The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
TPN · TRUSTED PARTNER NETWORK
The Motion Picture Association's content security programme changed in September 2025, and most material still describes the old two-shield model. It is worth understanding the new one before starting, because the studio reads the whole report and much of the process is visible to them while it happens.
DM11 prepares your company and runs the implementation. The assessment is carried out by a TPN-accredited assessor you choose and engage inside the TPN+ platform, and the report is reviewed and published by TPN itself. DM11 is not an accredited assessor and does not sell membership.
Who runs the preparation
ISO/IEC 27001 Lead Auditor certified by BSI
CISA, information systems auditing
An in-house penetration testing team for the application assessments
17 years of governance, risk and compliance
WHAT IT IS, AND WHAT THE MARKET GETS WRONG
TPN is the Motion Picture Association's content security programme. It maintains the MPA Content Security Best Practices, currently at version 5.3.1, and runs the TPN+ platform, where a service provider completes the assessment and a content owner looks the result up. There are more than fifteen hundred partners across more than sixty countries, and that registry is where a studio looks before it comes looking for you.
Worth setting the expectation calmly here, because it changes how the project runs. The official guide explains that the assessment and the shield do not work as an approval, a certification or a pass/fail: each content owner makes its own independent, risk-based decision, using the TPN result as a baseline. In practice that favours companies that prepare well, because the studio reads what the report says rather than only the colour of the shield.
Blue publishes the answers you gave the questionnaire yourself. Silver means an accredited assessor reviewed evidence against those answers and the report was published, with a remediation plan from you. Gold means the best practice remediation items were closed and reviewed by TPN. Gold Star adds the additional recommendations, also closed.
Earlier versions of the Best Practices carried only two shields, Blue and Gold, and that Gold matched what Silver means now: an assessor's report published alongside a remediation plan. On the current version, Gold requires the remediation actually closed. The bar rose, which is why it is worth checking which version any shield on display was issued against, including your competitors'.
Security is measured across services, sites and applications, and no one of those elements tells the whole story on its own. A company with three facilities does not receive a single shield. Deciding what enters the scope is the first decision of the project, and the one that moves the cost most.
TPN recommends adding both in-house developed and licensed applications to your profile. Where a web application stores, processes or transfers content assets, and the portal your customer uploads masters through almost always does, an application assessment is recommended. It falls outside the scope of anyone who only thought about the physical facilities.
Membership is annual, set by the prior year's gross revenue band, and it is what gives you registry visibility and the right to complete the assessment on the platform. The assessment cost is separate and agreed with the assessor, who scopes and prices it with you. It is the most common budget surprise, and it lands after the agreement is signed.
WHO USUALLY NEEDS IT
Companies handling studio and streaming content rarely pick the timing. The requirement arrives fully formed, inside a contract already on the table.
Dubbing, subtitling, mixing, post-production, finishing, VFX and localisation. The studio added TPN at renewal and set a date. This is the most common case and the tightest one, because the deadline was set by someone who does not know what sits inside your operation.
The TPN+ registry is where content owners search for vendors. Being visible there, with a shield, puts your company on a shortlist that is currently being drawn up without you. It is the one reason on this page that does not begin with a requirement: it begins with sales.
Plenty of companies answer the questionnaire, publish the Blue shield and consider the matter settled. When the customer asks for evidence reviewed by a third party, they discover Blue is self-declared, and that the optimistic answer given months ago is now the yardstick the assessor will measure against.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
Dubbing and subtitling
The company filled the questionnaire in on its own, marked nearly every question as met and published the Blue shield. Months later a customer asked for an evidence-based assessment. Opening those answers to brief the assessor, much of it had no document behind it: the practice existed, the record did not.
We went back through the questionnaire item by item, refusing to accept any answer without evidence attached. Where the control genuinely existed, we organised the proof. Where it did not, it became a plan with an owner and a date. And we made clear to the board which answers would have to change meaning on republication.
The assessment ran against answers that held up, with no scene of an assessor discovering the gap. The heavier work was filing rather than technology: almost everything missing was proof of something already being done.
Post-production and finishing
Customer material moved across the same network as email and the back-office system, and the finishing workstation had unrestricted internet access. There were cameras at the door and a visitor log on paper, so the internal perception was that physical security was handled and the problem lay elsewhere.
We separated the production network from the rest, with explicit rules on what may leave and where to. We dealt with removable media, which was the real route content took out, and reviewed access to the suites by function rather than by person. The physical side gained records, because a camera with no retention and nobody reviewing it is not evidence.
The scope came out smaller than the company feared. Isolating production from the back office meant half the controls stopped applying to the whole environment and applied only where content actually lives.
Content distribution and delivery
The company prepared its facilities carefully and forgot the web application customers used to send and download material. Because the portal was an old internal system, nobody treated it as part of the content environment, and it had never been tested.
We brought the portal into scope and ran a penetration test on the application before any assessment. We found broken access control between different customer accounts, fixed it, and only then added the application to the platform profile.
The failure that mattered most was not in the building, it was at the login. Fixed before the assessment started, it never became a public remediation item or a conversation with the studio.
SELF-ASSESSMENT
The first three questions classify your case: what your customer asked for, what you deliver and where content is worked on. The rest walk through the topics the Best Practices cover. The full result appears on screen, with a score for each topic and an honest read on what does not yet hold up. We do not ask for your email to show it.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
Without a map of the path content takes and without someone who answers for it, there is no way to say what enters the assessment or who decides what is acceptable. It is the gap that blocks all the others, because every topic below depends on knowing where the material is. The first step costs an afternoon: sit down with production, IT and coordination and draw on a board where content enters, where it is worked on, where it is stored and where it leaves, including the homes of people working remotely. The drawing becomes the list of facilities and applications that are candidates for the scope, and it is what a first conversation with an assessor will ask for.
50 to 79
The map exists in people's heads, which works right up to the day that person is on holiday or the cloud arrived after the last drawing. In practice that means the answer about where content is changes depending on who answers, and that divergence is what surfaces in the assessor's interview. What usually goes missing is the update after changes nobody treated as a security change: a new portal, a customer who started sending material another way, a team that started working from home. Set a simple trigger, review the map whenever a new customer or a new tool arrives, and put in writing who has the final word when production and security disagree.
80 or above
The path content takes is mapped and someone answers for it with real authority, which is the position a defensible scope comes from. What separates this band from what the assessor expects is the justification for exclusions: for every facility or application left out, you have to be able to explain why customer content does not pass through there. The concrete next step is to write that out-of-scope list with a line of reasoning on each item, before engaging an assessment. It is the document that avoids the worst surprise in this band, which is the scope growing after the budget was closed.
Below 50
Without physical separation between production and the rest of the company, practically every digital control you install lives next to an open door. In a studio that is concrete: someone from the back office cuts through the edit suite, a visitor waits sitting where a screen is on, talent walks around with a phone in hand. Start with the demarcation, even a simple one: define which rooms are content areas, who is authorised to enter each one, and lock what is still unlocked. After that, individual badges and an authorised list kept by a named person already cover most of what gets asked here.
50 to 79
There is a door, a key and probably a camera, and what is missing is the discipline around them: the key that circulates, the informal exception for talent and for the customer, the recording nobody reviews and whose retention period nobody knows. It is the most frequent finding in this band, and the assessor reaches it by asking what happens when a famous actor arrives late and the session is already set up. Face the exception head on: write the rule with the exception inside it, saying who authorises it and where it is recorded, rather than keeping a rule everyone knows gets broken. Set the retention period for the footage too, and name who reviews the entry log, even if only by monthly sampling.
80 or above
The physical side is among your strengths, and it is what impresses most on an assessor's on-site visit. In this band the risk stops being the control and becomes the proof that it operates every day: an authorised list with the date of its last review, a visitor log someone signed, evidence that the footage review actually happened. Pull together a folder with three months of those records now, because that is exactly what will be asked for and it is what tends to exist on loose paper. It is also worth checking whether new areas, a storage room set up in a hurry or an extra suite rented for a busy stretch, came under the same rule.
Below 50
This is the topic where the industry diverges most from what the Best Practices assume, because half the work passes through freelancers, talent and partner studios with no employment tie. A low score here means outside people touch content with nothing signed, and that their access depends on someone remembering to close it. The quickest win is a short confidentiality agreement, specific to content, signed before the first access, with the file kept somewhere you can find in thirty seconds. Next comes the offboarding checklist, which is the test the assessor runs on their own: they ask for the list of people who worked in recent months and check whether the access is still live.
50 to 79
The pieces exist for people on the payroll and fail exactly where the volume is: the freelancer, the outside artist and the partner who received material to make the deadline. The classic symptom is access left live after the project and the borrowed drive nobody asked back. Tie the closing of access to the end of the work rather than to someone's memory, with a named owner and a record of the day it was done. On the partner side, the next step is knowing where the material went: a simple spreadsheet of what left, to whom and when already answers the question that today would go unanswered.
80 or above
The people cycle is covered, including for those not on the payroll, and that is rare in this industry. What tends to be missing in this band is the reassessment of those already inside: the partner assessed once on the way in and never again, the recurring freelancer whose agreement is two years old. Set a re-check cadence for the partners who receive material often, and deal with chained subcontracting, which is when your partner passes work on to someone else without telling you. A clause forbidding onward transfer without written authorisation settles in the contract what would be impossible to discover later.
Below 50
Production and back office on the same network is the finding that alarms a content owner most, because it means one click on the wrong email reaches the workstation where the master is open. A low score here usually comes alongside shared accounts in the suites, the other item that surfaces quickly in a review. The order by return is well known: separate the production network with an explicit rule on what may leave and where to, then end the shared login, then turn on two-step authentication for remote access and administrative accounts. None of the three depends on a large purchase, and all three change the conversation with the assessor more than any document.
50 to 79
There is some separation and what is missing is the rule that makes it useful: the VLAN is there, but the finishing workstation browses freely, or two-step exists on email and not on remote access. Worth remembering that this topic has only two questions in the diagnostic, so your score says less than in the others, and a full read of the environment means looking at what the questionnaire left out: patching, workstation updates and whatever runs in the cloud. The concrete step is to write the egress rule for the production network, saying which destinations are allowed, and to review who has access to what by function rather than by person. A scan of the production environment shows, in order of severity, what this questionnaire did not ask about.
80 or above
The digital base is in place, and in this band what decides things is the exception: the old workstation that will not take the policy, the service account for the render system, the supplier with permanent access who came in once and stayed. A documented exception with a compensating measure holds up in a review; an exception nobody mapped is what turns into a finding. List your exceptions now, with the reason and what compensates each one, while the subject is still yours. Because the diagnostic covers little of this topic, consider a technical test of the production environment before the assessment, since that is what confirms whether the design on paper is what is actually running.
Below 50
Not knowing how many copies of a title exist is the most expensive gap in this diagnostic, because it is the one that prevents any promise to the customer about return and destruction. In post and finishing copies multiply on their own: the proxy, an old render, a backup version, the editor's personal folder, the drive that went home for a weekend. Start with a survey of where content is today, storage by storage and machine by machine, and delete what should no longer exist before trying to control what stays. Only then is it worth setting up the media in and out log and locking the cabinet, because controlling new flow with an unknown stock underneath does not solve the problem.
50 to 79
You know where the master is and would lose count of the working copies, which is precisely what the studio's contract tends to cover. The other symptom in this band is disposal by disk space: you delete when the storage fills up rather than when the agreed deadline expires, with no record at all of what went. Holding material past the deadline is a breach of contract even when nobody complains, and it is one of the few things here that a decision solves rather than an investment. Set the deadline per customer or per project, put an expiry date alongside the project when it is opened, and record the disposal with what was deleted and by whom.
80 or above
Copy and media control is mature, which is uncommon and worth showing the assessor in an organised way rather than letting them discover it. In this band the point of attention is the edge: the old backup on tape or in cold storage that never enters the periodic review, and material from a closed project kept as internal reference without the customer knowing. Review the retention policy against what the contracts actually require, customer by customer, because a single rule tends to be more generous than the strictest contract allows. Keep the destruction evidence with the closure of each project, rather than in a separate folder, so the proof shows up when that project is sampled.
