> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft SSPA

> Meet Microsoft's Supplier Security and Privacy Assurance requirements.

> Meet Microsoft's Supplier Security and Privacy Assurance requirements.

The Microsoft Supplier Security and Privacy Assurance (SSPA) program sets data protection requirements for suppliers that process Microsoft personal and confidential data. Suppliers must comply with the Microsoft Data Protection Requirements (DPR) and may need an independent assessment.

<Note>
  SSPA compliance is required for vendors and suppliers in Microsoft's supply chain that handle Microsoft personal or confidential data.
</Note>

## Who needs Microsoft SSPA?

<CardGroup cols={2}>
  <Card title="Microsoft suppliers" icon="handshake">
    Any vendor processing Microsoft personal or confidential data as part of a supplier relationship.
  </Card>

  <Card title="Subprocessors" icon="link">
    Organizations that process Microsoft data on behalf of a Microsoft supplier.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Data Protection Requirements" icon="file-shield">
    Microsoft's detailed DPR covering privacy and security obligations.
  </Card>

  <Card title="Data Processing Profile" icon="clipboard-list">
    Defines the type of data processing the supplier performs.
  </Card>

  <Card title="Independent assessment" icon="user-tie">
    Higher-risk suppliers require a third-party attestation of compliance.
  </Card>

  <Card title="Annual attestation" icon="calendar-check">
    Suppliers reconfirm compliance through the SSPA program each year.
  </Card>
</CardGroup>

## How DSALTA helps with Microsoft SSPA

<Steps>
  <Step title="Activate Microsoft SSPA">
    Select Microsoft SSPA from the Frameworks page. DSALTA maps the DPR to controls.
  </Step>

  <Step title="Review DPR controls">
    Review the Microsoft Data Protection Requirements and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather supporting evidence.
  </Step>

  <Step title="Approve policies">
    Review and approve policies aligned with the DPR.
  </Step>

  <Step title="Prepare for attestation">
    Organize evidence for self-attestation or independent assessment.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Who must comply with SSPA?" icon="circle-question">
    Suppliers processing Microsoft personal or confidential data, as determined by their Data Processing Profile.
  </Accordion>

  <Accordion title="Do I always need an independent assessor?" icon="user-tie">
    Not always. Lower-risk processing may qualify for self-attestation, while higher-risk profiles require independent assessment.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
