Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. TPN · TRUSTED PARTNER NETWORK
  3. TPN assessment preparation

TPN · TRUSTED PARTNER NETWORK

The shields changed in September 2025, and now there are four

The Motion Picture Association's content security programme changed in September 2025, and most material still describes the old two-shield model. It is worth understanding the new one before starting, because the studio reads the whole report and much of the process is visible to them while it happens.

Talk to a specialistSee the other standards

DM11 prepares your company and runs the implementation. The assessment is carried out by a TPN-accredited assessor you choose and engage inside the TPN+ platform, and the report is reviewed and published by TPN itself. DM11 is not an accredited assessor and does not sell membership.

Who runs the preparation

  • ISO/IEC 27001 Lead Auditor certified by BSI

  • CISA, information systems auditing

  • An in-house penetration testing team for the application assessments

  • 17 years of governance, risk and compliance

WHAT IT IS, AND WHAT THE MARKET GETS WRONG

How the studio reads your result

TPN is the Motion Picture Association's content security programme. It maintains the MPA Content Security Best Practices, currently at version 5.3.1, and runs the TPN+ platform, where a service provider completes the assessment and a content owner looks the result up. There are more than fifteen hundred partners across more than sixty countries, and that registry is where a studio looks before it comes looking for you.

What the result means to a content owner

Worth setting the expectation calmly here, because it changes how the project runs. The official guide explains that the assessment and the shield do not work as an approval, a certification or a pass/fail: each content owner makes its own independent, risk-based decision, using the TPN result as a baseline. In practice that favours companies that prepare well, because the studio reads what the report says rather than only the colour of the shield.

Four shields since September 2025

Blue publishes the answers you gave the questionnaire yourself. Silver means an accredited assessor reviewed evidence against those answers and the report was published, with a remediation plan from you. Gold means the best practice remediation items were closed and reviewed by TPN. Gold Star adds the additional recommendations, also closed.

Yesterday's Gold is not today's Gold

Earlier versions of the Best Practices carried only two shields, Blue and Gold, and that Gold matched what Silver means now: an assessor's report published alongside a remediation plan. On the current version, Gold requires the remediation actually closed. The bar rose, which is why it is worth checking which version any shield on display was issued against, including your competitors'.

The shield belongs to a site or an application, not the company

Security is measured across services, sites and applications, and no one of those elements tells the whole story on its own. A company with three facilities does not receive a single shield. Deciding what enters the scope is the first decision of the project, and the one that moves the cost most.

Your application very likely belongs in scope too

TPN recommends adding both in-house developed and licensed applications to your profile. Where a web application stores, processes or transfers content assets, and the portal your customer uploads masters through almost always does, an application assessment is recommended. It falls outside the scope of anyone who only thought about the physical facilities.

Membership and assessment are separate costs

Membership is annual, set by the prior year's gross revenue band, and it is what gives you registry visibility and the right to complete the assessment on the platform. The assessment cost is separate and agreed with the assessor, who scopes and prices it with you. It is the most common budget surprise, and it lands after the agreement is signed.

WHO USUALLY NEEDS IT

Three moments when a shield becomes a contract condition

Companies handling studio and streaming content rarely pick the timing. The requirement arrives fully formed, inside a contract already on the table.

The contract started requiring it

Dubbing, subtitling, mixing, post-production, finishing, VFX and localisation. The studio added TPN at renewal and set a date. This is the most common case and the tightest one, because the deadline was set by someone who does not know what sits inside your operation.

You want to be found before you are approached

The TPN+ registry is where content owners search for vendors. Being visible there, with a shield, puts your company on a shortlist that is currently being drawn up without you. It is the one reason on this page that does not begin with a requirement: it begins with sales.

Blue was not enough

Plenty of companies answer the questionnaire, publish the Blue shield and consider the matter settled. When the customer asks for evidence reviewed by a third party, they discover Blue is self-declared, and that the optimistic answer given months ago is now the yardstick the assessor will measure against.

STORIES

Three situations we have already worked through

We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.

Dubbing and subtitling

The questionnaire was answered by optimism

Situation

The company filled the questionnaire in on its own, marked nearly every question as met and published the Blue shield. Months later a customer asked for an evidence-based assessment. Opening those answers to brief the assessor, much of it had no document behind it: the practice existed, the record did not.

What we did

We went back through the questionnaire item by item, refusing to accept any answer without evidence attached. Where the control genuinely existed, we organised the proof. Where it did not, it became a plan with an owner and a date. And we made clear to the board which answers would have to change meaning on republication.

Outcome

The assessment ran against answers that held up, with no scene of an assessor discovering the gap. The heavier work was filing rather than technology: almost everything missing was proof of something already being done.

Post-production and finishing

The production network talked to the office network

Situation

Customer material moved across the same network as email and the back-office system, and the finishing workstation had unrestricted internet access. There were cameras at the door and a visitor log on paper, so the internal perception was that physical security was handled and the problem lay elsewhere.

What we did

We separated the production network from the rest, with explicit rules on what may leave and where to. We dealt with removable media, which was the real route content took out, and reviewed access to the suites by function rather than by person. The physical side gained records, because a camera with no retention and nobody reviewing it is not evidence.

Outcome

The scope came out smaller than the company feared. Isolating production from the back office meant half the controls stopped applying to the whole environment and applied only where content actually lives.

