Get Certified TPSA Label
Three maturity levels, proportionate to supplier size and criticality. Independent third-party audits by accredited certification bodies. 3-year validity with ongoing surveillance.
Current Status Pre-Certification Period
TPSA v1.0 was published in April 2026. Formal certification by accredited bodies is expected from H2 2027 onwards. In the meantime, suppliers may adopt TPSA in self-declaration mode clearly marked as "TPSA Self-Declared Not Independently Certified". Self-declared suppliers will benefit from an expedited initial audit when formal certification becomes available.
Choose Your Level
Level 1
TPSA Basic
For SME suppliers and non-critical providers. Foundational transparency through a conformant Disclosure Card.
- Complete Disclosure Card all 7 domains, all mandatory fields
- Annual review cycle
- Common Disclosure only (no Client-Specific Annexes required)
- No Risk Dialogue Protocol requirement
Level 2 Recommended
TPSA Enhanced
For SaaS providers, MSPs, and mid-tier suppliers serving regulated clients (DORA, NIS2).
- Full Disclosure Card all mandatory + conditional fields
- Client-Specific Annexes supported
- Semi-annual + event-driven (30-day) updates
- Risk Dialogue Protocol operational
- RSC acknowledgement ≤10 business days; SRA ≤30 business days
- Exchange log maintained
- 5+ baseline KRIs published
Level 3
TPSA Full
For critical ICT providers to DORA-regulated entities and major cloud/infrastructure providers.
- All fields including recommended optional
- Continuous update cycle (15-day max)
- TIBER-EU Coordination Messages supported
- RSC acknowledgement ≤5 business days; SRA ≤15 days
- Classification Uplift mechanism demonstrated
- All baseline KRIs published
- Auditor countersignature at surveillance
Four-Phase Certification Process
Application & Scoping
Submit application to an accredited certification body. Specify target level, scope description, and any existing certifications (ISO 27001, SOC 2). CB issues a scoping proposal and indicative timeline.
Document Review
CB conducts a Stage 1 review of your Disclosure Cards, Risk Dialogue documentation (if applicable), and exchange logs. Any identified gaps are documented. Usually remote.
Substantive Audit
Stage 2: Disclosure Card content verified against primary source evidence (backup logs, pentest reports, access review records, incident history). Key personnel interviews. For Enhanced/Full: RSC/SRA exchanges reviewed.
Certification Decision
Decision by a committee independent of the audit team. Outcomes: Certified, Conditional (minor NCs corrected within 90 days), or Denied. Certificate valid for 3 years subject to surveillance.
Certification Roadmap
| Timeline | Milestone |
|---|---|
| Q2–Q3 2026 | TPSA v1.0 published. Self-declaration mode available. |
| Q4 2026 | Pilot programme launch (financial services, energy, public sector). Early adopter feedback incorporated. |
| H1 2027 | TPSA v1.0 published. Auditor Training Programme launched. CB engagement: AFNOR, LSTI, BSI, Bureau Veritas. |
| H2 2027 | First CB accreditations. Auditor training. Transition of self-declared suppliers to formal certification. |
| 2028 | First formally certified TPSA suppliers. Public register operational. Market scaling via DORA/NIS2 requirements. |
| 2029+ | TPSA-03 expansion (NIST CSF, APRA CPS 234). Continuous framework improvement. Non-European expansion. |
Early Adopter Programme (2026–2027)
Selected suppliers across sizes, sectors, and geographies are invited to participate in the pilot programme. Pilot participants receive the "TPSA Early Adopter" designation and contribute to shaping the v1.0 standard before formal certification bodies become operational.