Architecture

TPSA addresses a fundamental gap in third-party security governance: suppliers are assessed, but have no standard mechanism to respond. The framework provides that mechanism structured, bidirectional, and aligned to existing regulatory obligations.

The four documents form an integrated whole. TPSA-01 defines what to disclose; TPSA-02 defines how to dialogue about risk; TPSA-03 proves regulatory coverage; TPSA-04 ensures independent verification of conformance.

Two-Layer Disclosure Architecture

TPSA-01 introduces a two-layer model that balances transparency with confidentiality:

  • Common Disclosure shared infrastructure controls, published for all clients. Covers the supplier's baseline security posture across all 7 domains.
  • Client-Specific Annexes per-client overlays for dedicated assets, data classification overrides, and tailored SLAs. Confidential to the individual client relationship.

EBIOS RM Integration

TPSA-02 maps directly onto the five EBIOS Risk Manager workshops:

  • WS1 (Scope) pre-populated from the Disclosure Card
  • WS2 (Risk Sources) client submits SR/OV pairs via RSC Section A
  • WS3–4 (Scenarios) client constructs MITRE ATT&CK scenarios mapped to supplier assets
  • WS5 (Treatment) joint risk treatment plan from SRA response

TIBER-EU Integration

At TPSA Full level, the framework integrates directly with DORA Article 26 TLPT exercises. The Disclosure Card's structured asset register dramatically accelerates TIBER-EU scoping; RSCs already submitted provide input for test scenario design.

Framework Status

TPSA v1.0 is published as an open standard. Feedback from suppliers, clients, auditors, and regulators is welcome for future iterations of the framework.

Reference Implementation

A free, self-hosted reference platform (Rust/Actix, PostgreSQL) is planned for Q4 2026. Single compiled binary. Mutual ED25519 authentication. Not required for certification.

Forthcoming see roadmap

The Four Documents

TPSA-01

Supplier Disclosure Standard

Defines the Disclosure Card a structured, machine-readable document that suppliers publish to communicate their security posture. Covers 7 domains with mandatory, conditional, and optional fields.

  • D1 Asset Inventory & Data Mapping
  • D2 Data Protection
  • D3 Backup & Recovery
  • D4 Access Control & Identity
  • D5 Vulnerability Management
  • D6 Incident Management & Notification
  • D7 Compliance & Certification Status
Read TPSA-01 →
TPSA-02

Risk Dialogue Protocol

Specifies the bidirectional exchange mechanisms between clients and suppliers. Based on EBIOS RM and MITRE ATT&CK, with full TIBER-EU integration at the Full level.

  • Risk Scenario Cards (RSC) client to supplier
  • Supplier Risk Assessments (SRA) step-by-step response
  • TIBER-EU Coordination Messages (TEC)
  • Key Risk Indicator (KRI) exchange
  • Defined timelines and escalation procedures
Read TPSA-02 →
TPSA-03

Regulatory Mapping Matrix

Field-by-field mapping of every TPSA requirement to four regulatory frameworks. Provides auditable traceability for clients demonstrating compliance and suppliers aligning to regulatory obligations.

  • 41 CIS Controls v8 safeguards mapped
  • 28 ISO 27001:2022 Annex A controls mapped
  • 22 DORA article paragraphs mapped
  • 7 NIS2 Art. 21 measures mapped
View TPSA-03 →
TPSA-04

Labelling & Certification Scheme

Defines how conformance is assessed, by whom, and what the label means. Three maturity levels, four-phase audit process, 3-year validity with annual/semi-annual surveillance.

  • TPSA Basic / Enhanced / Full levels
  • ISO/IEC 17021-1 or 17065 accredited CBs
  • Integration with existing ISO 27001 / SOC 2
  • Public register maintained by governance body
Read TPSA-04 →