Supplier questionnaires from primes
Automotive, aerospace and FMCG primes increasingly require Cyber Essentials from suppliers. Questionnaires often arrive at short notice, before contract renewal.
Manufacturing has become one of the most attacked sectors in the UK, and the risk does not stay where the breach happens. When attackers halted Jaguar Land Rover production for around five weeks in late 2025, the Cyber Monitoring Centre put the most likely cost at £1.9bn spread across roughly 5,000 organisations, most of them suppliers who suffered no intrusion of their own. For a supplier on thin margins, five weeks without orders is a financing problem long before it is a security one.
The wider picture matches. Survey findings from Make UK, the manufacturers organisation, show that 30% of UK manufacturers experienced a cyber incident in the past 12 months, directly or through their supply chain, while only 51% hold a formal cyber security incident response plan. Among firms reporting incidents, roughly a third suffered reduced production capacity or delayed customer deliveries, and nearly a quarter experienced component shortages caused by an attack somewhere upstream.
The consequence for suppliers is practical rather than abstract: primes that have just absorbed the cost of supplier fragility are tightening their assurance requirements. Supplier questionnaires increasingly ask for Cyber Essentials certification as a baseline, and firms that cannot evidence their controls risk losing their place on approved lists at renewal.
Forensic Control works with manufacturers to get ahead of that conversation: certification to the level primes specify, evidence packs their procurement teams can accept without argument, and an incident response capability for when something does go wrong.
For most manufacturing suppliers, Cyber Essentials is the certification supplier questionnaires name, and Cyber Essentials Plus is the level that ends the conversation. The independent technical audit, with an assessor testing a sample of your devices and running vulnerability scanning against your systems, produces evidence a prime procurement or insurance team can accept without argument. Self-assessed answers, taken on trust, increasingly cannot.
Forensic Control is an authorised IASME Certification Body, not a reseller. We have been delivering Cyber Essentials since 2017, and we work with manufacturers to certify on the timeline the contract allows:
The five Cyber Essentials controls map closely onto the entry routes used in the attacks now hitting the sector. Certification is not just a procurement checkbox: it closes the doors most attacks actually walk through.
A typical engagement, from the questionnaire arriving to a renewal-ready evidence pack. We work to your contract timeline.
“Most of the Jaguar Land Rover bill did not sit on JLR's own balance sheet. It spread through suppliers who suffered no attack on their own systems, only a customer that could not build cars. The firms that come through that kind of event are the ones that could evidence their controls before anyone asked.”
Whether a security questionnaire has just arrived, a contract renewal is approaching, or you want to close the incident response gap before anyone asks, we can help. Book a short call to talk through where you are and what you need.