Framework Documents
All TPSA documents are freely available for download. Published under open review feedback and contributions are welcome.
Open Standard
TPSA v1.0 is published as an open standard. The documents below represent the current state of the framework. Feedback and contributions are welcome. See the About page for guidance.
TPSA Position Paper
The problem statement, framework architecture, strategic positioning, and implementation roadmap. Start here.
TPSA-01 Supplier Disclosure Standard
Defines the Disclosure Card: 7 domains, header fields, JSON schema, classification uplift, card lifecycle, and maturity requirements.
TPSA-02 Risk Dialogue Protocol
Risk Scenario Cards, Supplier Risk Assessments, TIBER-EU coordination messages, KRI exchanges, timelines, and escalation procedures.
TPSA-03 Regulatory Mapping Matrix
Field-by-field mapping to CIS Controls v8, ISO 27001:2022, DORA (Art. 28–30, 26, 19), and NIS2 (Art. 21).
TPSA-04 Labelling & Certification Scheme
Three maturity levels, audit process, certification lifecycle, non-conformity classification, CB requirements
TPSA Worksheet EN
This worksheet is the operational tool for TPSA implementation and audit preparation.
Coming Soon
The following resources are planned for release alongside TPSA v1.0:
- TPSA-01 JSON Schema (
tpsa-01-schema.json) - Disclosure Card template Common Disclosure (JSON)
- Disclosure Card template Client-Specific Annex (JSON)
- Auditor Training Programme materials