Does Microsoft's SSPA require ISO 42001?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
6 min read
Contents
No. It names ISO 42001 as one of exactly two ways to satisfy a requirement it does make, and that requirement is a great deal more specific than most suppliers realise.
Where this sits
The FY26 SSPA Program Guide version 12, March 2026, and the FY26 Supplier Data Protection Requirements version 12, both linked from microsoft.com/en-us/procurement/sspa.
What is actually required
For a supplier whose profile includes AI Systems, the requirement is stated as:
"Self-attestation of compliance to the DPR, including the AI branch (Section K) and Independent Assurance of compliance against AI branch of DPR (Section K)"
Two routes are given, and only two:
"Complete Independent Assessment against Section K of DPR"
"Submit ISO 42001"
And:
"All suppliers providing AI Systems will be required to provide Independent Assurance options. The ISO 42001 can be offered to validate compliance against Section K of the DPR."
So ISO 42001 is an accepted route, not a mandate. A supplier that would rather commission an independent assessment against Section K directly is doing what the document expressly allows.
The assessor clause, which is easy to misread
The Program Guide sets who may conduct a Section K assessment, and the sentence is a three-part disjunction rather than a single list of qualifications one person must hold at once. The routes it gives are affiliation with the International Federation of Accountants or the American Institute of Certified Public Accountants; or a certified ISO auditor qualified for ISO 27001, ISO 27701 and ISO 42001 where applicable; or certain other certifications.
Read at a glance the middle limb looks like the whole requirement, which would make the bar considerably higher than it is. Read the full sentence in the Guide before you conclude your assessor does or does not qualify.
Section J, which is the one most suppliers hit first
For the security requirements at Section J, a valid ISO 27001 certificate is an acceptable substitute, alongside others including an unqualified SOC 2 report covering security.
This is a buyer's term, not law
Microsoft sets this for its own supply chain. It is a contract condition, and it carries no force outside that relationship.
That distinction matters because there is no UK statute, statutory instrument, procurement policy note or NHS-wide rule requiring ISO 42001, and across a search of the major cloud and enterprise buyers no other buyer-owned public supplier document requiring it was located. Microsoft is currently the exception rather than an example of a trend, which is exactly why it is worth knowing about.
What this does not settle
Two separate attempts by an automated research tool failed to locate these documents, so anyone telling you this is checkable in two minutes is overstating it. The document names are given above. Go to the SSPA page and find them by name rather than by search.
Sources
FY26 SSPA Program Guide v12, March 2026, and FY26 Microsoft Supplier Data Protection Requirements v12, both hosted by Microsoft and linked from microsoft.com/en-us/procurement/sspa. Read at source 3 September 2026 and unchanged as at 10 September 2026.
See the AI Trust Evidence PackAlfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
