Certification · Last verified
Open Trusted Technology Provider Standard
O-TTPS is The Open Group's certification standard against maliciously tainted and counterfeit ICT products, with a live public certification register. The register lists organizations under two tiers, Third-Party Assessed and Self-Assessed, and each entry records its own O-TTPS version — both Version 1.1.1 (ISO/IEC 20243:2018) and Version 1.2 (ISO/IEC 20243:2023) appear.
- Class
- Certification
- Owner
- The Open Group
- Public register
- Verified working
- Last verified
What it is
The Open Group describes the O-TTPS as "a standard of The Open Group, provides a set of guidelines, recommendations and requirements that help assure against maliciously tainted and counterfeit products throughout commercial off-the-shelf (COTS) information and communication technology (ICT) product lifecycles." The program's stated purpose is to "assure customers of the integrity of commercial off-the-shelf (COTS) information and ICT products worldwide and to safeguard global supply chains against increasingly sophisticated security attacks."
The full title is Open Trusted Technology Provider™ Standard (O-TTPS) — Mitigating Maliciously Tainted and Counterfeit Products, published in two parts (Part 1: Requirements and Recommendations; Part 2: Assessment Procedures), currently at Version 1.2.
The Open Group's narrative pages do not mention ISO/IEC 20243, but its own public certification register documents the equivalence for each entry: rows show both "Version 1.1.1 (ISO/IEC 20243:2018)" and "Version 1.2 (ISO/IEC 20243:2023)" (confirmed by reading the register page itself, 2026-09-04), so the ISO edition tracks the O-TTPS version rather than being a single fixed equivalence.
Who owns it
The O-TTPS is owned and published by The Open Group.
Who assesses it
Two assessment tiers exist on the register: Third-Party Assessed, where a Recognized Assessor listed on The Open Group's separate Recognized Assessors register performs the assessment, and Self-Assessed, where the provider assesses itself.
Assessment tiers
- Third-Party Assessed —
Assessment carried out by a Recognized Assessor listed on The Open Group's own Recognized Assessors register
- Self-Assessed —
The provider itself carries out the assessment against the O-TTPS requirements
Sources
- The Open Group — O-TTPS certification standard (scheme owner) ↗ — accessed
- The Open Group — O-TTPS certifications overview ↗ — accessed
- The Open Group — O-TTPS certification program (source of the "assure customers of the integrity..." quote below) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.