Filed under: Data Protection Requirements, SSPA Compliance, Technology
April 24, 2025
Protection of sensitive corporate and personal information is a dynamic and paramount business concern. Microsoft has leveraged their Supplier Security and Privacy Assurance (SSPA) program to address these concerns, which intersect with their supplier network.
Microsoft periodically updates the SSPA program, as well as the accompanying Data Protection Requirements (DPR), to ensure data is continually protected against various risks. Microsoft released a revision to this program in April 2025, which resulted in the publishing of version 11 (v11) of the SSPA Program Guide and DPR. As compliance with this program is a major prerequisite to continue doing business with Microsoft — it is vitally important for suppliers to stay current with the changing SSPA requirements.
Clark Nuber has reviewed the v11 Program Guide and DPR, and we have detailed the newly added requirements, removed requirements, and general updates below. At a high level, the security and privacy themes remain the same. Like v10, there are 11 sections in the program, A through K. The number of requirements in v11 has decreased from 70 to 67, with 5 requirements being removed, 2 requirements being added, and several others receiving updates to either the requirement content or the suggested evidence of compliance. The requirements relating to Artificial Intelligence (AI) introduced in v10 were unchanged in this update. Please see our article on Program Update for Version 10 to learn more about these requirements.
Specific observations are detailed below.
Addition and Removal of DPRs
DPR Additions
| Section/Requirement | Requirement Text | Clark Nuber Analysis |
|---|---|---|
| Section G: Subcontractors Requirement #24 | Require the subcontractor to agree in writing to terms no less protective of Microsoft than the terms in supplier’s agreement with Microsoft, including the privacy and data protection terms. | We have observed that suppliers often form agreements with their subcontractors to comply with various requirements in this section, including privacy and data protection. This has previously been implied in this section, but it is now a specific requirement. |
| Section J: Security Requirement #45 | Supplier will verify throughout the hiring and placing process, via voice and visual appearance, the employee they interviewed, hired, and placed in Microsoft is the same person. Address information for the employee must match their banking information and the location for any equipment shipments. | The Evidence of Compliance guidance provided by Microsoft in the DPR is quite prescriptive. To comply with this requirement, the supplier must have the primary Microsoft contact meet with each new employee to ensure that the individual that was interviewed is the same person beginning work. Additionally, the supplier must facilitate regular, real-time audio and video interactions with the employee during normal business hours. Additionally, for all equipment shipments, the supplier must ensure and document that the shipment location is “an actual, livable residence (i.e., not a transshipment point) and matches the address the employee provided for banking services.” |
DPR Removals
| Section/Requirement | Requirement Text | Clark Nuber Analysis |
|---|---|---|
| Section A: Management Requirement #3 | Assign responsibility and accountability for compliance with the DPR to a designated person or group within the company. | The assignment of a designated person to oversee compliance with the AI elements of the SSPA program is reflected in other requirements in Section A, as well as a specific requirement in Section K. |
| Section B: Notice Requirement #8 | When collecting Microsoft Personal Data via a live or recorded voice call, suppliers must be prepared to discuss the applicable data collection, handling, use, and retention practices with Data Subjects. | Our understanding is that this requirement rarely applies to suppliers and is being removed due to low risk. |
| Section G: Subcontractors Requirement #27 | Where Microsoft is a Controller of Microsoft Personal Data, ensure the subcontractor uses Microsoft Personal Data in accordance with a Data Subject’s stated contact preferences. | Contractual requirements for data privacy and protection between a supplier and its subcontractor are now included in the new Requirement #24 (discussed in the Additions section above). |
| Section G: Subcontractors Requirement #29 | Review complaints for indications of any unauthorized or Unlawful Processing of Microsoft Personal Data. | Incident response, including incidents involving subcontractors, are addressed in Section I: Monitoring and Enforcement. |
| Section G: Subcontractors Requirement #32 | Promptly take actions to mitigate any actual or potential harm caused by a subcontractor’s unauthorized or Unlawful Processing of Microsoft Personal and Confidential Data. | This requirement was included in Section G: Subcontractors. Incident response, including those involving subcontractors, is addressed in Section I: Monitoring and Enforcement. |
Updates to Other Requirements
V11 of the SSPA program includes several updates for the purpose of cleaning up language, which are not included below.
Substantive changes to requirements or suggested evidence are listed below:
| v10/v11 Indexing | What does the requirement relate to? | What does the update entail? |
|---|---|---|
| #5/#4 | Applying sanctions against employees for noncompliance with company policies. | Specifically extends requirement to supplier personnel working within the Microsoft corporate environment. |
| #7/#6 | Use of a privacy statement when collecting personal data. | Provides an example of a processing activity that would allow a supplier to use their own privacy statement. |
| #10/#8 | Use of cookies for suppliers that manage or create Microsoft websites or applications. | Removed the requirement to register Microsoft websites in the internal web compliance portal. Also removed the requirement to use a standard banner produced by 1ES. |
| #34/#30 | Maintain an incident response plan that includes notification requirements to Microsoft. | Adds a requirement to update contact fields in SupplierWeb in the event of a data incident. |
| #48/#44 | Identity authentication and use of multi-factor identification (MFA) in access management. | Use of a security key is now permitted as a method for MFA. |
SSPA Program Guide Changes
Changes were also made to the SSPA Program Guide. Notable changes are as follows:
- If the supplier is a software as a service (i.e., SaaS) provider, the requirement to have an ISO 27001 certificate has changed from “may be required” if it is specifically mentioned in your Cloud Services Agreement to “will be required”. Microsoft has previously considered specific circumstances for providing a waiver, but the Guide does not specifically address this possibility.
- The Guide now specifically points out that the AI requirements do not apply for companies that are using Copilot or another “third-party AI that you do not publish”. Previously, this was shared with the assessor community, but not specifically codified in the Guide.
- In the case where a supplier has an ISO 27001 certificate, this certificate can be used in place of testing performed by an independent assessor over requirements in Section J. Several years ago, a previous version of the SSPA program allowed for the use of an SOC 2 report covering Security as a substitute as well. The Guide now mentions that an SOC 2 with security “may be” accepted for Section J, when no qualifications are noted. The Guide does not define qualifications. That could mean an issue that rises to a level of a “qualified opinion”, which is rare. It could also mean any deviations noted in the testing of an SOC 2, which is more common. This will have to be adjudicated through the SSPA compliance process. Regardless, this is a positive sign as many of our clients have an SOC 2 report but do not have an ISO 27001.
- In a case where multiple supplier IDs are included in a single letter of attestation, the revised Guide says the letter needs to include a list of supplier accounts included in the assessment, which has always been required. While the previous Guide stated that associated addresses need to be included, the revised Guide removes this address requirement, which will simplify the reporting process.
If you have any questions about these updates or any of the other SSPA literature, please contact us at sspa@clarknuber.com, and we would be happy to continue this conversation.
© Clark Nuber PS, 2025. All Rights Reserved.