Below 50
With no official route for sending and receiving, content leaves by whatever is closest to hand under deadline pressure: a public link, a personal cloud account, a messaging app. It is the industry's most common leak route and the hardest to reconstruct afterwards, because no record of who downloaded is left behind. Choose a single route, with access control and download logging, and treat adoption as a production problem rather than an IT one: if the official route is slower than the shortcut, the shortcut wins. Until the route exists, avoid publishing a favourable answer on this topic, because it is the item the assessor tests by asking to see the history of a recent send.
50 to 79
The official tool exists and production uses another one when the deadline bites, which is the honest answer from most studios and also the finding that comes up most. Look into the shortcuts before banning them: there is nearly always a real reason, file size, a customer who insists on their own portal, a reviewer who cannot install anything. The concrete step is to close the list of permitted routes, including the portals customers impose, and switch off whatever is left. In parallel, turn on per-recipient identification and expiry on sends of working copies, which is what lets you find where a leak came from when material shows up where it should not.
80 or above
Delivery is under control, and this is the topic where a high score protects the relationship with the studio most, because it is where the damage would be public. What tends to slip in this band is the application itself: the portal your customer sends and collects material through is an element with its own assessment, and it has almost never been through a technical test. A penetration test on that application before the assessment is the best return on investment from your position, because broken access control between different customer accounts is the most common serious finding and it shows up in no questionnaire. Fixed beforehand, it never becomes a remediation item visible to the people assessing you.
Below 50
Without a written plan, the first decision after a leak is taken in a panic, by whoever is available, and it is usually the wrong one: wiping traces, telling people late, or telling the customer before you know what happened. The plan does not have to be long. It has to say who is called, who decides, what is preserved before anything is touched, and how long you have before the customer is told. That deadline is not yours to choose: go to your customers' contracts and read the notification clause, because that is what rules and it tends to be shorter than any internal process could carry. Two pages written this week are worth more than a complete plan six months from now.
50 to 79
There is an IT plan and it covers a system being down, not customer content out on the internet, which is an incident with a contractual clock running and communication going outside. If the plan has never been rehearsed, it is still a hypothesis: on paper everyone knows what they do, and in practice nobody knows who calls the studio at eleven on a Friday night. The next step is a two-hour tabletop with the people who really decide, the board, production and IT, on a concrete scenario from your business: an unreleased episode turns up in a messaging group before the premiere. Record what got stuck and adjust the plan with what came out, because that record is what turns the plan into evidence.
80 or above
A written and rehearsed plan is the topic where fewest companies in this industry get where you got, and it is what reassures a content owner most, because what they fear is not you making a mistake, it is you hiding it. In this band the value is in keeping the cycle alive: every incident or near incident should change something, a control, a runbook or a piece of training. Keep the record of the last exercise with its date and the adjustments applied afterwards, because that is the question that closes the interview. It is also worth aligning the plan with the notification deadlines of each new contract that comes in, since every studio writes its own differently.
HOW WE RUN IT
Order matters here more than on any other standard on this site, for one specific reason: much of the process is visible to content owners while it happens. A completed questionnaire, a published report and an open remediation plan all show up for the people assessing you. So preparation comes before publication, not after.
We map where customer content actually moves, which is rarely only where the company assumes. We define the sites and applications entering the assessment, separate the production environment from the back office wherever we can, and translate the Best Practices into the kind of service your company delivers.
A map of where content enters, is handled, is stored and leaves
Sites and applications defined in scope, with each exclusion justified
The target shield defined, and what it demands in each case
The Best Practices read against your specific service
Delivery milestoneScope approved by the board, with the assessment cost already sized with the assessor.
We answer the questionnaire internally, item by item, accepting no answer without evidence attached. This is the opposite of filling it in quickly to publish Blue: here the optimistic answer is the problem, because it becomes visible and turns into the yardstick the assessor will later check evidence against.
The questionnaire answered with evidence attached to every item
Gaps listed in order of risk to the content
A plan with an owner and a date for each gap
A recommendation on what to publish now and what to hold
Delivery milestoneNo answer marked as met without a document standing behind it.
We implement alongside your team, and the two fronts run together. On the physical and organisational side: access, removable media, visitors, logging and network segregation. On the application side: penetration testing of the applications in scope, with fixes verified before the assessor arrives rather than after.
