Version 1.0 · April 2026
A New Standard for Third-Party Supplier Accountability
Supply chain attacks are rising. Existing frameworks evaluate suppliers but give them no standard way to respond. TPSA closes this gap with a bidirectional, structured accountability protocol for suppliers and their clients.
The Supply Chain Accountability Gap
Regulations require clients to assess their suppliers but give suppliers no standard way to demonstrate accountability.
What existing frameworks do
CIS Controls v8, ISO 27001, DORA, and NIS2 all require organizations to assess their supply chain but exclusively from the client's perspective.
Suppliers are evaluated through questionnaires (SIG, CAIQ), audited periodically (SOC 2), or checked against certifications (ISO 27001) but no standard defines:
- What a supplier must proactively disclose
- How a client communicates its specific threat landscape
- How a supplier responds to a concrete attack scenario
- How this evidence feeds into TIBER-EU / TLPT exercises
What TPSA adds
The Missing Piece
TPSA is not another questionnaire. It is a bidirectional accountability protocol suppliers disclose structured, machine-readable security posture data; clients submit concrete threat scenarios; both parties maintain an auditable dialogue record aligned to EBIOS RM and MITRE ATT&CK.
TPSA provides suppliers with a competitive label that demonstrates structured accountability reducing questionnaire fatigue while producing richer, more verifiable evidence.
Four Interlocking Components
Each document addresses a distinct layer of the accountability gap, from disclosure to dialogue, regulatory proof, and independent verification.
Supplier Disclosure Standard
A structured, machine-readable Disclosure Card covering 7 mandatory domains: asset inventory, data protection, backup & recovery, access control, vulnerability management, incident management, and compliance status.
Read Standard →Risk Dialogue Protocol
A bidirectional exchange protocol. Clients submit Risk Scenario Cards (RSC) using EBIOS RM and MITRE ATT&CK. Suppliers respond with Supplier Risk Assessments (SRA) detailing their defensive posture step-by-step.
Read Protocol →Regulatory Mapping Matrix
Every TPSA requirement mapped field-by-field to CIS Controls v8, ISO 27001:2022, DORA (Art. 28–30, 26, 19), and NIS2 (Art. 21). Auditable traceability for clients and suppliers alike.
View Mapping →Labelling & Certification Scheme
Three maturity levels Basic, Enhanced, Full audited by accredited third-party certification bodies. Designed to integrate with existing ISO 27001 and SOC 2 scopes to reduce audit duplication.
View Scheme →Three Maturity Levels
Proportionate to supplier size, criticality, and regulatory context.
Level 1
TPSA Basic
Foundational transparency. Conformant Disclosure Card, annual review.
- Complete Disclosure Card all 7 domains
- All mandatory fields populated
- Annual review cycle
- Common Disclosure only
Level 2
TPSA Enhanced
Active accountability. Full Disclosure Card + operational Risk Dialogue Protocol.
- All mandatory + conditional fields
- Client-Specific Annexes supported
- Semi-annual review + event-driven (30 days)
- RSC/SRA exchanges operational
- Response within 10/30 business days
- KRI publication 5 baseline metrics
Level 3
TPSA Full
Complete accountability. TIBER-EU integration. Continuous maintenance.
- All fields including optional
- Continuous update cycle (15 days)
- TIBER-EU Coordination Messages
- Response within 5/15 business days
- Classification Uplift mechanism
- Auditor countersignature required
Designed for the European Regulatory Context
Every TPSA requirement is mapped to the major frameworks applicable to supply chain security.
Complementary, not competitive
TPSA does not replace ISO 27001, SOC 2, or DORA compliance. It fills the specific gap none of them cover: a standardized format for suppliers to demonstrate accountability to their clients, with structured bidirectional risk dialogue and auditable evidence chains.
From Standard Publication to Market Certification
Q2–Q3 2026
TPSA v1.0 Publication
All four framework documents published. Reference Platform v1.0.
Q4 2026
v1.0 Pilots & Adoption
Pilot programme launch in financial services, energy, and public sector. Early adopter feedback incorporated.
H1 2027
v1.0 & CB Engagement
TPSA v1.0 published. Auditor Training Programme. CB engagement: AFNOR, LSTI, BSI, Bureau Veritas.
2027–2028
First Certified Suppliers
First CB accreditations. First formally certified TPSA suppliers. Public register operational.
Early Adoption Self-Declaration Mode
Suppliers may adopt TPSA now in self-declaration mode, clearly marked as "TPSA Self-Declared Not Independently Certified". When accredited certification bodies become operational, self-declared suppliers will benefit from an expedited initial audit process.
Contribute to the TPSA Community
TPSA is published for community review. Read the documents, test the framework against your context, and contribute feedback to shape v1.0.