Skip to main content
Meet Microsoft’s Supplier Security and Privacy Assurance requirements.
The Microsoft Supplier Security and Privacy Assurance (SSPA) program sets data protection requirements for suppliers that process Microsoft personal and confidential data. Suppliers must comply with the Microsoft Data Protection Requirements (DPR) and may need an independent assessment.
SSPA compliance is required for vendors and suppliers in Microsoft’s supply chain that handle Microsoft personal or confidential data.

Who needs Microsoft SSPA?

Microsoft suppliers

Any vendor processing Microsoft personal or confidential data as part of a supplier relationship.

Subprocessors

Organizations that process Microsoft data on behalf of a Microsoft supplier.

Key components

Data Protection Requirements

Microsoft’s detailed DPR covering privacy and security obligations.

Data Processing Profile

Defines the type of data processing the supplier performs.

Independent assessment

Higher-risk suppliers require a third-party attestation of compliance.

Annual attestation

Suppliers reconfirm compliance through the SSPA program each year.

How DSALTA helps with Microsoft SSPA

1

Activate Microsoft SSPA

Select Microsoft SSPA from the Frameworks page. DSALTA maps the DPR to controls.
2

Review DPR controls

Review the Microsoft Data Protection Requirements and assign owners.
3

Collect evidence automatically

Connect integrations to gather supporting evidence.
4

Approve policies

Review and approve policies aligned with the DPR.
5

Prepare for attestation

Organize evidence for self-attestation or independent assessment.

Frequently asked questions

Suppliers processing Microsoft personal or confidential data, as determined by their Data Processing Profile.
Not always. Lower-risk processing may qualify for self-attestation, while higher-risk profiles require independent assessment.

How DSALTA automates this

274 of DSALTA’s automated checks contribute evidence to this framework, drawn from 70 integrations. Browse them in the Compliance Tests catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.