Segregation between the production and back-office environments
Access control, removable media handling and logging implemented
Penetration testing of the in-scope applications, with a retest
An evidence repository organised the way the assessor expects
Delivery milestoneHigh-risk gaps closed and verified, with the evidence filed.
You choose the accredited assessor on the platform and they scope and price the work. We stay on your side through the assessment, prepare whoever will be interviewed and organise whatever is requested. Once the report is published, we drive the remediation plan through to closure, which is what separates Silver from Gold.
The team prepared for the assessor's interviews
Support throughout the assessment
A structured remediation plan with realistic dates
The closure of each item driven through to TPN's review
Delivery milestoneReport published, and remediation items closed and reviewed.
HOW LONG IT TAKES
That is the reference the official guide gives for a first site or application shield, and it is an honest starting point. We do not publish a timeline of our own, because a published timeline turns into a promise, and the variation here is wide. What follows are the three factors that move the clock most, and the first conversation already shows which one your company is in.
One site and one application is one project. Four facilities and a portal with integrations is an entirely different one, and each element carries its own assessment. Scope is the heaviest variable, which is why it is the first thing we settle.
Blue depends only on answering honestly and holding the evidence. Silver adds the assessor's time. Gold depends on actually closing every remediation item, and that is the stretch that most escapes your control, because in some companies it means capital spend and building work.
A company with ISO 27001 in operation arrives with access management, logging, third-party management and incident response already in place, and saves months. What does not carry over is the content-specific part, which is where most projects spend their time.
THE ROLES ARE KEPT APART
The separation here comes from the structure of the programme, not from a choice of ours. The assessment is carried out by a TPN-accredited assessor you select in TPN+, who scopes and prices the work directly with your company. The report is reviewed and published by TPN, and the closure of remediation goes through TPN's review as well. Preparing and assessing are different roles, and mixing them would strip the result of its value for exactly the people who have to read it.
DM11 prepares, implements and supports. It is not an accredited assessor
You choose the assessor inside the platform, and the choice is yours
Membership is contracted by you, directly with TPN
TPN is who publishes the report and reviews the remediation
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No. The official guide states that the assessment and the shields are not an approval, a certification or a pass/fail, and that each content owner makes its own independent, risk-based decision using the result as a baseline. The phrase TPN certification circulates widely, including in vendor material, but it does not describe what the programme delivers. What exists is a shield, and it tells people which stage of the assessment your company has reached.
Blue publishes the answers you gave the questionnaire yourself, with no third-party review. Silver means an accredited assessor reviewed evidence against those answers and had the report published, with a remediation plan supplied by you. Gold means the best practice remediation items were closed and reviewed by TPN. Gold Star adds the closure of the additional recommendations.
It is worth checking which version it was issued against. Earlier versions of the Best Practices carried only two shields, Blue and Gold, and that Gold meant an assessor's report published with a remediation plan, which is what Silver corresponds to today. Since September 2025, on version 5.3.1, Gold requires the remediation closed and reviewed. On validity: Blue should be updated annually, and Silver, Gold and Gold Star are valid for two years from the publication of the report.
Yes. Membership is annual, set by the prior year's gross revenue band, and it is what gives you visibility in the TPN+ registry and the right to complete the assessment on the platform. The assessment cost is separate and agreed with the assessor. The Blue questionnaire is accessible before payment, which lets you use it as a free gap analysis, and that is exactly how we recommend starting: as an internal diagnostic, without publishing.
TPN recommends adding in-house developed and licensed applications to your profile, and recommends an application assessment where one stores, processes or transfers content assets. In practice that reaches the portal your customers use to send and collect material, which is precisely what gets left out when a company thinks only about physical facilities. It is also where we find the most serious issues.
It helps considerably, more than most people expect. Access management, logging and monitoring, third-party management, incident response and the discipline of keeping evidence carry over almost intact. What does not carry over is the content-specific part: how customer material moves, is stored, is copied and leaves your company. That is where the project spends its time, and where ISO 27001 does not reach.
Bring us the contract wording and a list of your facilities. We will tell you what belongs in scope, which shield answers the requirement, and what can be closed before anything becomes visible in the registry.
Comparisons on this subject
See all 13 comparisons