA catalogue, and a passed assessment at the agreed level.
NEEDED TO START
A scoping call, the customer requirement letter, current certificate status (ISO 27001, previous TISAX), a site list and a current network diagram.
02 / CORE
NIS2 Compliance
Implementation of the NIS2 Directive as transposed into national law for manufacturing entities. The work covers applicability determination, the risk management measures in Article 21, incident reporting procedures and the management accountability duties. Where an ISMS exists, NIS2 requirements are mapped onto it rather than run in parallel.
WHO IT IS FOR
Manufacturers classified as important or essential entities, in automotive and in other sectors brought into scope, and suppliers whose customers pass NIS2 obligations down the supply chain contractually.
WHAT DONE LOOKS LIKE
A documented applicability decision, a NIS2 control mapping against existing ISO 27001 or TISAX controls, an incident reporting procedure tested in a tabletop exercise, and a management briefing record.
NEEDED TO START
Company size and sector data, existing policies and ISMS scope, the current incident response process, and access to management for the accountability briefing.
03 / CORE
Industrial IT & OT Security
Security architecture and hardening for production systems: MES, ERP integration, plant networks and machine connectivity. The work follows IEC 62443 zoning principles and produces changes that can be implemented during planned downtime without stopping production.
WHO IT IS FOR
Plants in any manufacturing sector with flat networks, direct machine-to-ERP connections, vendor remote access without controls, or audit findings on OT segmentation.
WHAT DONE LOOKS LIKE
A zone and conduit model for the plant network, a segmentation implementation plan with firewall rule sets, hardened MES and ERP interfaces, and a controlled remote access process for machine vendors.
NEEDED TO START
Network diagrams, asset list or permission to run a passive discovery, MES and ERP integration overview, and a maintenance window schedule.
Secondary line for existing clients
Automation Readiness follows the audit work. By the time controls and evidence are in place, access to your systems, processes and owners is already established. That is what makes automating the recurring compliance workload safe and accurate. It is not offered as a standalone service.
Audit & Compliance Evidence Automation
Evidence for recurring controls is collected and filed against the ISA catalogue automatically, so the next assessment starts from a current package rather than a scramble.
Supplier & Customer Questionnaire Automation
Customer security questionnaires are pre-filled from the approved control set and returned in days, with every answer traceable to a document.
Production & Quality Reporting Automation
Shift, scrap and quality reports are produced from MES and ERP data on schedule, replacing manual spreadsheet consolidation.
Fixed price plus ongoing support, quoted per engagement.
Three ways to engage. No price list.
Services are scoped and quoted per site and per assessment level. Each engagement type below has a fixed scope and a defined deliverable.
A
Assessment
Two to four weeks. On-site and remote review, interviews and document analysis. Output: gap report and remediation plan. Fixed price.
B
Implementation
Three to eight months. Execution of the remediation plan with your IT and plant teams, policy writing, technical changes and evidence collection. Milestone-based pricing.
C
Ongoing Support
Retained days per month. External support, control monitoring, audit-window availability and Automation Readiness work. Quoted per site.
FRAMEWORKS & STANDARDS
TISAX
ISO 27001
IATF 16949
NIS2
IEC 62443