Insights · Audit defense · Issue I, MMXXVI.

Manufacturing, audited across OT and IT.

Manufacturing Red Hat audit considerations. Operational technology and information technology separation, ISA-95 boundaries, MES, SCADA, embedded RHEL, and the audit posture each shapes.
By The Buyer-Side Desk, an independent advisory practice. 190+ engagements, $180M+ recovered. Published
Abstract

Manufacturing Red Hat audits run across two structurally different domains. The information technology side looks like a standard commercial audit. The operational technology side is governed by ISA-95 boundary discipline, plant safety constraints, and embedded RHEL footprint that audit teams rarely model correctly. This note treats the manufacturing Red Hat audit, the OT and IT separation that anchors the response, and the posture that consistently produces materially lower settlements than the initial finding.

§ 1

The OT and IT separation.

A manufacturing Red Hat audit begins with the same compliance notice that lands at any other enterprise customer. What sits underneath the notice is a structurally bifurcated estate. The information technology side, including corporate functions, ERP, and general datacenter, looks like a standard commercial enterprise. The operational technology side, including manufacturing execution systems, supervisory control and data acquisition, distributed control systems, and embedded RHEL on production line equipment, looks nothing like a commercial enterprise. The ISA-95 enterprise control system reference model describes the boundary that separates the two; mature manufacturers maintain the boundary as a network and operational discipline. Red Hat audit teams who treat the manufacturing estate as a single commercial estate produce findings that ignore the boundary and overstate the OT exposure substantially.1

The practice's reading across manufacturing defenses is consistent: separating OT from IT in the first reply changes the audit shape. The IT side is treated as a standard commercial audit; the OT side is treated under the plant safety and operational continuity constraints that govern its day to day operation. In manufacturing Red Hat audits the ISA-95 boundary is the customer's structural leverage; surfacing it early prevents the audit team from setting expectations the boundary will later refuse. Customers who do not surface the boundary frequently find that the audit team has anchored on IT evidence expectations and applied them to OT environments where the expectations do not fit.

The companion overview on regulated industries Red Hat audits treats the broader pattern; the present note treats the manufacturing specific application. The parent practice note on RHEL licensing treats the product side.

§ 2

ISA-95 boundaries in practice.

The ISA-95 reference model defines five levels of enterprise control: level zero (sensors and actuators), level one (sensing and manipulation), level two (control), level three (manufacturing operations management), and level four (business planning). Mature manufacturers treat the level three to level four boundary as a strong segmentation; the OT environment lives at levels zero through three, the IT environment lives at level four. The Red Hat audit team's interest in OT is typically in finding entitlement gaps at levels two and three, where MES and SCADA workloads run RHEL at scale.

The defended response treats the OT environment as a separate audit scope with its own entitlement basis. The basis frequently relies on the RHEL standard tier with extended update support, or on RHEL for Edge image mode, or on embedded subscriptions that ship with OT equipment from automation vendors. The audit team's opening position frequently overlooks the embedded subscriptions and counts the equipment as if it required a separate entitlement. The defended response surfaces the embedded subscription and shows the audit team that the equipment is already entitled by the OEM.

Fig. 2.1 · Manufacturing estate by ISA-95 levelRHLA · 2026 Q2
LevelWorkload classAudit posture
Level 4 (IT)ERP, datacenter, corporateStandard commercial audit
Level 3 (MOM)MES, historianPlant safety constrained
Level 2 (control)SCADA, DCS HMIOEM embedded entitlement
Levels 0 and 1PLC, sensor, actuatorOut of scope for RHEL audit
Manufacturing estates separate cleanly by ISA-95 level. Level 4 is a commercial audit; level 3 is constrained by plant safety; level 2 frequently runs under OEM embedded entitlements; levels 0 and 1 are typically below the Red Hat audit's relevance. The defended response treats each level on its own terms.

§ 3

MES, SCADA, and plant safety.

MES workloads at ISA-95 level three frequently run on RHEL at scale, with high availability clusters supporting line side execution. SCADA at level two runs on a mix of RHEL and proprietary platforms. Both fall under plant safety constraints that govern when and how changes may be made to production equipment, and that constrain what evidence may be exposed to external parties. The audit team's evidence request that asks for live inventory data on MES or SCADA workloads is asking for evidence that may require a plant safety review before disclosure. The defended response surfaces the plant safety constraint and substitutes attested totals from a plant operations officer in place of live data exports.

