Companies arriving from consumer or enterprise are surprised by three things: the sourcing cycle is measured in years, the decision is often made at the Tier 1 rather than the OEM, and the conversation is conducted in a language — ISO 26262, ASPICE, deterministic networking, PPAP — that they do not yet speak.
The calendar nobody warned you about
A vehicle program is planned three to five years before start of production. The electronics architecture is set early in that window. Suppliers for each module are selected, qualified, and locked well before the first prototype vehicle is built, and once locked they are very hard to displace — a change means re-validation of everything that touches the part. So a component that is "ready" today is competing for a slot in vehicles that will ship around the end of the decade, and the decision on that slot may already have been made.
This is why a technically superior part so often loses. The winner was in the room two years earlier, with a roadmap that aligned with the OEM's platform plan and a process story the Tier 1 could take to its own quality organization without embarrassment.
Who actually decides
The OEM's name is on the car, but the module — the ECU, the gateway, the camera, the domain controller — is usually built by a Tier 1, and the Tier 1 chooses the silicon and the software inside it. The OEM may specify requirements, may express a preference, may even mandate a supplier for strategic parts. But for most components the Tier 1 owns the bill of materials, carries the warranty risk, and makes the call. Selling to the OEM without a Tier 1 relationship is selling to someone who cannot sign the purchase order.
The practical consequence: you need two parallel conversations, and the Tier 1 conversation is about risk. Can your part be qualified? Will your company exist in seven years? Is your process evidence good enough that the Tier 1's auditor will not flag it? Will you support the part for the fifteen-year life of the platform?
Learn the language before you need it
ISO 26262 is functional safety: the discipline of showing that the system cannot cause harm when it fails, and that it fails in known ways. ASPICE is process capability: evidence that your software organization can be trusted to build and maintain automotive software repeatably. Deterministic networking — time-sensitive Ethernet, CAN scheduling — is how the vehicle guarantees the brake message arrives on time. PPAP is the production part approval process that says your manufacturing is under control. None of these are optional, and none can be bolted on at the end.
The winners learn the language early and treat it as product design rather than compliance. They show up with the safety concept, the process evidence, and the platform alignment already in hand, on the OEM's timeline rather than their own. Do that, and the OEM roadmap becomes your roadmap. Skip it, and the best technology in the room loses to the one that was qualified.
Functional safety is not paperwork. It is how the customer decides whether to trust you with a brake.
What an entry plan looks like
Start with the platforms, not the products: identify which vehicle programs are being architected now and which Tier 1s hold the relevant modules. Get an assessor-grade gap analysis against ISO 26262 and ASPICE before the first serious meeting, because the Tier 1 will do one anyway. Build the safety concept into the architecture of the part rather than documenting it afterward. Assign an executive owner to the automotive channel who understands that "no decision this year" is the normal state of affairs and not a signal to give up. And expect the first design win to take two years and the second to take six months — because once one Tier 1 has qualified you, the others know it can be done.
Red Tomatoes Enterprises · Published · Updated