TPSA Framework Overview
Four interlocking documents from structured disclosure to bidirectional risk dialogue, regulatory proof, and independent certification.
Architecture
TPSA addresses a fundamental gap in third-party security governance: suppliers are assessed, but have no standard mechanism to respond. The framework provides that mechanism structured, bidirectional, and aligned to existing regulatory obligations.
The four documents form an integrated whole. TPSA-01 defines what to disclose; TPSA-02 defines how to dialogue about risk; TPSA-03 proves regulatory coverage; TPSA-04 ensures independent verification of conformance.
Two-Layer Disclosure Architecture
TPSA-01 introduces a two-layer model that balances transparency with confidentiality:
- Common Disclosure shared infrastructure controls, published for all clients. Covers the supplier's baseline security posture across all 7 domains.
- Client-Specific Annexes per-client overlays for dedicated assets, data classification overrides, and tailored SLAs. Confidential to the individual client relationship.
EBIOS RM Integration
TPSA-02 maps directly onto the five EBIOS Risk Manager workshops:
- WS1 (Scope) pre-populated from the Disclosure Card
- WS2 (Risk Sources) client submits SR/OV pairs via RSC Section A
- WS3–4 (Scenarios) client constructs MITRE ATT&CK scenarios mapped to supplier assets
- WS5 (Treatment) joint risk treatment plan from SRA response
TIBER-EU Integration
At TPSA Full level, the framework integrates directly with DORA Article 26 TLPT exercises. The Disclosure Card's structured asset register dramatically accelerates TIBER-EU scoping; RSCs already submitted provide input for test scenario design.
Framework Status
TPSA v1.0 is published as an open standard. Feedback from suppliers, clients, auditors, and regulators is welcome for future iterations of the framework.
Reference Implementation
A free, self-hosted reference platform (Rust/Actix, PostgreSQL) is planned for Q4 2026. Single compiled binary. Mutual ED25519 authentication. Not required for certification.
Forthcoming see roadmap
The Four Documents
Supplier Disclosure Standard
Defines the Disclosure Card a structured, machine-readable document that suppliers publish to communicate their security posture. Covers 7 domains with mandatory, conditional, and optional fields.
- D1 Asset Inventory & Data Mapping
- D2 Data Protection
- D3 Backup & Recovery
- D4 Access Control & Identity
- D5 Vulnerability Management
- D6 Incident Management & Notification
- D7 Compliance & Certification Status
Risk Dialogue Protocol
Specifies the bidirectional exchange mechanisms between clients and suppliers. Based on EBIOS RM and MITRE ATT&CK, with full TIBER-EU integration at the Full level.
- Risk Scenario Cards (RSC) client to supplier
- Supplier Risk Assessments (SRA) step-by-step response
- TIBER-EU Coordination Messages (TEC)
- Key Risk Indicator (KRI) exchange
- Defined timelines and escalation procedures
Regulatory Mapping Matrix
Field-by-field mapping of every TPSA requirement to four regulatory frameworks. Provides auditable traceability for clients demonstrating compliance and suppliers aligning to regulatory obligations.
- 41 CIS Controls v8 safeguards mapped
- 28 ISO 27001:2022 Annex A controls mapped
- 22 DORA article paragraphs mapped
- 7 NIS2 Art. 21 measures mapped
Labelling & Certification Scheme
Defines how conformance is assessed, by whom, and what the label means. Three maturity levels, four-phase audit process, 3-year validity with annual/semi-annual surveillance.
- TPSA Basic / Enhanced / Full levels
- ISO/IEC 17021-1 or 17065 accredited CBs
- Integration with existing ISO 27001 / SOC 2
- Public register maintained by governance body