Open Standard

TPSA v1.0 is published as an open standard. The documents below represent the current state of the framework. Feedback and contributions are welcome. See the About page for guidance.

PP

TPSA Position Paper

The problem statement, framework architecture, strategic positioning, and implementation roadmap. Start here.

Version 1.0 · April 2026 PDF
01

TPSA-01 Supplier Disclosure Standard

Defines the Disclosure Card: 7 domains, header fields, JSON schema, classification uplift, card lifecycle, and maturity requirements.

Version 1.0 · April 2026 PDF
02

TPSA-02 Risk Dialogue Protocol

Risk Scenario Cards, Supplier Risk Assessments, TIBER-EU coordination messages, KRI exchanges, timelines, and escalation procedures.

Version 1.0 · April 2026 PDF
03

TPSA-03 Regulatory Mapping Matrix

Field-by-field mapping to CIS Controls v8, ISO 27001:2022, DORA (Art. 28–30, 26, 19), and NIS2 (Art. 21).

Version 1.0 · April 2026 PDF
Download
04

TPSA-04 Labelling & Certification Scheme

Three maturity levels, audit process, certification lifecycle, non-conformity classification, CB requirements

Version 1.0 · April 2026 PDF
Download
WS

TPSA Worksheet EN

This worksheet is the operational tool for TPSA implementation and audit preparation.

Version 1.0 · April 2026 XLSX
Download

Coming Soon

The following resources are planned for release alongside TPSA v1.0:

  • TPSA-01 JSON Schema (tpsa-01-schema.json)
  • Disclosure Card template Common Disclosure (JSON)
  • Disclosure Card template Client-Specific Annex (JSON)
  • Auditor Training Programme materials