Attestation · Last verified

Supplier Security & Privacy Assurance Program

Microsoft SSPA is Microsoft's own supplier compliance program, not a portable certificate — suppliers self-attest annually to its Data Protection Requirements. It is Microsoft's internal supplier-compliance record, tracked as Green (compliant) or Red (noncompliant) — not a public credential another buyer can look up.

Class
Attestation
Owner
Microsoft Corporation — a partnership of Microsoft Procurement, Corporate External and Legal Affairs, Corporate Security, and the Office of Responsible AI
Last verified

What it is

"The Supplier Security and Privacy Assurance (SSPA) Program delivers Microsoft's data processing instructions, through the Microsoft Supplier Data Protection Requirements (DPR), to suppliers working with Personal Data, Microsoft Confidential Data, and AI Systems." — Microsoft SSPA program page.

"The scope of SSPA covers all suppliers globally that process Personal Data and/or Microsoft Confidential Data." — Microsoft Learn, Supplier Security and Privacy Assurance Program.

The requirement set is called the Microsoft Supplier Data Protection Requirements (DPR); the specific requirements that apply to a given supplier depend on that supplier's declared Data Processing Profile.

"All enrolled suppliers must complete an annual self-attestation of DPR compliance." — Microsoft Learn, Supplier Security and Privacy Assurance Program.

"Suppliers that are on a published Microsoft subprocessor list must also provide independent verification of compliance." — Microsoft Learn, Supplier Security and Privacy Assurance Program.

A supplier that misses the 90-day window to complete a requested self-attestation moves to Red status, and Microsoft's purchasing systems stop processing new orders for that supplier until status returns to Green.

A SaaS supplier may need to provide a valid ISO 27001 certificate — but only "if this is required in the Microsoft Cloud Services Agreement" with that supplier; the requirement is contract-conditional, not a blanket SSPA rule.

Who owns it

Microsoft Corporation, run as a partnership between Microsoft Procurement, Corporate External and Legal Affairs, Corporate Security, and the Office of Responsible AI.

Who assesses it

Most suppliers self-attest their own DPR compliance annually.

Where an independent assessment is required (for example, suppliers with a Subprocessor data-processing role, who must have an Independent Assessment conducted annually and cannot change this by updating their Data Processing Profile), the supplier selects an assessor that meets Microsoft's published criteria: "Assessors must be affiliated with the International Federation of Accountants (IFAC) or the American Institute of Certified Public Accountants (AICPA); a certified ISO auditor qualified for ISO 27001, ISO 27701, and ISO 42001 where applicable; or must possess certifications from other relevant privacy and security organizations, such as the International Association of Privacy Professionals (IAPP) or the Information Systems Audit and Control Association (ISACA)." Microsoft also publishes a Preferred Assessors list; a supplier is free to choose any assessor meeting the criteria above, and the assessor's fee is paid by the supplier.

SSPA compliance status

  • Green — Supplier is compliant with its DPR obligations; Microsoft procurement systems process new orders normally.
  • Red — Supplier is noncompliant (including missing the 90-day window to complete a requested self-attestation); Microsoft's purchasing systems do not process new orders while status is Red.

Who asks for it

Buyer-driven. Not a legal or public-procurement requirement. It becomes a de facto condition of doing business with Microsoft the moment a supplier processes Personal Data, Microsoft Confidential Data, or uses AI Systems in connection with its performance for Microsoft — the trigger is the commercial relationship, not a statute.

Microsoft, for its own suppliers that process Personal Data, Microsoft Confidential Data, or use AI Systems in their work for Microsoft.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Supplier Security & Privacy Assurance Program." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/microsoft-sspa

All frameworks & audits →