Composite: a manufacturer answering customer security schedules
How a bid activity staffed by operations people becomes a repeatable answer drawn from one evidence base.
The starting position
A tier-two supplier into automotive and aerospace, two plants, an engineering function that is the commercial crown jewels, and a quality team that had absorbed security questionnaires because nobody else would.
Every large customer arrived with its own security schedule, its own questionnaire and its own deadline. Answering them was a bid activity, staffed by people hired to run operations.
What the real cost was
Not the controls. Most were in place in some form. The cost was that each customer asked for the same assurance in a different shape, and each answer was rebuilt from scratch by people whose day job was elsewhere.
The second cost was slower and less visible: security response time was extending commercial cycles, and nobody was measuring that.
The change
One control set, implemented and evidenced once, mapped to every schedule that asks for it. IEC 62443 for the plant, NIST SP 800-171 and CMMC for defence-adjacent work, ISO 27001 as commercial currency, and each customer schedule mapped onto that rather than answered independently.
Adding a new customer schedule becomes a gap analysis against what already exists, which is a very different exercise from a bespoke project.
Where it got difficult
Evidence freshness, not coverage. Controls existed; showing that they had operated continuously did not. That is a systems problem rather than a security one, and it is the part that takes longest to fix.
The plant side also needed care. Asset evidence for the operational estate had to be produced without introducing anything into the process, which meant passive collection rather than the scanning approach the IT team was used to.
What changed commercially
The security response stopped being a bottleneck in the bid. That is the outcome the business cared about, and it is worth stating plainly because it is rarely how security programmes are justified.
The secondary effect was on the engineering IP question: once you can see where process knowledge actually goes across the supplier base, the conversation about protecting it becomes concrete.
Questions, answered
Is this just certification?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.