Content distribution and delivery

The customer portal was left out of scope

Situation

The company prepared its facilities carefully and forgot the web application customers used to send and download material. Because the portal was an old internal system, nobody treated it as part of the content environment, and it had never been tested.

What we did

We brought the portal into scope and ran a penetration test on the application before any assessment. We found broken access control between different customer accounts, fixed it, and only then added the application to the platform profile.

Outcome

The failure that mattered most was not in the building, it was at the login. Fixed before the assessment started, it never became a public remediation item or a conversation with the studio.

HOW WE RUN IT

From scope to shield, without publishing an answer that will not hold

Order matters here more than on any other standard on this site, for one specific reason: much of the process is visible to content owners while it happens. A completed questionnaire, a published report and an open remediation plan all show up for the people assessing you. So preparation comes before publication, not after.

  1. 01

    Scope: which sites and which applications enter

    We map where customer content actually moves, which is rarely only where the company assumes. We define the sites and applications entering the assessment, separate the production environment from the back office wherever we can, and translate the Best Practices into the kind of service your company delivers.

    • A map of where content enters, is handled, is stored and leaves

    • Sites and applications defined in scope, with each exclusion justified

    • The target shield defined, and what it demands in each case

    • The Best Practices read against your specific service

    Delivery milestoneScope approved by the board, with the assessment cost already sized with the assessor.

  2. 02

    A rehearsal of the questionnaire, before anything is published

    We answer the questionnaire internally, item by item, accepting no answer without evidence attached. This is the opposite of filling it in quickly to publish Blue: here the optimistic answer is the problem, because it becomes visible and turns into the yardstick the assessor will later check evidence against.

    • The questionnaire answered with evidence attached to every item

    • Gaps listed in order of risk to the content

    • A plan with an owner and a date for each gap

    • A recommendation on what to publish now and what to hold

    Delivery milestoneNo answer marked as met without a document standing behind it.

  3. 03

    Closing the gaps, in the building and in the software

    We implement alongside your team, and the two fronts run together. On the physical and organisational side: access, removable media, visitors, logging and network segregation. On the application side: penetration testing of the applications in scope, with fixes verified before the assessor arrives rather than after.

    • Segregation between the production and back-office environments

    • Access control, removable media handling and logging implemented

    • Penetration testing of the in-scope applications, with a retest

    • An evidence repository organised the way the assessor expects

    Delivery milestoneHigh-risk gaps closed and verified, with the evidence filed.

  4. 04

    Assessment and closing the remediation

    You choose the accredited assessor on the platform and they scope and price the work. We stay on your side through the assessment, prepare whoever will be interviewed and organise whatever is requested. Once the report is published, we drive the remediation plan through to closure, which is what separates Silver from Gold.

    • The team prepared for the assessor's interviews

    • Support throughout the assessment

    • A structured remediation plan with realistic dates

    • The closure of each item driven through to TPN's review

    Delivery milestoneReport published, and remediation items closed and reviewed.

HOW LONG IT TAKES

TPN itself suggests aiming for a first shield within ninety days

That is the reference the official guide gives for a first site or application shield, and it is an honest starting point. We do not publish a timeline of our own, because a published timeline turns into a promise, and the variation here is wide. What follows are the three factors that move the clock most, and the first conversation already shows which one your company is in.

How many sites and applications enter

One site and one application is one project. Four facilities and a portal with integrations is an entirely different one, and each element carries its own assessment. Scope is the heaviest variable, which is why it is the first thing we settle.

Which shield you are aiming at

Blue depends only on answering honestly and holding the evidence. Silver adds the assessor's time. Gold depends on actually closing every remediation item, and that is the stretch that most escapes your control, because in some companies it means capital spend and building work.

What is already running

A company with ISO 27001 in operation arrives with access management, logging, third-party management and incident response already in place, and saves months. What does not carry over is the content-specific part, which is where most projects spend their time.

THE ROLES ARE KEPT APART

DM11 prepares. The assessor is accredited by TPN.

The separation here comes from the structure of the programme, not from a choice of ours. The assessment is carried out by a TPN-accredited assessor you select in TPN+, who scopes and prices the work directly with your company. The report is reviewed and published by TPN, and the closure of remediation goes through TPN's review as well. Preparing and assessing are different roles, and mixing them would strip the result of its value for exactly the people who have to read it.

  • DM11 prepares, implements and supports. It is not an accredited assessor

  • You choose the assessor inside the platform, and the choice is yours

  • Membership is contracted by you, directly with TPN

  • TPN is who publishes the report and reviews the remediation

FREQUENTLY ASKED

What people ask before deciding

The questions that come up in almost every first meeting, answered straight.

No. The official guide states that the assessment and the shields are not an approval, a certification or a pass/fail, and that each content owner makes its own independent, risk-based decision using the result as a baseline. The phrase TPN certification circulates widely, including in vendor material, but it does not describe what the programme delivers. What exists is a shield, and it tells people which stage of the assessment your company has reached.

The studio asked for TPN and the clock is already running?

Bring us the contract wording and a list of your facilities. We will tell you what belongs in scope, which shield answers the requirement, and what can be closed before anything becomes visible in the registry.

Talk to a specialist

Comparisons on this subject

  • TISAX vs ISO 27001
  • Pentest vs Vulnerability Assessment
See all 13 comparisons