Skip to main content
Meet Microsoft’s Supplier Security and Privacy Assurance requirements.
The Microsoft Supplier Security and Privacy Assurance (SSPA) program sets data protection requirements for suppliers that process Microsoft personal and confidential data. Suppliers must comply with the Microsoft Data Protection Requirements (DPR) and may need an independent assessment.
SSPA compliance is required for vendors and suppliers in Microsoft’s supply chain that handle Microsoft personal or confidential data.

Who needs Microsoft SSPA?

Microsoft suppliers

Any vendor processing Microsoft personal or confidential data as part of a supplier relationship.

Subprocessors

Organizations that process Microsoft data on behalf of a Microsoft supplier.

Key components

Data Protection Requirements

Microsoft’s detailed DPR covering privacy and security obligations.

Data Processing Profile

Defines the type of data processing the supplier performs.

Independent assessment

Higher-risk suppliers require a third-party attestation of compliance.

Annual attestation

Suppliers reconfirm compliance through the SSPA program each year.

How DSALTA helps with Microsoft SSPA

1

Activate Microsoft SSPA

Select Microsoft SSPA from the Frameworks page. DSALTA maps the DPR to controls.
2

Review DPR controls

Review the Microsoft Data Protection Requirements and assign owners.
3

Collect evidence automatically

Connect integrations to gather supporting evidence.
4

Approve policies

Review and approve policies aligned with the DPR.
5

Prepare for attestation

Organize evidence for self-attestation or independent assessment.

Frequently asked questions

Suppliers processing Microsoft personal or confidential data, as determined by their Data Processing Profile.
Not always. Lower-risk processing may qualify for self-attestation, while higher-risk profiles require independent assessment.