Coverage Summary
TPSA-03 serves two purposes: it gives clients auditable traceability from TPSA compliance to their regulatory obligations, and it demonstrates to suppliers that TPSA certification covers third-party transparency requirements across multiple frameworks simultaneously.
Important Interpretation
TPSA certification does not replace ISO 27001 or DORA compliance. It provides structured evidence facilitating a client's own compliance demonstration. Where mapping shows "partial" or "supports", the client and/or supplier must identify additional measures.
| Framework |
Third-Party Relevant Scope |
Directly Mapped |
Partially / Supporting |
| CIS Controls v8 |
Safeguard 15 (6 sub-controls) + related controls across 12 categories |
41 safeguards |
8 safeguards |
| ISO 27001:2022 |
A.5.19–A.5.23 (5 controls) + supporting controls |
28 Annex A controls |
12 controls |
| DORA |
Art. 28–30 + Art. 9, 10, 11, 12, 17, 19, 25, 26 |
22 article paragraphs |
9 article paragraphs |
| NIS2 |
Art. 21(2)(a)–(j) 10 risk management measures |
7 measures |
3 measures |
Mapping types: Direct requirement explicitly addressed by the TPSA field.
Partial TPSA addresses part of the requirement; additional measures needed.
Supporting TPSA data supports the requirement but does not fulfil it independently.
"—" indicates no applicable mapping.
D1 Asset Inventory & Data Mapping
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D1-01 Asset Register | CIS 1.1 / 1.2 | A.5.9 / A.5.10 | Art.28(3) | Art.21(2)(a) |
| D1-02 Asset Location | CIS 1.1 | A.5.9 / A.8.1 | Art.28(7)(a) | Art.21(2)(d) |
| D1-03 Hosting Model | CIS 1.1 | A.8.22 | Art.28(7)(b) | Art.21(2)(d) |
| D1-04 Data Types Hosted | CIS 3.2 | A.5.12 / A.5.13 | Art.28(7)(a) | Art.21(2)(d) |
| D1-05 Data Flow Diagram | CIS 3.4 | A.5.14 | Art.28(3) (supports) | — |
| D1-06 Sub-processors | CIS 15.2 | A.5.21 | Art.29 | Art.21(2)(d) |
| D1-07 Asset Classification | CIS 3.7 | A.5.12 / A.5.13 | Art.28(7)(a) (partial) | Art.21(2)(a) (partial) |
| D1-08 Asset Owner | CIS 1.2 | A.5.9 | Art.28(3) (supports) | — |
D2 Data Protection
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D2-01 Encryption at Rest | CIS 3.6 | A.8.24 | Art.9(2) | Art.21(2)(h) |
| D2-02 Encryption in Transit | CIS 3.10 | A.8.24 / A.5.14 | Art.9(2) | Art.21(2)(h) |
| D2-03 Key Management / BYOK / HYOK | CIS 3.6 / 3.10 (supports) | A.8.24 | Art.9(2) (partial) | Art.21(2)(h) (partial) |
| D2-04 Data Segregation (multi-tenant) | CIS 3.12 | A.8.22 | Art.28(7)(b) | Art.21(2)(d) |
| D2-05 Data Retention Policy | CIS 3.1 | A.5.33 | Art.28(7)(d) | Art.21(2)(a) (supports) |
| D2-06 Data Deletion Process | CIS 3.1 | A.8.10 / A.7.14 | Art.28(7)(d) / 28(8) | Art.21(2)(a) (supports) |
| D2-07 Data Classification Scheme | CIS 3.7 | A.5.12 / A.5.13 | Art.28(7)(a) (partial) | — |
| D2-08 Cross-border Transfers | — | A.5.14 (partial) | Art.28(7)(a) | Art.21(2)(d) (supports) |
D3 Backup & Recovery
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D3-01 Backup Policy | CIS 11.2 | A.8.13 | Art.11(1) / Art.12 | Art.21(2)(c) |
| D3-02 Backup Location | CIS 11.2 | A.8.13 | Art.12(2) | Art.21(2)(c) |
| D3-03 Backup Encryption | CIS 11.3 | A.8.13 / A.8.24 | Art.9(2) (supports) | Art.21(2)(h) (supports) |
| D3-04 RTO Declared | CIS 11.1 | A.5.29 | Art.11(4) | Art.21(2)(c) |
| D3-05 RPO Declared | CIS 11.1 | A.5.29 | Art.11(4) | Art.21(2)(c) |
| D3-06 Last Restore Test | CIS 11.5 | A.8.13 / A.5.30 | Art.11(6) / Art.12(2) | Art.21(2)(c) |
| D3-07 Restore Test Frequency | CIS 11.5 | A.5.30 | Art.11(6) | Art.21(2)(c) |
| D3-08 DR Plan Reference | CIS 11.1 | A.5.29 / A.5.30 | Art.11(1)–(3) | Art.21(2)(c) |
