What is TPSA?

TPSA Third-Party Supplier Accountability is an open standard that closes a specific gap in the supply chain security landscape: the absence of a standardized, bidirectional accountability protocol between suppliers and their clients.

While DORA, NIS2, ISO 27001, and CIS Controls all require organizations to manage their supply chain risk, they do so exclusively from the client's perspective. Suppliers are assessed, audited, and queried but have no standard way to proactively demonstrate their security posture, engage in structured risk dialogue, or provide auditable evidence aligned to multiple frameworks simultaneously.

TPSA provides suppliers with that mechanism and gives clients richer, more verifiable evidence than any questionnaire can produce.

Why Now?

The regulatory environment has changed fundamentally. DORA (effective January 2025) and NIS2 impose specific third-party risk management obligations on thousands of entities across the EU. They create demand for supplier accountability that existing tools SOC 2, SIG/CAIQ, ISO 27001 are not designed to satisfy.

TPSA is designed to be the operational layer that enables both clients and suppliers to meet these obligations with documented, auditable, and structured evidence.

Sébastien Poitrasson

CISSP · ISO 27001 Lead Implementer · CIS Supporter

Arthur Koenig

Founder of Arthur Koenig and senior cybersecurity consultant. Expertise in GRC, regulatory compliance (DORA, NIS2), and offensive security. Editor of K_HIVE, a sovereign operational governance platform. TPSA was created to address a methodological gap observed across multiple client engagements.

Arthur Koenig

Cybersecurity consulting firm specializing in GRC, and editor of the software suite K_HIVE.

Visit arthurkoenig.fr →

TPSA Logo

TPSA Logo To Be Created

The official TPSA logo is forthcoming. Once available, it will be displayed here and made available for certified suppliers to use according to the label usage rules defined in TPSA-04.

Framework Status

TPSA v1.0 was published in April 2026. It represents a complete, internally consistent framework, open for feedback and continuous improvement.

The framework is published free of charge. No fees are required to adopt it. Certification costs when formal certification becomes available are paid to independent accredited certification bodies, not to the standard author.

How to Contribute

Feedback on any aspect of the framework is welcome technical accuracy, practical applicability, regulatory alignment, implementation feasibility, or gaps not yet addressed.

Priority feedback areas for v1.0:

  • Applicability to specific sectors (financial services, energy, healthcare, public sector)
  • Proportionality of the Enhanced and Full levels for SME suppliers
  • TIBER-EU coordination message format and process
  • JSON schema completeness and machine-readability requirements
  • Non-EU regulatory framework mappings (NIST CSF, APRA CPS 234)

TPSA vs. Existing Frameworks

TPSA is not a replacement for existing tools it fills a specific gap none of them cover.

Existing Tool What It Does What TPSA Adds
CIS Controls v8 Tells the client what to do about supplier risk (Safeguard 15) Tells the supplier how to demonstrate accountability in a standardized format
ISO 27001:2022 Requires supplier security policies and monitoring Provides the operational protocol and format for that monitoring
SOC 2 Periodic, confidential audit of supplier controls Continuous, transparent, client-oriented disclosure with bidirectional risk dialogue
SIG / CAIQ Standardized questionnaires for supplier assessment Standardized disclosures initiated by the supplier, plus ongoing risk dialogue mechanism
DORA / NIS2 Regulatory obligations on third-party risk management Operational framework to satisfy those obligations with documented, auditable evidence