Frameworks · Global standards
Microsoft SSPA
The Supplier Security and Privacy Assurance (SSPA) programme is Microsoft's requirement for suppliers that process Microsoft personal data or confidential data. Suppliers attest to the Microsoft Supplier Data Protection Requirements, which are revised annually. Higher-risk suppliers also provide independent assurance.
Who it applies to
It applies to suppliers and vendors that process personal or confidential data for Microsoft. These range from software and services firms to marketing and staffing providers.
Main requirements
Data protection requirements
Suppliers meet the current version of Microsoft's Data Protection Requirements across management, notice, choice, retention, security and subcontractors.
AI systems
Recent versions consolidate the requirements for suppliers that operate AI systems on Microsoft data.
Assurance
Suppliers self-attest, and provide an independent assessment where Microsoft's risk profile for them requires it.
Renewal
Suppliers attest each year against the version in force.
How xmodo supports it
- 1
The requirements are set up as controls with evidence. The version in force is recorded as a field, and the annual renewal is tracked as an evidence expiry date.
- 2
Requirements map to ISO/IEC 27001, ISO/IEC 27701 and GDPR, which satisfy most of them.
Related frameworks
Microsoft SSPA shares requirements with the frameworks below. Controls you already run for any of them count towards Microsoft SSPA as well.
Frequently asked questions
Which version of the Data Protection Requirements applies?
The version in force for Microsoft's fiscal year applies, and it is revised annually. xmodo records the version as a structured field and updates the pack when Microsoft publishes the next one.