Version 1.0 · April 2026

A New Standard for Third-Party Supplier Accountability

Supply chain attacks are rising. Existing frameworks evaluate suppliers but give them no standard way to respond. TPSA closes this gap with a bidirectional, structured accountability protocol for suppliers and their clients.

DORA Art. 28–30 aligned NIS2 Art. 21 aligned ISO 27001:2022 aligned CIS Controls v8 aligned EBIOS RM · MITRE ATT&CK · TIBER-EU

The Supply Chain Accountability Gap

Regulations require clients to assess their suppliers but give suppliers no standard way to demonstrate accountability.

12,000+
data breaches recorded in 2025
$4.44M
average breach cost per incident
+47%
increase in supply chain incidents (ENISA/CISA, 2025)
0
standardized supplier response protocols before TPSA

What existing frameworks do

CIS Controls v8, ISO 27001, DORA, and NIS2 all require organizations to assess their supply chain but exclusively from the client's perspective.

Suppliers are evaluated through questionnaires (SIG, CAIQ), audited periodically (SOC 2), or checked against certifications (ISO 27001) but no standard defines:

  • What a supplier must proactively disclose
  • How a client communicates its specific threat landscape
  • How a supplier responds to a concrete attack scenario
  • How this evidence feeds into TIBER-EU / TLPT exercises

What TPSA adds

The Missing Piece

TPSA is not another questionnaire. It is a bidirectional accountability protocol suppliers disclose structured, machine-readable security posture data; clients submit concrete threat scenarios; both parties maintain an auditable dialogue record aligned to EBIOS RM and MITRE ATT&CK.

TPSA provides suppliers with a competitive label that demonstrates structured accountability reducing questionnaire fatigue while producing richer, more verifiable evidence.

Four Interlocking Components

Each document addresses a distinct layer of the accountability gap, from disclosure to dialogue, regulatory proof, and independent verification.

TPSA-01
D

Supplier Disclosure Standard

A structured, machine-readable Disclosure Card covering 7 mandatory domains: asset inventory, data protection, backup & recovery, access control, vulnerability management, incident management, and compliance status.

Read Standard →
TPSA-02
R

Risk Dialogue Protocol

A bidirectional exchange protocol. Clients submit Risk Scenario Cards (RSC) using EBIOS RM and MITRE ATT&CK. Suppliers respond with Supplier Risk Assessments (SRA) detailing their defensive posture step-by-step.

Read Protocol →
TPSA-03
M

Regulatory Mapping Matrix

Every TPSA requirement mapped field-by-field to CIS Controls v8, ISO 27001:2022, DORA (Art. 28–30, 26, 19), and NIS2 (Art. 21). Auditable traceability for clients and suppliers alike.

View Mapping →
TPSA-04
C

Labelling & Certification Scheme

Three maturity levels Basic, Enhanced, Full audited by accredited third-party certification bodies. Designed to integrate with existing ISO 27001 and SOC 2 scopes to reduce audit duplication.

View Scheme →

Three Maturity Levels

Proportionate to supplier size, criticality, and regulatory context.

Level 1

TPSA Basic

Foundational transparency. Conformant Disclosure Card, annual review.

  • Complete Disclosure Card all 7 domains
  • All mandatory fields populated
  • Annual review cycle
  • Common Disclosure only

Level 3

TPSA Full

Complete accountability. TIBER-EU integration. Continuous maintenance.

  • All fields including optional
  • Continuous update cycle (15 days)
  • TIBER-EU Coordination Messages
  • Response within 5/15 business days
  • Classification Uplift mechanism
  • Auditor countersignature required

Designed for the European Regulatory Context

Every TPSA requirement is mapped to the major frameworks applicable to supply chain security.

DORA Art. 28–30 Third-Party Risk DORA Art. 26 TIBER-EU / TLPT DORA Art. 19 Incident Notification NIS2 Art. 21 Security Measures ISO 27001:2022 A.5.19–A.5.23 CIS Controls v8 Safeguard 15 EBIOS Risk Manager (ANSSI) MITRE ATT&CK Enterprise & ICS

Complementary, not competitive

TPSA does not replace ISO 27001, SOC 2, or DORA compliance. It fills the specific gap none of them cover: a standardized format for suppliers to demonstrate accountability to their clients, with structured bidirectional risk dialogue and auditable evidence chains.

From Standard Publication to Market Certification

1

Q2–Q3 2026

TPSA v1.0 Publication

All four framework documents published. Reference Platform v1.0.

2

Q4 2026

v1.0 Pilots & Adoption

Pilot programme launch in financial services, energy, and public sector. Early adopter feedback incorporated.

3

H1 2027

v1.0 & CB Engagement

TPSA v1.0 published. Auditor Training Programme. CB engagement: AFNOR, LSTI, BSI, Bureau Veritas.

4

2027–2028

First Certified Suppliers

First CB accreditations. First formally certified TPSA suppliers. Public register operational.

Early Adoption Self-Declaration Mode

Suppliers may adopt TPSA now in self-declaration mode, clearly marked as "TPSA Self-Declared Not Independently Certified". When accredited certification bodies become operational, self-declared suppliers will benefit from an expedited initial audit process.

Contribute to the TPSA Community

TPSA is published for community review. Read the documents, test the framework against your context, and contribute feedback to shape v1.0.