Microsoft SSPA Reassessment: The 90-Day Deadline Most Suppliers Underestimate

Every year, Microsoft suppliers that handle Personal Data or Microsoft Confidential Data get a familiar email: it's time for SSPA reassessment. And every year, a number of those suppliers underestimate how fast 90 days actually goes.

Here's the quick version of what's at stake. The Supplier Security and Privacy Assurance (SSPA) program requires an annual self-attestation confirming your organization still meets Microsoft's Data Protection Requirements (DPR). You get 90 days from the request to respond. Miss it, and your SSPA status turns Red no more in-scope purchase orders until you're back to Green.

What makes the 90-day window trickier than it sounds:

  1. Your Data Processing Profile (DPP) determines your workload. A supplier that just processes basic data has a lighter lift than one offering SaaS, hosting websites, using subcontractors, or handling payment cards those categories trigger extra assurance obligations.
  2. Some suppliers need independent assessments, not just self-attestation. Higher-risk activities require third-party verification that controls are designed and operating effectively, and that takes longer to arrange than most teams expect.
  3. Evidence collection eats more time than the actual attestation. Pulling together current policies, access control records, and incident response documentation is usually the real bottleneck — not filling out the form itself.
  4. DPP changes mid-year restart the clock. If your services change, you may face reassessment before the annual cycle even comes around.

The suppliers who handle this well aren't scrambling in month three. They're reviewing their DPP, refreshing policies, and keeping evidence organized as a continuous habit rather than an annual scramble.

For a full walkthrough of the process the step-by-step reassessment flow, Green vs Red status explained, and a complete best-practices checklist check out this detailed guide on the Microsoft SSPA reassessment process.

If you're part of a compliance, security, or procurement team working with Microsoft, treat the 90-day window as a checkpoint, not a starting line.