Microsoft SDPR Compliance Services

Microsoft SDPR Compliance

Your organization will be required to demonstrate compliance with the Microsoft SDPR before becoming a vendor, and on a yearly basis for existing vendors.

Comprehensive Microsoft SDPR Solutions.

Microsoft SDPR Compliance is a Natural Extension of Our Quality Compliance Services.

If your organization is looking to partner with Microsoft, Auditwerx can help you demonstrate your compliance with the Microsoft Supplier Data Protection Requirements (SDPR) and the Supplier Security & Privacy Assurance (SSPA) program.

Your organization must certify compliance before starting work and recertify on a yearly basis or if the scope of your services changes. 

Learn More About
Microsoft SDPR Compliance

By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy.

Efficient Gap Assessments

For organizations new to compliance or trying to navigate new business processes as they relate to compliance, a readiness assessment/gap engagement will provide the needed guidance to ensure compliance prior to an assessment.

The readiness process identifies any gaps in your controls and allows you to address those gaps before going through your assessment. This can provide efficiencies to the ultimate assessment process and help save time, cost, and avoid unanticipated gaps or expansion of scope.

auditwerx bee headphone icon

Microsoft SDPR FAQ

(Click for More Details)

Do you have questions about the Microsoft SDPR or SSPA? 

The Microsoft Supplier Security and Privacy Assurance (SSPA) Program exists to communicate Microsoft’s data processing instructions to current and potential suppliers. These instructions are referred to as the Microsoft Supplier Data Protection Requirements (SDPR).

The Microsoft Supplier Data Protection Requirements (SDPR) are the standards that Microsoft suppliers must follow in order to securely process, transmit, or store data within the Microsoft ecosystem.

Your organization will need to certify compliance with the Microsoft SDPR ahead of becoming a Microsoft supplier or vendor, and will need to recertify on a yearly basis thereafter.

Your organization may also receive a request to recertify compliance if the scope of your work with Microsoft changes.

  1. Your assessor must offer sufficient technical training and subject knowledge to assess compliance.
  2. Your independent assessor must be affiliated to either the AICPA (like Auditwerx), the IFAC, the ISACA, the IAPP or another relevant security organization.
  3. Your systems will be assessed against the most recent version of the Data Protection Requirements (DPR).
  4. For your initial assessment, the design of your controls will be assessed, and the effectiveness of your controls will be assessed in subsequent evaluations.
  5. The scope of your assessment will need to be limited to the applicable data related to your performance and services.
  6. Your engagement must be limited to the supplier that receives the request to certify compliance, if there is more than one related supplier account, that information must be reflected in the letter of attestation.
  7. The letter of attestation must not indicate any issues in relation to the supplier meeting the DPR. Any issues must be remedied ahead of submitting the letter of attestation.

After joining the Microsoft SSPA program, and certifying compliance with the Data Protection Requirements, additional compliance attestations like PCI DSS may be requested, depending on the scope of data that your organization processes.

Free Download: What You Need to Know About SDPR Compliance

Download our free information on the qualities to look for in a SDPR assessor and how Auditwerx can help support your compliance initiatives.

Fill out this form to receive your free download.

By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy.

Expand Your Knowledge

We use cookies to ensure the best experience. By accessing our site, you agree to our cookie policy.