By:
Chris Lippert
October 20th, 2025
Many suppliers working with Microsoft are now required to complete the Microsoft Supplier Data Protection Requirements (MSDPR) Independent Assessment each year to maintain Supplier Security and Privacy Assurance (SSPA) compliance. In practice, we continue to see organizations misinformed about what’s actually required, which often leads to unnecessary costs, re-tests, or delays.
Cybersecurity Assessments | Privacy Assessments
By:
Emily Heintz
October 13th, 2025
The California Consumer Privacy Act (CCPA) is reminiscent of Michael Meyers, Freddie Krueger, or Ghostface in that no matter how many times you think its presence is done, it keeps coming back with more. While privacy professionals have been tracking the slow rulemaking process for some time, the newly approved regulations may have startled others, fittingly just in time for spooky season.
By:
Chris Lippert
May 28th, 2025
In groundbreaking news, it was announced at the CBPR Forum held in Singapore this week that the Global CBPR System will officially go live on June 2nd, 2025.
Cybersecurity Assessments | Payment Card Assessments | Compliance and Certification | Privacy Assessments | Federal Assessments | Crypto and Digital Trust | ISO Certifications | Healthcare Assessments | SOC Examinations
By:
Christian Underkoffler
April 30th, 2025
In today’s complex and constantly evolving regulatory environment, businesses face an ever-growing array of compliance requirements across multiple frameworks ranging from FedRAMP, PCI, ISO, GDPR, and HIPAA, to name a few. Navigating these compliance waters is increasingly challenging, particularly with regards to cybersecurity and data protection. However, there are measures you can take to significantly refine your compliance processes. In this article, we will explore how streamlining all of your compliance efforts with a single trusted provider can not only simplify your processes but also enhance your overall security posture.
By:
Chris Lippert
April 23rd, 2025
Microsoft recently released v11 of their Data Protection Requirements (DPR) for suppliers required to undergo an annual security and privacy assessment through Microsoft’s Supplier Security and Privacy Assurance (SSPA) program. Microsoft DPR v11 went into effect April 2025 and features a total of 67 requirements.
Privacy Assessments | ISO Certifications | ISO 42001
By:
Schellman
September 26th, 2024
Within a few months of their latest update to their Data Protection Requirements (DPR) to address a coding incident (version 9.1), Microsoft released a draft or “pre-read” for their version 10 requirements that will be utilized for its Supplier Security and Privacy Assurance (SSPA) process as of the 2025 fiscal year. Arguably the largest update to the DPR since September 2018, v10’s new mandates address artificial intelligence (AI) and include important references to ISO 42001 that suppliers may want to take advantage of during their next compliance cycle.
By:
Chris Lippert
August 1st, 2024
When Microsoft released version 9 of their Data Protection Requirements (DPR) back in October 2023, the new framework contained several important updates, as well as a few brand new requirements, including the addition of new considerations for suppliers processing protected health information (PHI).
By:
Kathryn Young
April 5th, 2024
Amidst the evolving patchwork of data protection and privacy legislation in the United States, privacy remains a top priority for organizations. But protecting privacy also requires resources, and while not all organizations have that much to spare, it is possible to make do with only a small, dedicated team.