# TPN assessment readiness for media and entertainment vendors

> How consultants prepare media and entertainment vendors for a Trusted Partner Network assessment, what each TPN Shield requires, and how to scope Site, Cloud and Application assessments.

Canonical: https://controls.run/frameworks/tpn
Updated: 2026-09-29

The Trusted Partner Network (TPN) is the film and television industry's content security program, built on the Motion Picture Association's Content Security Best Practices. Vendors that handle pre-release film and television content, such as post-production houses, localization studios and cloud platforms, are assessed against those best practices and earn a Shield that studios check before sharing content. A readiness assessment tells the vendor which Shield is realistic, what the assessor will look for, and what to fix first.

## The four Shields

| Shield | What it takes | Valid for |
|---|---|---|
| Blue | Self-reported questionnaire in TPN+ | 1 year |
| Silver | Assessment by a TPN-qualified assessor, with a remediation plan | 2 years |
| Gold | Findings fully remediated and reviewed by TPN | 2 years |
| Gold Star | Gold, plus the additional recommendations | 2 years |

## Scoping the assessment

TPN assessments are scoped as **Site**, **Cloud** or **Application**, or a combination. A post-production house with an on-premises facility and a cloud render pipeline may need both Site and Cloud. Before collecting evidence, confirm:

- Which content workflows are in scope, such as production, post-production, localization, storage, delivery or processing by automated tools.
- Which applications and services handle pre-release or sensitive content.
- Which Shield the vendor is preparing for.
- Where the vendor stands in TPN+: profile created, questionnaire completed, assessor selected or remediation plans submitted.

## What to request

Content security evidence mixes physical and technical records. Expect site access logs and camera coverage, visitor and escort records, network segmentation diagrams, content transfer logs, watermarking and encryption settings, and access reviews for the systems that hold content. The questionnaire answers in TPN+ should match what the evidence shows, since the assessor will compare them.

## How Control+s supports TPN readiness

- **Scope by assessment type and Shield target**, with the content workflows and TPN+ status recorded alongside the assessment.
- **Score each best practice** from 0 to 5 with a rationale citing the evidence and the remaining gaps, rolled up by domain.
- **Share a TPN Shield readiness snapshot** with the vendor, or generate a readiness report with the remediation path.
- **Reuse the evidence** when the vendor also needs ISO 27001 or SOC 2 for non-studio customers.

Control+s is not a TPN-qualified assessor and does not award Shields. It prepares the readiness assessment you deliver.

## Frequently asked questions

### What are the TPN Shields?

TPN uses four Shields. Blue is self-reported and valid for one year. Silver adds an assessment by a TPN-qualified assessor with a remediation plan. Gold means the findings are fully remediated and reviewed by TPN. Gold Star also meets the additional recommendations. Silver, Gold and Gold Star are valid for two years.

### Which version of the MPA Content Security Best Practices applies?

The four-Shield system launched on 9 September 2025 with version 5.3.1 of the MPA Content Security Best Practices. TPN's resources page lists version 5.3.2 as of September 2026. Check the TPN site for the current version before starting an engagement.

### Who performs a TPN assessment?

A TPN-qualified assessor, selected by the service provider through the TPN+ platform. Consultants who are not the assessor help with readiness by scoping the assessment, checking evidence against the best practices and planning remediation.

## Related

- [Control+s vs spreadsheets for security assessments](https://controls.run/compare/spreadsheets)
- [ISO 27001 gap assessments for consultants](https://controls.run/frameworks/iso-27001)
- [Reusing evidence across ISO 27001, NIST CSF, CIS Controls, SOC 2 and CPCSC](https://controls.run/frameworks/cross-framework-evidence)

## Sources

- [Trusted Partner Network: FAQs](https://trustedpartnernetwork.org/faqs/)
- [Trusted Partner Network: Links and resources](https://trustedpartnernetwork.org/links-resources/)

## About Control+s

Control+s is a control assessment platform for security consultants and vCISO teams. It maps client evidence across the frameworks in scope, drafts maturity scores with cited rationale for the assessor to review, and produces client deliverables.

- Try it free: https://controls.run/try
- Agent guide: https://controls.run/llms.txt
