Current Status Pre-Certification Period

TPSA v1.0 was published in April 2026. Formal certification by accredited bodies is expected from H2 2027 onwards. In the meantime, suppliers may adopt TPSA in self-declaration mode clearly marked as "TPSA Self-Declared Not Independently Certified". Self-declared suppliers will benefit from an expedited initial audit when formal certification becomes available.

Choose Your Level

Level 1

TPSA Basic

For SME suppliers and non-critical providers. Foundational transparency through a conformant Disclosure Card.

  • Complete Disclosure Card all 7 domains, all mandatory fields
  • Annual review cycle
  • Common Disclosure only (no Client-Specific Annexes required)
  • No Risk Dialogue Protocol requirement

Level 3

TPSA Full

For critical ICT providers to DORA-regulated entities and major cloud/infrastructure providers.

  • All fields including recommended optional
  • Continuous update cycle (15-day max)
  • TIBER-EU Coordination Messages supported
  • RSC acknowledgement ≤5 business days; SRA ≤15 days
  • Classification Uplift mechanism demonstrated
  • All baseline KRIs published
  • Auditor countersignature at surveillance

Four-Phase Certification Process

1

Application & Scoping

Submit application to an accredited certification body. Specify target level, scope description, and any existing certifications (ISO 27001, SOC 2). CB issues a scoping proposal and indicative timeline.

2

Document Review

CB conducts a Stage 1 review of your Disclosure Cards, Risk Dialogue documentation (if applicable), and exchange logs. Any identified gaps are documented. Usually remote.

3

Substantive Audit

Stage 2: Disclosure Card content verified against primary source evidence (backup logs, pentest reports, access review records, incident history). Key personnel interviews. For Enhanced/Full: RSC/SRA exchanges reviewed.

4

Certification Decision

Decision by a committee independent of the audit team. Outcomes: Certified, Conditional (minor NCs corrected within 90 days), or Denied. Certificate valid for 3 years subject to surveillance.

Certification Roadmap

TimelineMilestone
Q2–Q3 2026 TPSA v1.0 published. Self-declaration mode available.
Q4 2026 Pilot programme launch (financial services, energy, public sector). Early adopter feedback incorporated.
H1 2027 TPSA v1.0 published. Auditor Training Programme launched. CB engagement: AFNOR, LSTI, BSI, Bureau Veritas.
H2 2027 First CB accreditations. Auditor training. Transition of self-declared suppliers to formal certification.
2028 First formally certified TPSA suppliers. Public register operational. Market scaling via DORA/NIS2 requirements.
2029+ TPSA-03 expansion (NIST CSF, APRA CPS 234). Continuous framework improvement. Non-European expansion.

Early Adopter Programme (2026–2027)

Selected suppliers across sizes, sectors, and geographies are invited to participate in the pilot programme. Pilot participants receive the "TPSA Early Adopter" designation and contribute to shaping the v1.0 standard before formal certification bodies become operational.

Contact to Express Interest →