Privacy Assessments
Microsoft’s SSPA program requires vendors that process Microsoft personal and/or confidential information to comply with Microsoft’s Data Protection Requirements (DPR) on an annual basis.
If your organization is a current or aspiring Microsoft vendor, you’re probably familiar with the Microsoft Supplier Security and Privacy Assurance (SSPA) program (previously called the Vendor Privacy Assurance Program). You might be wondering what this requirement means for your business and what to expect during a Microsoft Data Protection Requirements (MS DPR) assessment.
Microsoft provisions suppliers with an account in their supplier management portal, Aravo. The Aravo portal is where the supplier will manage their compliance tasks, including completing the self-assessment. Suppliers have a 90-day window to enroll in or renew their participation in the SSPA program, set their profile, and complete their self- and independent assessments for Microsoft’s approval before they are placed in a “red status” with Microsoft. It’s imperative that the supplier responds to the profile queries and self-assessment as accurately as possible for the services provided to Microsoft to avoid any delays in the SSPA process. Regardless of whether an independent review is needed, suppliers should adjust their controls to comply with the requirements and retain documentation evidencing their conformance. Microsoft ultimately determines whether the supplier requires an independent third-party assessment based on the supplier’s responses to their self-assessment.
If your organization is subject to other types of IT audits, discuss the option of combining the Microsoft DPR attestation with other audits or assessments to determine if there is an overlap in testing efforts or documentation to ease the burden of multiple audits. When the assessment is complete, you’ll be given a letter of attestation which you can submit to Microsoft via the Aravo portal. If you choose Schellman as an assessor, your auditor can point out areas for improvement and help you identify weaknesses in your current practice to avoid jeopardizing your Microsoft contract.
In this video, Chris Lippert explains the cost for an MS DPR assessment as well as the two primary factors that could influence the price:
Schellman performs each assessment with your end goals and preparation for future key compliance initiatives in mind. Effective communication and timely coordination of project activities are central to our methodology.
The planning phase occurs at least two months in advance of fieldwork in accordance with the timing outlined in the job arrangement letter (JAL) or statement of work (SOW) executed with the client. Planning includes obtaining the approved Aravo profile and self-assessment, confirming timing of interviews with key points of contact, and deployment of and evidence gathering for the information request list provided via AuditSource 2.0. Schellman will be available to the client to answer any questions associated with the assessment to ensure both parties are aligned on scope and expectations.
Schellman will hold a kickoff meeting to start fieldwork. Fieldwork consists of various testing procedures to evidence the requirements are met. The testing procedures may include one of the following:
Schellman has a no surprises policy and regular contact with the client during fieldwork, allowing clients to be apprised at all times of conformance status.
Schellman's assessment is focused on creating a deliverable that is clear, concise, and accurate. The draft report is provided within 2-3 weeks of the last day of fieldwork. The final deliverable is available within 5 business days of the client approving the draft version.
Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.