xmodoxmodo

Frameworks · Global standards

Microsoft SSPA

The Supplier Security and Privacy Assurance (SSPA) programme is Microsoft's requirement for suppliers that process Microsoft personal data or confidential data. Suppliers attest to the Microsoft Supplier Data Protection Requirements, which are revised annually. Higher-risk suppliers also provide independent assurance.

Who it applies to

It applies to suppliers and vendors that process personal or confidential data for Microsoft. These range from software and services firms to marketing and staffing providers.

Main requirements

Data protection requirements

Suppliers meet the current version of Microsoft's Data Protection Requirements across management, notice, choice, retention, security and subcontractors.

AI systems

Recent versions consolidate the requirements for suppliers that operate AI systems on Microsoft data.

Assurance

Suppliers self-attest, and provide an independent assessment where Microsoft's risk profile for them requires it.

Renewal

Suppliers attest each year against the version in force.

How xmodo supports it

  • 1

    The requirements are set up as controls with evidence. The version in force is recorded as a field, and the annual renewal is tracked as an evidence expiry date.

  • 2

    Requirements map to ISO/IEC 27001, ISO/IEC 27701 and GDPR, which satisfy most of them.

Related frameworks

Microsoft SSPA shares requirements with the frameworks below. Controls you already run for any of them count towards Microsoft SSPA as well.

Frequently asked questions

Which version of the Data Protection Requirements applies?

The version in force for Microsoft's fiscal year applies, and it is revised annually. xmodo records the version as a structured field and updates the pack when Microsoft publishes the next one.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo