Blog

Why Auto Component Suppliers Score Poorly on OEM Cybersecurity Assessments, and the Nine Documents That Close Most of the Gap

Scored assessments award marks for documented evidence, not for practice. That is why secure suppliers score badly, and nine documents close most of the gap.

Neha Dvivedi · 13 September 2026

Suppliers who score poorly on a customer cybersecurity assessment are rarely insecure. The scoring basis explains why. Marks are awarded for documented, approved and dated evidence, not for practice, and a great deal of what a component manufacturer already does every day produces no evidence at all.

The gap is evidence, not practice

Consider what a typical component manufacturer already does. Access to the ERP system is granted on a manager’s approval and removed when someone leaves. The firewall denies by default. Workstations lock after a few minutes. USB ports are restricted with exceptions approved by the IT head. Visitors sign in. Backups run.

Every one of those is a control an assessor would credit. Most score nothing, because full marks generally require the name of the internal regulation, the year it was established, and evidence of revision and adoption. A control operating by shared understanding rather than documented procedure produces nothing to show.

This is the most useful thing to understand before starting remediation. The task is not usually to become secure. It is to make what already happens visible, approved and dated.

The second common loss: undeclared plans

The marking scheme allows partial credit where measures are underway, provided current status and a scheduled completion date are recorded. Those marks are available and easily forfeited.

An organisation that has evaluated a log management solution, obtained quotations and scheduled implementation can claim partial credit. The same organisation that has done identical thinking but written none of it down claims nothing. Where a control requires capital expenditure that cannot be committed immediately, a documented and dated plan is the correct answer, and a far better one than silence.

The nine documents that close most of the gap

The following address the majority of documentation-related losses. None requires significant expenditure.

  • 1. Information security policy. Approved by management, covering scope, roles, acceptable use, access control, asset handling and an annual review cycle. Published where staff can reach it, with evidence of accessibility. Assessments weight governance heavily, and this document underpins checkpoints across several families.
  • 2. Access control procedure and RBAC matrix. A documented role-to-access mapping for ERP, email, shared drives and shop floor systems, with a defined approval route and periodic access review. Add a segregation of duties matrix, which is separately assessed.
  • 3. Administrator account list. A centralised record of privileged accounts across all platforms with assigned privileges, updated on change and reviewed periodically.
  • 4. Acceptable use and removable media policy. Rules for company IT equipment covering permitted use, prohibited actions and lost device handling, with a documented position on USB and removable storage. Extend to a short clause on external uploads and social media.
  • 5. Awareness training calendar and records. An annual schedule covering induction and periodic refreshers on phishing, acceptable use and incident reporting, with attendance records and a post-session evaluation. Assessments look for evidence of effectiveness, not only delivery.
  • 6. Network and data flow diagrams. Most suppliers have a network diagram that scores nothing because it carries no title, version number, approval or review date. Reissue it as a controlled document and add a data flow diagram for critical systems.
  • 7. Change management procedure. A documented change request carrying a security impact analysis, authorisation before implementation, a fallback position, and a retained change log, with periodic verification that implemented changes match approved requests.
  • 8. Log retention definition. A stated retention period for email, firewall, authentication, remote access and endpoint logs, with a documented review schedule and retained review records. Indian suppliers carry an independent statutory obligation here under the CERT-In Directions of April 2022, which should be reflected in the policy.
  • 9. Business continuity plan. A documented plan with defined recovery point and recovery time objectives, stated as RPO and RTO, a business impact analysis identifying critical systems, and at least one drill record. Business continuity is among the most heavily weighted areas, and organisations producing nothing here lose a disproportionate share of the total.

Two supporting items are worth adding at the same time. Extend non-disclosure agreements to contractors and third party personnel, not only direct employees, since assessment scope commonly reaches outside employees including temporary staff. And formally assign responsibility for information security to a named person within the existing management structure, with a documented contact list. The absence of a named accountable individual is a heavily weighted failure that costs nothing to correct.

What legitimately takes longer

Some gaps cannot be closed with documentation. Centralised log management, mobile device management, immutable backup storage and network segmentation require expenditure and time. These should not be rushed, and should not be left blank either. Record the requirement, the evaluation status and a committed date, and claim the partial credit a documented plan attracts.

One gap surprises organisations that consider themselves well covered. An ISO/IEC 27001 certificate scoped to corporate IT does not extend to the production environment. Where an assessment reaches plant systems, the relevant standards are IEC 62443-2-1 and IEC 62443-3-3, and a supplier may need to widen scope rather than assume existing certification answers the question.

Sequencing the work

Assign a single owner. Draft the information security policy first, because several other documents sit within its framework and governance carries the heaviest weight. Take the administrator account list, session and access configurations and removable media position next, since these describe controls that already operate. Then the training calendar, change procedure and log retention definition. Leave business continuity to last but do not omit it, because it carries weight out of proportion to the effort involved.

The submission windows in these assessments are measured in weeks, not months. A supplier approaching the exercise as documentation with a defined owner and a dated plan has a realistic path to a defensible score within one improvement cycle. One approaching it as a technology procurement exercise will miss the deadline and close nothing.

Where the number of open checkpoints makes the submission window look unrealistic, a structured gap assessment against the instrument is usually the fastest way to separate what can be closed with documentation from what genuinely needs investment.

The full reference guide to the control families and scoring sets out what each area asks for, and ISO 22301 addresses the continuity section that costs suppliers most. MSCi works with automotive component manufacturers on exactly this work. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. The free readiness checklist shows where the gaps are.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles