Automotive & Suppliers · TISAX Prototype Protection

Physical security for
plant sites & prototypes

TISAX is close to mandatory for suppliers in the German automotive industry. For the full picture, VDA ISA, Assessment Levels, certification labels, head to our dedicated TISAX page. This page covers what a questionnaire can't: physical security around plant sites, R&D areas, and prototypes, exactly what an auditor checks during the on-site walkthrough.

Focused on the site walkthrough & prototype protection Experience with OEM & Tier-1 requirements Free initial consultation
What you get
A real access attempt, not a checklist
We simulate how someone would actually try to get near a prototype, instead of just checking whether a door is locked on paper.
No disruption to the line
Timing and depth are agreed in advance so production and R&D keep running undisturbed.
Ready to hand to your auditor
The report gives you exactly the evidence your TISAX auditor expects to see during the site walkthrough.
Flagship topic

The perimeter test your site walkthrough already expects

From Assessment Level 2 upward, a site walkthrough is part of the TISAX process, and AL3 requires a full on-site audit. That's exactly where plant premises, R&D areas, and prototype storage get checked against a real access attempt. A realistic physical and social-engineering assessment is exactly the preparation for what the auditor will look for in person.

A realistic scenario
01

The pretext

A tester shows up at the plant gate posing as an employee of a known supplier or a delivery driver, hi-vis vest, clipboard, and a plausible delivery in hand.

02

The entry

At a busy turnstile or a side door into the engineering wing, it's often enough to slip in right behind a badged employee. Tailgating works especially well wherever a lot of people are moving in and out at once.

03

Proximity to the prototype

Once inside the R&D area, it becomes clear whether covers, access zones, and camera coverage actually stop an unauthorized person from getting within sight of a camouflaged test vehicle unnoticed.

Every step is controlled and agreed in advance, including a designated contact who gets notified immediately if anything unexpected happens.
The automotive supplier attack surface

Where attackers actually get in at suppliers

Three areas come up again and again when we assess plant sites and networks at automotive suppliers.

R&D & prototype areas

CAD data, test vehicles, and concept documents sit close together here, often with more internal foot traffic than is visible from outside.

Production networks

Manufacturing lines and control systems frequently run alongside standard IT, over legacy connections nobody had on their radar by the time of the last network redesign.

Supply chain: Tier-2 & Tier-3 suppliers

Smaller suppliers are increasingly targeted, precisely because they're seen as an easier way into the larger OEMs' ecosystem.

For the compliance depth

VDA ISA mapping and Assessment Levels live on our TISAX page

This page stays deliberately lean. For the full VDA ISA mapping, the Assessment Level details (AL1 through AL3), and preparation for your TISAX certification audit: our in-depth TISAX page.

Go to the TISAX page
What can happen

Continental: ransomware hits Tier-1 suppliers too

Continental AG · 2022

In 2022, Continental, one of the largest Tier-1 suppliers in the German automotive industry, was, according to media reports, targeted by the LockBit ransomware group. The case shows that even established, well-secured suppliers aren't immune to ransomware, regardless of size or TISAX maturity.

Based on public reporting. accessgranted was not involved in this incident.

Related modules

These tests round out your TISAX assessment

For the physical and network side of your security evidence, this combination has proven itself with automotive suppliers.

Physical Pentest

Simulated access to plant sites, engineering wings, and prototype areas, exactly the part your site walkthrough is looking for.

Learn more

OT/ICS Pentest

Security testing of manufacturing lines and control systems, without putting ongoing production at risk.

Learn more

Infrastructure Pentest

Network segmentation between R&D, production, and administration, including access rights and remote maintenance access.

Learn more

Automotive & prototype protection: your questions

Our TISAX page covers the full topic: VDA ISA controls, Assessment Levels AL1 through AL3, TISAX labels, and the comparison to ISO 27001. This page deliberately zooms in on one slice of that, physical access to plant sites and prototype areas, because it's often the least-tested part.
Prototype protection is its own TISAX assessment module for protecting test vehicles and parts from unauthorized viewing: covers, camouflage, secure storage, transport, and access control for the relevant areas. You'll find the details and the associated labels on our TISAX page.
Yes. Smaller suppliers are increasingly a target precisely because they're often seen as an easier way into a larger OEM's supply chain. We scale scope and depth to your company size and Assessment Level.
It depends on the number and size of your sites, and whether social engineering should be included as preparation. After a free initial consultation we know your scope and you get a transparent fixed-price quote.
The physical core, the simulated access attempt itself, yes, that can't be done remotely. Preparation, scoping, and the debrief run as usual over video call, so on-site time stays limited to the actual test.