ISO 27001 for manufacturers: when your customers start asking

6 min read · Updated

More manufacturers are finding a new line in their customers' supplier questionnaires: "Do you hold ISO 27001 or Cyber Essentials?" Large customers, especially in automotive, defence, energy, food and the public sector, are checking the security of their whole supply chain, because an attack on one supplier can stop their production line too. If you already hold ISO 9001, much of the management-system thinking will feel familiar.

Why customers ask

  • Shared drawings and specifications: your customers' designs and IP sit on your systems.
  • Connected supply chains: orders, schedules and EDI links mean your systems touch theirs.
  • Downtime spreads: ransomware at a supplier can halt a customer's line within days.
  • Contract terms: security requirements are increasingly written into supply agreements.

Start by checking exactly what your customer asked for. Cyber Essentials is often the minimum; ISO 27001 is for customers who want to see you manage information risk across the business. See Cyber Essentials vs ISO 27001.

What's different in a manufacturing business

Area What it means on a factory floor
Scope Office IT, design and drawing systems, ERP/MRP, and how far the shop floor is included
Operational technology Machines and controllers that can't be patched like a laptop need other protections
Shared accounts Shop-floor terminals and machine logins shared between shifts
Customer IP Drawings and specs: who can access them, how they're shared and kept
Suppliers Machine vendors with remote access, ERP providers, hauliers' systems
Continuity Keeping production going if ERP or the network is down
People Training for staff who don't sit at a desk all day

You may be closer than you think

If you hold ISO 9001, you already run document control, internal audits, management reviews and corrective actions. ISO 27001 uses the same high-level structure, so those habits carry over. The new parts are the information security risk assessment, the Statement of Applicability and the security controls themselves.

Common gaps

  • No list of information assets beyond the IT inventory.
  • Remote access for machine vendors that is always on and never reviewed.
  • Shared shop-floor logins with no way to tell who did what.
  • Backups never restore-tested, especially for ERP.
  • Drawings emailed to subcontractors without any control over where they end up.

How ClearIMS helps

ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there. Describe your business in plain English and it drafts your scope, risk register, Statement of Applicability, policies and tasks. A named person in your business approves every record; the AI never approves anything. Then it keeps the system running with owned, dated tasks for things like vendor access reviews and restore tests. Cyber Essentials and business continuity are included.

We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.

Take the 2-minute readiness check, or book a 20-minute call.

SOURCES

  1. ISO/IEC 27001:2022 (ISO)
  2. Supply chain security guidance (NCSC)
  3. About Cyber Essentials (NCSC)
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.