Certification · Last verified

Open Trusted Technology Provider Standard

O-TTPS is The Open Group's certification standard against maliciously tainted and counterfeit ICT products, with a live public certification register. The register lists organizations under two tiers, Third-Party Assessed and Self-Assessed, and each entry records its own O-TTPS version — both Version 1.1.1 (ISO/IEC 20243:2018) and Version 1.2 (ISO/IEC 20243:2023) appear.

Class
Certification
Owner
The Open Group
Public register
Verified working
Last verified

What it is

The Open Group describes the O-TTPS as "a standard of The Open Group, provides a set of guidelines, recommendations and requirements that help assure against maliciously tainted and counterfeit products throughout commercial off-the-shelf (COTS) information and communication technology (ICT) product lifecycles." The program's stated purpose is to "assure customers of the integrity of commercial off-the-shelf (COTS) information and ICT products worldwide and to safeguard global supply chains against increasingly sophisticated security attacks."

The full title is Open Trusted Technology Provider™ Standard (O-TTPS) — Mitigating Maliciously Tainted and Counterfeit Products, published in two parts (Part 1: Requirements and Recommendations; Part 2: Assessment Procedures), currently at Version 1.2.

The Open Group's narrative pages do not mention ISO/IEC 20243, but its own public certification register documents the equivalence for each entry: rows show both "Version 1.1.1 (ISO/IEC 20243:2018)" and "Version 1.2 (ISO/IEC 20243:2023)" (confirmed by reading the register page itself, 2026-09-04), so the ISO edition tracks the O-TTPS version rather than being a single fixed equivalence.

Who owns it

The O-TTPS is owned and published by The Open Group.

Who assesses it

Two assessment tiers exist on the register: Third-Party Assessed, where a Recognized Assessor listed on The Open Group's separate Recognized Assessors register performs the assessment, and Self-Assessed, where the provider assesses itself.

Assessment tiers

  • Third-Party Assessed — Assessment carried out by a Recognized Assessor listed on The Open Group's own Recognized Assessors register
  • Self-Assessed — The provider itself carries out the assessment against the O-TTPS requirements

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Open Trusted Technology Provider Standard." Certifidex, FutureTechnologies. Last verified 4 September 2026. https://certifidex.com/frameworks/o-ttps

All frameworks & audits →