- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Defense, Supply Chain & NIST Catalogue
Microsoft SSPA DPR
The Supplier Security and Privacy Assurance (SSPA) program is Microsoft's own compliance regime for suppliers that handle Microsoft personal data or confidential data.
Each in-scope supplier must complete an annual self-attestation against the Microsoft Data Protection Requirements (DPR), a numbered set of privacy, security, and (since recent versions) AI requirements published by Microsoft Procurement.
Version 10 of the DPR took effect September 23, 2024; later versions have since been issued, with version 12 adding AI-specific requirements and recognizing ISO/IEC 42001 (verify the current version in the SSPA Program Guide).
Suppliers whose data processing role is subprocessor, or who otherwise meet Microsoft's risk criteria, must also obtain an annual independent assessment: an outside assessor validates the self-attestation and issues an unqualified letter of attestation using Microsoft's report template.
Suppliers can substitute certain certifications (for example ISO/IEC 27001 or a SOC 2 Type 2 with matching scope) for parts of the assessment.
In writing, a supplier needs the completed DPR self-attestation in the SSPA portal, policies and procedures that map to each DPR item in scope (notice, choice, retention, subprocessor management, incident notification, encryption, access control, secure development, AI governance where applicable), the data processing profile agreed with Microsoft, and the independent assessor's letter.
Failure to stay green in the SSPA portal blocks purchase orders.
Who has to comply
Microsoft suppliers whose engagement involves processing Microsoft personal data or Microsoft confidential data, as determined by the data processing profile set when the supplier is onboarded. The requirement is contractual under the Microsoft Supplier Data Protection Requirements.
Subprocessors and suppliers handling more sensitive data face the independent assessment requirement; lower-risk suppliers self-attest only.
What the assessor asks to see
Assessors follow the DPR item list: data processing profile and scope; privacy notices and consent handling; data retention and deletion records; subprocessor inventory and contracts; incident and breach notification procedures; access control and authentication; encryption in transit and at rest; vulnerability management and secure development; logging and monitoring; personnel training and background checks; business continuity; AI governance documentation where AI requirements apply; any substitute certifications with scope documents.
Where the requirement sits: Microsoft Supplier Security and Privacy Assurance - Data Protection Requirements (annual attestation)
What AllyMatter does here
Policy and training-acknowledgment layer for the DPR self-attestation.
AllyMatter publishes this site.
Assessors
Who assesses Microsoft SSPA DPR
Independent assessors chosen by the supplier from firms meeting Microsoft's qualification guidance, which points to recognized professional bodies such as the AICPA and IFAC members; in practice CPA firms and established security assessment firms.
Microsoft does not operate a closed assessor list but does publish the assessment report template the assessor must use. scheme-specific. Assessors rely on their professional licensure or recognized security assessment credentials as described in the SSPA Program Guide.
No firm has claimed a Microsoft SSPA DPR assessor listing yet. Claim yours →
Consultants
Who helps with Microsoft SSPA DPR
Privacy and security consultancies, often the advisory arms of CPA firms, help suppliers interpret the DPR, map existing controls, and prepare for the assessment. Engagements are short (weeks) for a self-attestation refresh and one to three months for a first independent assessment.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
Software
Tools for Microsoft SSPA DPR
Tools that name this framework in their own material.
Related reading
- Microsoft SSPA attestation program explainedExplains the data processing profile, the annual self-attestation and when an independent assessment becomes mandatory.Cherry Bekaert
- Microsoft SSPA v12 updates: what suppliers need to knowTracks what changed in the Data Protection Requirements between versions, which is where most suppliers get caught out.Clark Nuber
- What is the Microsoft SSPA program? Guidance for complianceAuditor's walkthrough of enrolment, the 90-day attestation window and the evidence a subprocessor has to produce.Linford & Company
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for Microsoft SSPA DPR
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of Microsoft SSPA DPR in AllyMatter
Approve the policies Microsoft SSPA DPR asks for, keep every version, and record a named acknowledgment from each person who has to read them.