| D3-09 DR Test Results | CIS 11.5 | A.5.30 | Art.11(6) / Art.25 | Art.21(2)(c) |
D4 Access Control & Identity Management
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D4-01 Authentication / MFA | CIS 6.3 / 6.5 | A.8.5 | Art.9(4)(c) | Art.21(2)(j) |
| D4-02 PAM | CIS 5.4 / 6.5 | A.8.2 | Art.9(4)(c) | Art.21(2)(i) |
| D4-03 Access Review Cycle | CIS 5.1 / 5.3 | A.5.18 | Art.9(4)(b) | Art.21(2)(i) |
| D4-04 Least Privilege | CIS 5.4 / 6.8 | A.5.15 / A.8.3 | Art.9(4)(a) | Art.21(2)(i) |
| D4-05 Client-Facing Access | CIS 6.7 | A.5.15 / A.8.5 | Art.28(7)(c) | Art.21(2)(i) (partial) |
| D4-06 Third-Party Access | CIS 15.3 | A.5.19 / A.5.20 | Art.29 | Art.21(2)(d) |
| D4-07 Logging & Monitoring | CIS 8.2 / 8.5 | A.8.15 / A.8.16 | Art.10 | Art.21(2)(b) |
D5 Vulnerability Management & Testing
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D5-01 Vulnerability Scanning | CIS 7.1 / 7.5 / 7.6 | A.8.8 | Art.9(1) | Art.21(2)(e) |
| D5-02 Patch Management SLAs | CIS 7.3 / 7.4 | A.8.8 / A.8.19 | Art.9(2) / Art.7(1) | Art.21(2)(e) |
| D5-03 Penetration Testing | CIS 18.2 / 18.3 | A.8.8 / A.5.36 | Art.25 / Art.26 | Art.21(2)(e) (partial) |
| D5-04 Pentest Remediation | CIS 7.6 | A.8.8 | Art.25 (supports) / Art.26(8) | Art.21(2)(e) (supports) |
| D5-05 Bug Bounty / VDP | CIS 7.1 (supports) | A.8.8 (supports) | — | Art.21(2)(e) (vuln. disclosure) |
| D5-06 SBOM | CIS 2.6 / 16.4 | A.8.19 / A.5.21 | Art.28(3) (supports) | Art.21(2)(d) (supports) |
| D5-07 TIBER-EU Readiness | CIS 18.2 / 18.3 | A.5.36 | Art.26(1)–(4) | Art.21(2)(e) (partial) |
D6 Incident Management & Notification
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D6-01 Detection Capabilities | CIS 13.1 / 13.3 | A.8.15 / A.8.16 | Art.10 | Art.21(2)(b) |
| D6-02 Incident Response Plan | CIS 17.1 / 17.2 | A.5.24 / A.5.25 | Art.17 | Art.21(2)(b) |
| D6-03 Client Notification SLA | CIS 17.2 | A.5.24 / A.5.26 | Art.19(1)–(4) 4h initial / 72h intermediate / 1 month final | Art.23 |
| D6-04 Notification Content Format | CIS 17.2 (supports) | A.5.26 / A.5.27 | Art.19(4) | Art.23(3) |
| D6-05 Post-Incident Review / RCA | CIS 17.8 | A.5.27 | Art.17(3)(e) | Art.21(2)(b) (supports) |
| D6-06 Incident History 24m | CIS 17.9 | A.5.27 (supports) | Art.17(3)(e) / Art.28(3) | Art.23 (supports) |
| D6-07 Secure Communication Channel | CIS 17.2 | A.5.14 / A.5.24 | Art.17(3)(c) | Art.21(2)(b) (supports) |
D7 Compliance & Certification Status
| Field | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| D7-01 Certifications Held | CIS 15.1 | A.5.22 | Art.28(4) | Art.21(2)(d) (supports) |
| D7-02 Certification Scope | CIS 15.3 | A.5.22 | Art.28(4)(b) | Art.21(2)(d) (supports) |
| D7-03 Audit Findings Summary | CIS 15.4 | A.5.22 / A.5.35 | Art.28(3) | — |
| D7-04 Regulatory Status | CIS 15.1 (supports) | A.5.31 / A.5.36 | Art.28(2) | Art.21(1) |
| D7-05 Exclusions & Gaps | CIS 15.3 (supports) | A.5.22 (supports) | Art.28(4) (supports) | — |
| D7-06 Insurance Coverage | — | — | Art.28(3) (supports) | — |
TPSA-02 Protocol Elements
| Element | CIS Controls v8 | ISO 27001:2022 | DORA | NIS2 |
| Risk Scenario Card (RSC) | — | — | Art.28(1)(a) / Art.26(2) | Art.21(2)(a)/(d) |
| Supplier Risk Assessment (SRA) | — | — | Art.28(3) / Art.28(6) | Art.21(2)(d) |
| TEC-SCOPE (TIBER-EU Scoping) | — | — | Art.26(2) | — |
| TEC-EXEC (TIBER-EU Execution) | — | — | Art.26(3)/(4) | — |
| TEC-RESULTS (TIBER-EU Results) | — | — | Art.26(7)/(8) | — |
| Classification Uplift Request (CUR) | — | A.5.12 / A.5.13 | Art.28(7)(a) | Art.21(2)(a) (supports) |
| H-13 Digital Signature | — | A.8.24 / A.5.33 | Art.9(2) (supports) | Art.21(2)(h) (supports) |