HomeFrameworksDefense, Supply Chain & NIST CatalogueMicrosoft SSPA DPR

Framework  Defense, Supply Chain & NIST Catalogue

Microsoft SSPA DPR

The Supplier Security and Privacy Assurance (SSPA) program is Microsoft's own compliance regime for suppliers that handle Microsoft personal data or confidential data.

Each in-scope supplier must complete an annual self-attestation against the Microsoft Data Protection Requirements (DPR), a numbered set of privacy, security, and (since recent versions) AI requirements published by Microsoft Procurement.

Version 10 of the DPR took effect September 23, 2024; later versions have since been issued, with version 12 adding AI-specific requirements and recognizing ISO/IEC 42001 (verify the current version in the SSPA Program Guide).

Suppliers whose data processing role is subprocessor, or who otherwise meet Microsoft's risk criteria, must also obtain an annual independent assessment: an outside assessor validates the self-attestation and issues an unqualified letter of attestation using Microsoft's report template.

Suppliers can substitute certain certifications (for example ISO/IEC 27001 or a SOC 2 Type 2 with matching scope) for parts of the assessment.

In writing, a supplier needs the completed DPR self-attestation in the SSPA portal, policies and procedures that map to each DPR item in scope (notice, choice, retention, subprocessor management, incident notification, encryption, access control, secure development, AI governance where applicable), the data processing profile agreed with Microsoft, and the independent assessor's letter.

Failure to stay green in the SSPA portal blocks purchase orders.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedDPR policy set v3by name, on record
Green Status Keptwith AllyMatter
Supply Microsoft the Modern WayEvery DPR-required policy, acknowledged before the attestation
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee on record
Who read which version, and when
03
Hand the assessor the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Microsoft suppliers whose engagement involves processing Microsoft personal data or Microsoft confidential data, as determined by the data processing profile set when the supplier is onboarded. The requirement is contractual under the Microsoft Supplier Data Protection Requirements.

Subprocessors and suppliers handling more sensitive data face the independent assessment requirement; lower-risk suppliers self-attest only.

What the assessor asks to see

Assessors follow the DPR item list: data processing profile and scope; privacy notices and consent handling; data retention and deletion records; subprocessor inventory and contracts; incident and breach notification procedures; access control and authentication; encryption in transit and at rest; vulnerability management and secure development; logging and monitoring; personnel training and background checks; business continuity; AI governance documentation where AI requirements apply; any substitute certifications with scope documents.

Where the requirement sits: Microsoft Supplier Security and Privacy Assurance - Data Protection Requirements (annual attestation)

What AllyMatter does here

Policy and training-acknowledgment layer for the DPR self-attestation.

AllyMatter publishes this site.

Assessors

Who assesses Microsoft SSPA DPR

Independent assessors chosen by the supplier from firms meeting Microsoft's qualification guidance, which points to recognized professional bodies such as the AICPA and IFAC members; in practice CPA firms and established security assessment firms.

Microsoft does not operate a closed assessor list but does publish the assessment report template the assessor must use. scheme-specific. Assessors rely on their professional licensure or recognized security assessment credentials as described in the SSPA Program Guide.

No firm has claimed a Microsoft SSPA DPR assessor listing yet. Claim yours →

Consultants

Who helps with Microsoft SSPA DPR

Privacy and security consultancies, often the advisory arms of CPA firms, help suppliers interpret the DPR, map existing controls, and prepare for the assessment. Engagements are short (weeks) for a self-attestation refresh and one to three months for a first independent assessment.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for Microsoft SSPA DPR

Tools that name this framework in their own material.

Related reading

  1. Microsoft SSPA attestation program explainedExplains the data processing profile, the annual self-attestation and when an independent assessment becomes mandatory.Cherry Bekaert
  2. Microsoft SSPA v12 updates: what suppliers need to knowTracks what changed in the Data Protection Requirements between versions, which is where most suppliers get caught out.Clark Nuber
  3. What is the Microsoft SSPA program? Guidance for complianceAuditor's walkthrough of enrolment, the 90-day attestation window and the evidence a subprocessor has to produce.Linford & Company

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for Microsoft SSPA DPR

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of Microsoft SSPA DPR in AllyMatter

Approve the policies Microsoft SSPA DPR asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.