Compliance · Supply chain integrity
Prove your hardware and software weren't tampered with on the way to the customer.
ISO/IEC 20243 — the Open Trusted Technology Provider Standard — addresses two threats regulators and defense buyers care about: tainted products (maliciously modified) and counterfeit products. It applies across the whole lifecycle, from design to delivery.
Tainted
Threat one
Counterfeit
Threat two
Lifecycle
Scope
Supply chain integrity for organizations that build or integrate technology products.
Preventing malicious modification anywhere in design, sourcing, build, or delivery — the software and hardware equivalent of a poisoned well.
Stopping fraudulent components from entering your product or your customers' environments through the parts you buy.
Requirements span secure development, sourcing, build, fulfilment, sustainment, and disposal — not just the factory floor.
Technology providers whose customers can't afford a compromised component.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We map your suppliers, components, and handoffs — you can't secure a chain you haven't drawn.
We implement the secure engineering, code integrity, and build controls the standard expects.
We build supplier vetting, component authentication, and anti-counterfeit measures into procurement.
We establish custody, tamper-evidence, and integrity verification through fulfilment.
We cover patching, updates, and secure disposal across the product's life.
We prepare the evidence for O-TTPS assessment and customer supply chain audits.
Inventory suppliers, components, and lifecycle handoffs.
Measure practices against O-TTPS requirements.
Close development, sourcing, and custody gaps.
Document practices and verification results.
Support formal assessment and keep controls live.
Primarily defense, government, and critical infrastructure buyers, and large OEMs pushing integrity requirements down their supply chain. If you sell components or systems into those markets, it shows up in contracts.
They're complementary. SBOM tells you what's in the software; O-TTPS covers the practices ensuring what's in it got there legitimately and wasn't tampered with. Buyers increasingly want both.
Yes. The standard covers commercial off-the-shelf ICT products generally — tainted software through compromised build pipelines or dependencies is squarely in scope, and is the more common attack today.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.