Article 50 applies 2 Aug 2026 EU AI Act transparency rules were not deferred by the Omnibus, and are not limited to high-risk systems. What it requires →
DPR v12 · Live 30 March 2026 · 63 requirements · Section K = AI Systems

Microsoft SSPA DPR v12: ISO 42001 mandatory for Sensitive Use AI

Microsoft's Supplier Security & Privacy Assurance (SSPA) Data Protection Requirements v12 accepts ISO/IEC 42001 in lieu of an independent Section K assessment for general AI services, and requires ISO 42001 certification for suppliers delivering "Sensitive Use" AI. For Microsoft suppliers in scope, this is the most consequential AI governance development of 2026.

What changed in DPR v12

Four material changes from v11 to v12

Microsoft released SSPA DPR v12 on 30 March 2026. The changes most relevant to AI suppliers are:

  1. Consolidated requirement set: 63 requirements (down from v11's 67). Three requirements removed, three consolidated, two added (one on networking security, one on prohibited AI uses).
  2. Section K (AI Systems): 18 requirements, 15 of which were updated in v12. Section K is the core AI governance section that ISO 42001 satisfies.
  3. Publisher vs Deployer supplier profiles. v12 distinguishes suppliers who provide AI capabilities to Microsoft customers ("Publishers") from those who deploy AI internally on Microsoft-furnished data ("Deployers"). The obligations differ materially.
  4. ISO 27001 tightened for SaaS suppliers. The requirement changed from "may be required" to "will be required" for SaaS providers, reinforcing Microsoft's consolidation on ISO certifications as the assurance baseline.

Two compliance pathways, and one mandate

For AI Systems in scope of Section K, Microsoft suppliers have two options:

For "Sensitive Use" AI: ISO 42001 is mandatory

Microsoft defines Sensitive Use AI as systems whose reasonably foreseeable use or misuse could affect an individual through consequential impact on legal position or life opportunities, physical or psychological harm, or significant impact on human rights. Examples include AI in hiring, credit, insurance, healthcare diagnosis, law enforcement, education access, public benefits, and biometric identification.

For suppliers delivering Sensitive Use AI services, Microsoft removes the choice, ISO 42001 certification is required. Option A is not available. This is the strongest signal yet that Microsoft has operationalised ISO 42001 as the de facto AI governance standard in its supply chain.

What this means in dollar terms

An Independent Assessment of Section K by a Microsoft Preferred Assessor typically runs $15,000–$30,000 per annual cycle. An ISO 42001 certification covers the same Section K obligation, plus enterprise customer questionnaire responses, plus EU AI Act readiness alignment, for a comparable or lower total cost over a 3-year cycle. For Sensitive Use AI suppliers, ISO 42001 is not a cost saving, it's the only path.

How the Professional tier's SSPA mapping works

The Professional tier includes PRO-SSPA_Section_K_Mapping.docx, a dedicated artefact that maps every Section K requirement in DPR v12 to the corresponding ISO 42001 clauses, Annex A controls, and toolkit evidence locations. The mapping document is structured in three columns:

Who this matters for

If your organisation is a Microsoft supplier, meaning Microsoft is a direct customer, or you provide services that process Microsoft-furnished data or deliver AI capabilities into Microsoft-managed workflows, SSPA is a contractual obligation. Attestation cycles happen annually; failures can put contracts at risk.

Typical SSPA-relevant suppliers include: SaaS providers integrated with Microsoft 365, Copilot, or Power Platform; ISVs in the Microsoft Cloud Partner Program; outsourcing / BPO providers processing Microsoft customer data; consultancies providing AI-implementation services where Microsoft data is in scope.

Our recommendation

For SSPA-bound suppliers:

  1. Start with the Professional tier ($697). You need the SSPA Section K mapping and the full Annex A deep-dives.
  2. Use the Four-Way Crosswalk to identify which existing ISO 27001 controls cover which SSPA requirements indirectly, this typically halves the new-documentation workload.
  3. Plan for actual ISO 42001 certification within 12 months if Microsoft is a material revenue source. The certificate itself is the cleanest evidence artefact for Section K's independent-assessment requirement.

SSPA DPR revisions are Microsoft's to issue. The v12 details above reflect Microsoft's public documentation as of the toolkit's April 2026 edition. Always verify against the current DPR text at the Microsoft SSPA portal. The toolkit's 24-month update window covers material DPR revisions.