Real time kernel workloads on the plant floor frequently require the RHEL real time kernel subscription, which has its own entitlement model. The audit team frequently mishandles the real time subscription by counting it twice (once as base RHEL, once as real time). The cross link into Lane 10 on RHEL real time kernel licensing is relevant; the practice's reading is that the real time subscription includes the base RHEL entitlement and that the audit team's double count is consistently incorrect.

"The audit team had counted every PLC supervisor as if it required a full RHEL subscription. We showed them the OEM embedded entitlements that shipped with the equipment, and three quarters of the finding disappeared in one meeting."
Testimony of record. Director of Manufacturing IT, global automotive manufacturer.
§ 4

Embedded RHEL and OEM entitlements.

Manufacturing equipment from major automation vendors frequently ships with embedded RHEL subscriptions that are bundled into the equipment's commercial price. The embedded entitlement is part of the OEM relationship, not the customer's enterprise agreement with Red Hat. Audit teams who do not understand the OEM channel frequently count the embedded equipment as if it required a separate customer entitlement, producing findings that double count the deployment. The defended response surfaces the OEM channel and documents the embedded entitlements with reference to OEM purchase orders and equipment specifications.

The companion note on Red Hat reseller versus direct in Lane 2 treats the related question of how channel relationships affect contract structure. The cross link into Lane 10 on RHEL for edge and embedded licensing is relevant when the manufacturer has adopted RHEL image mode or RHEL for Edge for its own embedded workloads; the entitlement model differs from base RHEL.

§ 5

NERC CIP and process safety standards.

Manufacturers in energy adjacent sectors (oil and gas, chemicals, pharmaceuticals) frequently fall under NERC CIP for any electric system assets they own, OSHA process safety management, and CFATS chemical facility anti terrorism standards. Each framework restricts evidence sharing about plant operations. The Red Hat audit team's evidence request that touches plant operations crosses one or more of these frameworks. The defended response surfaces the applicable framework and constrains the evidence exchange accordingly. The companion note on regulated industries Red Hat audits treats the energy framework in adjacent context.

Pharmaceutical manufacturers face additional FDA scrutiny on validated systems. Red Hat workloads supporting validated manufacturing processes (typically MES and historian) cannot be subjected to evidence collection protocols that interfere with validated state. The defended response treats validated systems as a separate scope with documented validation evidence in place of standard audit evidence.

§ 6

How the practice approaches manufacturing audits.

The practice begins manufacturing Red Hat audit engagement by mapping the estate against ISA-95 levels and identifying which workloads fall under plant safety, validated process, or OEM embedded entitlement. The map separates the audit into the IT scope (commercial) and the OT scope (framework constrained). The split frequently produces a finding that is materially smaller than the audit team's opening position because the audit team's position typically aggregates the two and applies IT evidence expectations to OT environments.

Manufacturing settlements in the practice's trailing twelve months consistently closed at lower percentages of the initial Red Hat finding than the commercial benchmark, despite the very large embedded RHEL footprint that frequently produces large initial findings. If the audit notice is in hand and the customer is a manufacturer, the first useful hour is a call with the desk. The companion notes on retail, telecom, and regulated industries Red Hat audit considerations treat comparable patterns in adjacent sectors.

Notes & references

  1. 1. ISA-95 boundary. The ISA-95 enterprise control system reference model defines five levels of enterprise control. The level three to four boundary separates OT from IT and shapes manufacturing audit posture.
  2. 2. OEM embedded entitlements. Manufacturing equipment from major automation vendors frequently ships with embedded RHEL subscriptions. The embedded entitlement is part of the OEM relationship, not the customer's enterprise agreement.
  3. 3. Plant safety constraint. MES and SCADA workloads fall under plant safety constraints that govern when and how changes may be made. Live evidence exports may require plant safety review.
  4. 4. Real time kernel. RHEL real time kernel subscriptions include the base RHEL entitlement. Audit teams frequently double count; the defended response separates the components.
  5. 5. Industry overlays. Energy adjacent manufacturers face NERC CIP, OSHA PSM, and CFATS overlays; pharmaceutical manufacturers face FDA validated system rules. Each overlay constrains evidence collection.

Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.

§ 7 · Engagement

Engage before the audit team aggregates OT into IT.

Two analyst calls. No fee. We tell you what we would do, what the leverage actually is, and whether we are the right firm. If the audit notice is in hand, the first call happens within twenty four hours.