Trusted Partner Network (TPN) Assessment: A Readiness Guide for Post-Production and VFX Vendors
What the Trusted Partner Network assessment covers, how the four TPN Shield tiers work, and a readiness checklist for post and VFX vendors.
The Trusted Partner Network (TPN) is the Motion Picture Association’s content security program, and it is how studios and streamers now check whether a vendor can be trusted with pre-release content. A TPN assessment measures a facility or application against the MPA Content Security Best Practices and publishes the result to a registry that content owners read before they award work. This guide covers what the assessment is, how the four Shield tiers work, and what to fix before an assessor arrives.
What Is the Trusted Partner Network?
TPN is wholly owned by the Motion Picture Association (MPA). It does three things. It maintains the MPA Content Security Best Practices, the single benchmark the industry uses for vendor security. It accredits the independent assessors who measure vendors against that benchmark. And it runs TPN+, the platform and global registry where service providers publish their questionnaires, assessment reports, and remediation status for content owners to review.
Participation is voluntary. In practice, a post house, VFX studio, localization vendor, or screening service that wants work involving unreleased picture, sound, or scripts will be asked for its TPN status early in the conversation.
TPN Does Not Certify Anyone
This is the most common misunderstanding. TPN says plainly that it does not issue certifications, and its assessments carry no pass or fail grade and no rating. An assessment reports how a site or application conforms to the Best Practices at the time it was assessed. Anything short of conformance is recorded as a remediation item. Each studio then makes its own risk-based decision about whether to send you work.
Two consequences follow. No vendor, consultant, or managed service provider can make you “TPN certified,” because the status does not exist. And open remediation items are visible to the people deciding whether to hire you, so what you do after the assessment matters as much as the assessment.
The Four TPN Shield Tiers
Until 2025, TPN had two Shields: Blue for a self-assessment and Gold for a third-party assessment. With the v5.3.1 release of the Best Practices, TPN moved to four tiers so the registry shows not only that a vendor was assessed, but how much of the remediation it completed.
| Shield | What It Means | Valid For |
|---|---|---|
| Blue | Self-assessment questionnaire completed and published on TPN+ | 1 year from submission |
| Silver | Assessed by a TPN-accredited third party, with a remediation plan submitted | 2 years from report publication |
| Gold | All Best Practice remediation items completed and reviewed by TPN | 2 years from report publication |
| Gold Star | All Best Practices and the additional recommendations completed and reviewed by TPN | 2 years from report publication |
A legacy Gold Shield earned under the old model stays valid until its assessment expires, but it does not show remediation progress. Moving into the new tiers requires a v5.3.1 assessment.
How the TPN Assessment Process Works
- Create your TPN+ profile. Register your company, sites, services, and any applications you built. You can complete the profile and questionnaires before paying the membership fee, but nothing is visible to content owners until you join.
- Answer the Best Practices questionnaire. One per site or application. Publishing it earns the Blue Shield. Answer it accurately: the same answers are what a third-party assessor will later test.
- Select an accredited assessor. You choose from the TPN directory and contract with the assessor directly. Assessment fees are separate from TPN membership, and TPN recommends collecting more than one bid.
- Undergo the assessment. The assessor reviews evidence and validates controls, then submits the report. TPN expects assessments to be completed and submitted within 15 business days.
- Submit a remediation plan. With the assessment published and a plan on file, you hold the Silver Shield.
- Close the items. TPN reviews your evidence as you remediate. Closing every Best Practice item earns Gold; closing the additional recommendations as well earns Gold Star.
Assessors are accredited separately for site assessments and for cloud and application assessments, so a facility that also runs its own review or transfer portal may need both. Companies with more than three sites or applications that share the same security implementation can ask TPN about its Global Pass process rather than repeating the questionnaire for each one.
Why Your Assessor Cannot Be Your Fixer
TPN keeps the two roles apart. An accredited assessor may consult on or plan remediation for a vendor only if it has not been that vendor’s assigned assessor within two years of the assessment. The firm that writes your findings is, by design, not the firm that closes them. Plan for a separate partner, or internal capacity, to do the remediation work.
A TPN Readiness Checklist
The Best Practices span organizational policy, day-to-day operations, physical security, and technical security. Work through these before you book an assessor.
- Map the content flow. Document where client content enters, where it is stored and worked on, who can reach it, and how it leaves. Every other control hangs on this map.
- Segment the production network. Keep content systems off the office, guest, and general internet-facing networks, with firewall rules that are written down and reviewed.
- Control and log access. Unique accounts, multi-factor authentication, least privilege, prompt offboarding, and logs that show who touched what.
- Secure transfer and storage. Encrypted transfer tools with per-recipient access and expiry, encrypted storage, and no content on personal cloud accounts or unmanaged drives.
- Protect the endpoints. Managed workstations with endpoint detection and response, patching, removable-media control, and hardened remote access for artists working off-site.
- Monitor continuously. Centralized logging with retention and around-the-clock alerting, so an incident is caught in hours rather than discovered in an audit.
- Test it. Regular vulnerability scanning and periodic penetration testing, with findings tracked to closure.
- Cover the building. Camera coverage with retention, badge or keyed access to edit bays and machine rooms, visitor logs, and a process for who may bring devices where.
- Write the policies you actually follow. Security policy, acceptable use, incident response, business continuity, and vendor management, with training records to match.
- Build the evidence library. Screenshots, configurations, logs, and records organized by control, so the assessment is a review of proof rather than a scramble to produce it.
How Boom Logic Helps
Boom Logic is not a TPN assessor and does not award Shields; an independent, TPN-accredited assessor that you select performs the assessment. We do the other half of the work. Our media and entertainment IT services cover the readiness review against the Best Practices, network segmentation, the managed security stack, 24/7/365 monitoring through SOC as a Service, cameras and access control, policies and evidence, and the remediation that moves a vendor from Silver toward Gold—delivered by one accountable team, on infrastructure we operate, with a presence in the world’s top-rated data centers, One Wilshire and Equinix.
Every facility gets a free IT and security assessment. Organizations with 25 or more staff or endpoints also receive a complimentary external penetration test and phishing simulation under a signed rules-of-engagement agreement.
Program details in this guide reflect the Trusted Partner Network’s published FAQs as of September 2026. TPN updates its program periodically; confirm current requirements with TPN before you schedule an assessment.
More from the blog. Security, infrastructure, and the business of IT.
CMMC 2.0 Compliance Checklist: What Defense Contractors Must Have Before Phase 2
A CMMC 2.0 compliance checklist for defense suppliers: scoping decisions, the 14 NIST SP 800-171 control families, the documents assessors open first, and the…
Read article →What Is a Written Information Security Plan (WISP)? A Guide for Accounting and Tax Firms
A WISP is the FTC Safeguards Rule document every accounting and tax firm must keep. Here are the nine required elements, what the plan…
Read article →Cybersecurity for Law Firms: The 2026 Incident-Response Checklist
What cybersecurity for law firms requires in 2026: the ethics duties, the controls that matter, and a step-by-step incident-response checklist for partners.
Read article →Have a question this article didn’t answer?
Talk to the engineers directly. Get a free security assessment and a clear, flat-rate plan from one accountable team.