Skip to content

What Microsoft's Supplier Security Assessment Actually Asks (and How to Pass It)

A supplier compliance portal invitation on a laptop screen beside a printed security questionnaire, on a London agency desk

The email that changes everything rarely looks like much. An agency I work with had just agreed a retainer with a division of one of the world's largest technology companies. Contracts were nearly done. Then procurement added one small thing: before the first invoice could be paid, they would need to complete the company's supplier security and privacy programme. A portal invitation followed.

Inside that portal was a questionnaire that assumed the supplier had a privacy officer, a data retention schedule, a subprocessor register and a documented information security programme. The agency had a shared drive and good intentions.

They passed, eventually, and the retainer survived. But the weeks in between were harder than they needed to be, and almost everything that made them hard is predictable. If enterprise contracts are on your roadmap, here is what an assessment like Microsoft's actually involves, and how to walk into it prepared.

What Microsoft's SSPA Programme Actually Is

Microsoft runs a programme called Supplier Security and Privacy Assurance, usually shortened to SSPA. Any supplier that processes Microsoft data, from a marketing agency holding campaign assets to a consultancy touching customer information, has to enrol, declare what data it handles, and demonstrate compliance with Microsoft's Data Protection Requirements, a published set of requirements covering both privacy and security.

Three things about the structure matter more than any individual question.

Your data profile decides your workload. When you enrol, you declare what kind of data you process and how. That profile determines which requirements apply. A supplier that only ever handles anonymised campaign metrics faces a fraction of the requirements of one storing personal data. Scoping honestly, and narrowly, is the single highest-leverage move in the whole process.

It is a privacy assessment as much as a security one. This is what catches technology-literate suppliers off guard. The requirements lean heavily on how you collect, use, retain and delete personal data: notice, consent, data subject rights, retention schedules, subprocessor disclosure. Your firewall does not answer any of those questions. Your policies do.

It is annual, not once. SSPA runs on a yearly cycle. Higher-risk profiles can also be asked for independent verification, an assessment carried out by an approved third party rather than a self-attestation. Whatever you build to pass the first year, you will need it again, every year, kept current.

  • SSPA applies to any supplier processing Microsoft data, and your declared data profile determines how much of it applies to you
  • The Data Protection Requirements cover privacy as heavily as security, which is where technically strong suppliers get caught out
  • The cycle is annual, with independent verification possible for higher-risk profiles, so the evidence you build has to be maintainable, not a one-off performance

What the Requirements Actually Cover

The precise requirements evolve from version to version, but the territory has been stable for years. Expect to answer for yourself across these areas.

Management and accountability. Someone in your business must own privacy and security, and be able to show a written programme: an information security policy, a privacy policy that reflects what you actually do, and evidence that staff are trained on both.

Data handling through its whole life. What data you collect and why, what you tell people about it, how long you keep it, and, the question that stalls more suppliers than any other, how you delete it when the engagement ends and can prove that you did. If you cannot produce a retention schedule, write one before you enrol.

Third parties and subprocessors. Every tool and contractor that touches the client's data is your responsibility. You will be asked to disclose them and show you hold them to equivalent standards. The freelancer with a personal Gmail account in the workflow is a finding waiting to be written up.

Security controls. The technical section covers what any serious assessment covers: access control and multi-factor authentication, encryption in transit and at rest, managed and encrypted devices, patching, logging, incident response with notification commitments, and tested backups. If you have been through Cyber Essentials, you have a head start on this section, though not on the privacy ones.

Incident notification. Enterprises care intensely about how fast you will tell them when something goes wrong. Have a written incident response plan with a notification step, and know the timescale you are committing to before you sign it.

  • Expect questions about ownership, policies and training, not just technology
  • Retention and provable deletion are the most commonly failed requirements in practice
  • Subprocessor disclosure means every tool and freelancer in the workflow, held to your standards
  • The security section rewards the unglamorous basics: MFA, encryption, patching, logging, tested backups

Where Suppliers Actually Fail

Having sat on the supplier side of these assessments, the failures are rarely exotic. The same four patterns account for nearly all of the pain.

Treating it as an IT task. The questionnaire lands with whoever "does computers", who answers the security third confidently and stalls on the privacy two-thirds. Passing needs operations, legal-ish thinking and IT together. In a 15-person company those are the same two people, but the work is still three kinds of work.

Over-claiming. Ticking "yes" to controls you do not have feels efficient right up until the evidence request or the independent assessment. A truthful "no, planned for Q3" with a date is survivable and normal. A "yes" that unravels poisons the whole submission.

Scoping too broadly. Suppliers routinely declare more data handling than they actually do, out of caution, and buy themselves dozens of requirements that need not apply. Precision about what you touch, and deliberately reducing what you touch, is compliance work of the most valuable kind.

Rebuilding from zero every year. The supplier who scrambles in year one and saves nothing scrambles again in year two. The one who builds an evidence pack, policies, control screenshots, subprocessor register, training records, all in one maintained place, turns every subsequent cycle into an afternoon of updates. This is the same evidence pack that answers every other enterprise's questionnaire too, which is the point most suppliers miss.

  • The privacy sections, not the technical ones, are where unprepared suppliers stall
  • Honest gaps with dates pass; confident over-claims fail at the evidence stage
  • Narrow, accurate scoping removes whole sections of the assessment legitimately
  • A maintained evidence pack converts an annual crisis into an annual afternoon

The Microsoft Assessment Is a Template for All of Them

Here is the encouraging part. Microsoft's programme is one of the most structured supplier assessments in the market, and the muscle you build passing it transfers almost entirely. The global brands, the social platforms, the sportswear giants, their questionnaires ask the same questions in different orders: who owns security, where does our data live, who else touches it, how do you delete it, how fast do you tell us when something breaks.

Prepare once, properly, and you stop being a supplier who dreads the portal invitation and become one whose sales team mentions the security posture in pitches. We have watched that shift win agencies enterprise accounts their creative work alone could not close, because the competing bidder was still three weeks into their questionnaire when the deal was awarded.

If a portal invitation is already sitting in your inbox with a deadline attached, our vendor security assessment service exists for exactly that moment: we triage the questionnaire within 48 hours, fix the gaps that would fail, build the evidence pack and stay with you through the follow-up rounds. If you would rather see how ready you are first, start with our free vendor assessment readiness checklist, and if the assessment is pushing you towards certification, our fixed-price Cyber Essentials and ISO 27001 packages put a published number on the next step.

  • Enterprise assessments overlap heavily, so preparation for one is preparation for all of them
  • Assessment readiness is a sales asset: it closes deals while unprepared competitors are still answering questionnaires
  • Start with the readiness checklist, or send us the questionnaire and a deadline and we will take it from there

At Blue Icon IT, we take UK agencies and suppliers through enterprise vendor security assessments, including programmes run by some of the world's largest technology and consumer brands, without losing deals to security review. If a supplier questionnaire is standing between you and a signed contract, get in touch.

#vendor-security-assessment#sspa#supplier-compliance#microsoft#enterprise-clients#agencies#due-diligence#compliance
Marc Dirrenberger

Blue Icon IT Founder & Tech Consultant

Marc helps businesses navigate technology adoption securely and effectively. He focuses on practical IT strategies that drive real business outcomes for SMBs and startups.

Need Help With Your IT Security?

Our CISSP-certified team helps London SMBs and startups build resilient, secure IT infrastructure. Get a free consultation to discuss your needs.

Get in Touch