Five Guiding Principles

Independence

Third-party accredited bodies only not the standard owner, not consultants, not the supplier itself.

Proportionality

Three maturity levels calibrated to different sizes, criticality, and regulatory exposure.

Transparency

Publicly available criteria, documented processes, unambiguous label meaning. Public register of certified suppliers.

Compatibility

Integrates with ISO 27001, SOC 2, HDS, SecNumCloud without duplicating existing audit work.

Continuous Validity

Unlike point-in-time certifications, TPSA validity is maintained through ongoing surveillance audits and event-driven reviews. Non-conformities trigger defined corrective action timelines, with suspension and withdrawal processes clearly specified.

Maturity Levels in Detail

BASIC Level 1

Foundational transparency. Target: SME suppliers and non-critical providers.

  • TPSA-01: Conformant Common Disclosure Card, all Mandatory fields populated
  • Annual review (H-05 ≤12 months)
  • Designated security contact, reachable and responsive
  • TPSA-02: Not required
  • Audit: source evidence verification of minimum 3 fields per domain

ENHANCED Level 2

Active accountability. Target: mid-tier suppliers, SaaS and MSPs serving regulated clients.

  • TPSA-01: All Mandatory + all applicable Conditional fields; Client-Specific Annexes for all clients requesting them; semi-annual + event-driven updates (30 days)
  • TPSA-02: Operationally implemented; ≥1 transport mechanism; acknowledge ≤10 business days; respond ≤30 business days; exchange log maintained; at least one RSC/SRA cycle completed (real or simulated)
  • Audit: minimum 5 fields per domain; review of ≥1 RSC/SRA exchange; exchange log verification

FULL Level 3

Complete accountability. Target: critical ICT third-party providers to DORA-regulated entities, major cloud/infrastructure providers.

  • TPSA-01: All fields including recommended Optional; continuous maintenance (15-day updates); Classification Uplift documented and exercised ≥1 time; Disclosure Cards countersigned by auditor at each surveillance
  • TPSA-02: Acknowledge ≤5 business days; respond ≤15 business days; TIBER-EU Coordination Messages supported; TIBER-EU readiness demonstrated (real or tabletop); TPSA Reference Platform API implemented
  • Audit: ≥3 RSC/SRA exchanges; ≥1 Classification Uplift cycle; TIBER-EU readiness evidence; 100% field coverage against source evidence

Audit Process Four Phases

1

Application & Scoping

Supplier submits application to an accredited CB, specifying target TPSA level, scope, and existing certifications. CB issues a scoping proposal.

2

Document Review (Stage 1)

CB reviews Disclosure Cards, Risk Dialogue documentation, and exchange logs. Identifies gaps and non-conformities. May be conducted remotely.

3

On-site / Remote Audit (Stage 2)

Substantive audit: Disclosure Card content verified against source evidence; RSC/SRA operations review (Enhanced/Full); key personnel interviews; simulated RSC/SRA for first-time Enhanced/Full without real exchanges.

4

Certification Decision

Decision by a person or committee independent of the audit team. Three outcomes: CERTIFIED (no major NCs), CONDITIONAL (minor NCs correct within 90 days), DENIED (major NCs).

Minimum Audit Duration

Supplier Size BASIC ENHANCED FULL
Small (<50 employees)1 day2 days3 days
Medium (50–500)1.5 days3 days5 days
Large (>500)2 days4 days7+ days

Integration with Existing Certifications

Scope Reduction Opportunity

If a supplier holds valid ISO 27001 covering services in scope, the TPSA auditor may rely on the Statement of Applicability and last audit report for domains D2, D4, D5, D6 focusing the TPSA audit on D1 (client-oriented asset inventory), D3 (backup requires tested restore evidence), D7, and the Risk Dialogue Protocol. SOC 2 Type II may similarly support D4, D5, D6.

However, the TPSA auditor always independently verifies: Disclosure Card accuracy (every field against source evidence), Risk Dialogue Protocol operationality, Classification Uplift process (Full), client-orientation of disclosures, and KRI accuracy.

Certification Lifecycle

Validity: 3 years from certification decision, subject to successful surveillance audits.

Level Surveillance Frequency Scope Mode
BASIC Annual Disclosure Card currency; 2 fields/domain sample Remote
ENHANCED Semi-annual Disclosure Card + RSC/SRA exchanges since last audit; 3 fields/domain Remote or on-site
FULL Semi-annual + event-driven Full Disclosure Card; all RSC/SRA/TEC exchanges; Classification Uplift activity; auditor countersignature On-site required ≥1/year

Non-Conformity Classification

ClassificationDefinitionRequired Action
Major NC Mandatory requirement not implemented, ineffective, or Disclosure Card materially inaccurate on a critical point (e.g. asset omission, false pentest date) Corrective action within 90 days. Verification audit required. Two unresolved Major NCs → suspension.
Minor NC Requirement partially implemented; field incomplete or imprecise; process inconsistently followed Corrective action within 180 days. Verification at next surveillance. Three+ minor NCs may escalate to Major.
Observation Area for improvement not a non-conformity; risk of future NC No mandatory action. Reviewed at next surveillance.

Suspension conditions: 2+ unresolved Major NCs; missed surveillance audit (>60 days overdue); voluntary suspension; credible material misrepresentation. Maximum 6 months to resolve before withdrawal.

Withdrawal leads to a 12-month cooling period before reapplication. A full initial audit is required.

Certification Bodies

Accreditation requirements:

  • ISO/IEC 17021-1 or ISO/IEC 17065 accreditation
  • ≥3 years ISO 27001, SOC 2, or equivalent certification activity
  • ≥2 qualified TPSA auditors on staff
  • Formal acceptance of TPSA Certification Body Agreement

Target CBs for initial engagement (H2 2027): AFNOR (France), LSTI (France), BSI (UK/Germany), Bureau Veritas (global)

Auditor qualifications: CISSP, CISA, ISO 27001 Lead Auditor, or equivalent; ≥5 years professional experience in information security including third-party risk; TPSA Auditor Training Programme completion; FULL audits with TIBER-EU: at least one team member with TLPT/TIBER-EU experience.

Impartiality: A CB that provided consulting to a supplier within the preceding 24 months may not certify that supplier. The standard author and affiliated consultancies may provide advisory support but never certification audits.

The TPSA Label

Designation format:

TPSA Certified [Level] [Scope Summary]
Certificate #[CB-REF] Valid until [DATE]

Example: TPSA Certified Enhanced CloudWorks Document Management Platform / Certificate #LSTI-TPSA-2027-001 / Valid until 2030-03-31

The label must always include the level, scope, certificate number, and validity date. Misleading use implying a higher level, or extending to out-of-scope services is grounds for immediate suspension.

A public register maintained by the governance body serves as the authoritative source. Supplier statements are secondary.

Costs & Economics

No Barrier to Adoption

Standard documents, JSON schemas, Disclosure Card templates, and the Reference Platform are all free. The only cost to suppliers is the certification audit fee paid to the accredited CB. No fees are charged by the governance body for standard adoption.

Supplier Size BASIC (initial) ENHANCED (initial) FULL (initial)
Small (<50 employees)€3,000 – €5,000€6,000 – €12,000€12,000 – €20,000
Medium (50–500)€5,000 – €8,000€10,000 – €20,000€20,000 – €35,000
Large (>500)€8,000 – €15,000€18,000 – €35,000€35,000 – €60,000+

Surveillance audits: approximately 30–50% of initial certification cost. Suppliers with existing ISO 27001 or SOC 2 may benefit from reduced scope and lower cost.

Governance

The TPSA governance body is responsible for: framework publication and maintenance, CB accreditation, Auditor Training Programme, public register, dispute resolution, and framework version management.

Funding: CB accreditation fees + auditor training fees + voluntary contributions. No fees charged to suppliers for standard adoption.

Advisory Board meets semi-annually with representatives from: ≥2 certified suppliers (1 SME, 1 large enterprise), ≥2 client organizations, ≥1 accredited CB, regulatory observers (ANSSI, ENISA, national financial supervisors), CIS, ISO national bodies, and independent experts.

Framework evolution: MAJOR version changes trigger transition periods 12 months for Basic, 18 months for Enhanced/Full. Minor updates applied at next surveillance or recertification audit.