Udostępnij za pośrednictwem


Get Started in Partner Center for Microsoft 365, Teams, SaaS, and SharePoint apps

Phase Title
Phase 1 Publisher Attestation
Phase 2 Microsoft 365 Certification

Overview of Publisher Attestation and Certification

This document is a step-by-step user guide for partners enrolled in the Microsoft 365 App Compliance program who want to undergo Publisher Attestation and Certification through Partner Center.

Important

SaaS apps require pre-approval by the Microsoft 365 App Compliance team. If your app isn't pre-approved, you won't be able to proceed in Partner Center. To get your SaaS pre-approved, contact appcert@microsoft.com.

Acronyms and definitions

Acronym Definition
PC (Partner Center) A portal for all Microsoft partners. A partner logs in to Partner Center and submits a self-assessment questionnaire. Partner Center for Microsoft 365 App Compliance
ISV Independent Software Vendor. Also known as partner or developer
App Source Catalog of apps
Example Now virtual agent

Publisher Attestation workflow

Home Page : This page is the landing page once a partner logs in to Partner Center.

  1. Select Marketplace Offers.

    Commercial Marketplace in Partner Center

  2. After selecting Marketplace Offers, toggle to Microsoft 365 and Copilot. Select an app from the list to begin the Publisher Attestation process.

    Screenshot showing how to select an app in the Commercial Marketplace.

  3. A navigation bar appears with the option Additional certification info. Select App Compliance.

    Screenshot showing the select app compliance option.

  4. Fill out the self-assessment questionnaire for Publisher Attestation.

    Screenshot showing the Publisher Attestation form.

    Note

    If you have another office app with a published attestation, you can clone the answers for other apps and update as needed. Select Choose the product, then select the app, and choose Clone.

    Clone

    Tip

    You can also use the Import and Export feature to complete the form offline and import it once completed.

    Import Export Feature

  5. Once you complete your attestation, select Submit. The page then shows that your attestation is under review.

    Click Sumbit

    Review is now in progress

Approve and reject scenarios

Here are some approval and rejection scenarios.

Publisher Attestation rejection

If you see a rejection, you can:

  • View the failure report. You receive notification by email. You can view the failure report in Partner Center.
  • Update and resubmit the Publisher Attestation.

Update and resubmit assessment

Publisher attestation approval

Upon approval, you can:

  • Update and resubmit the attestation.
  • View and share the completed Publisher Attestation.
  • Start the Microsoft 365 Certification process.

Update and resubmit

Begin M365 App Certification

Post Publisher Attestation approval

Here's an example of a link in AppSource for a publisher attested app.

Example of completed attestation

Microsoft 365 Certification workflow

  1. Begin the certification process by selecting the checkbox and choosing Submit.

    Start Certification

  2. Fill out the details, upload the relevant documents, and select Submit.

    Initial Submission Initial Submission 2

    The attestation submission appears under review.

    Certificaiton under review

    An analyst requests a revision in case the initial documents aren't sufficient or relevant. The analyst works with the partner to help get the right documents for approval.

    Analyst reviewing submission

    Once the analyst approves the initial document submission, the partner needs to submit the control requirements.

  3. Fill out the details for the control requirement submission, upload the relevant documents, and select Submit.

    Complete Control Requirements Upload Evidence Mark Document for sharing with Admins

  4. Select the checkbox if you would like to share your evidence with IT Admins through Teams Admin Center and Microsoft Admin Center.

    [!IMPORTANT] If you're more comfortable sharing more refined and scrubbed documents instead of the detailed evidence the analysts need, you can upload other documents like reports, cover letters, and a summary of documents. You then mark them to be shared.

Assure control requirements are complete

After you select Submit, the certification submission is under review.

Example of Evidence under review

An analyst requests a revision in case the control requirement documents aren't sufficient or relevant. The analyst works with the partner to help get the right documents for approval.

Evidence needs updating Understand which evidence needs updating Evidence under review

If the submission doesn't satisfy the approval standards, the analyst rejects the submission. The partner can then work with the analyst to provide the relevant information and documents.

Submission rejected

Once all the security standards are met, the analyst approves the submission, and the partner is Microsoft 365 Certified.

Submission approved

Post Certification Approval: Example of Microsoft 365 certification badge in AppSource

Example of Certification badge

Microsoft 365 Renewal workflow

Microsoft 365 Publisher Attestation and Certification Renewal Workflow: Microsoft 365 App Compliance Program now offers an annual renewal process. During this process, app developers can update their existing Publisher Attestation questionnaire and documents required for Microsoft 365 Certification.

Benefits:

  • Maintain your certification badge in AppSource, the Teams Store, the Office Store, and other storefronts to differentiate the app.
  • Increase customer confidence in using your certified app.
  • Help IT admins make informed decisions with updated certification information.

The renewal process is available in Partner Center to provide a seamless experience. A renewal reminder appears in Partner Center, starting 90 days before the expiration date. You also receive periodic reminders by email at 90, 60, and 30 days before expiration.

Phase 1: Publisher Attestation Renewal:

The new renewal process is available in Partner Center to provide a seamless experience. A renewal reminder is shown in Partner Center starting 90 days before the expiration date. You also receive periodic reminders by email at 90, 60, and 30 days before expiration.

Step 1: Select Renew to renew the Publisher Attestation.

Microsoft 365 Publisher Attestation and Certification Renewal Workflow

Step 2: Review the previous Publisher Attestation answers and update with the latest information as needed. Submit Publisher Attestation for renewal when ready. A Microsoft 365 app compliance analyst reviews it.

Update the Publisher Attestation

Publisher Attestation Renewal Approved

Publisher Attestation Renewed

Publisher Attestation Expired: The app’s information needs to be renewed before the expiration date to maintain the app’s Publisher Attestation page on the Microsoft docs. Timely renewal also ensures continued badging and icons for the app in AppSource, Teams Store, Office Store, and other storefronts.

Publisher Attestation Expired

Note: Once expired, Publisher Attestation renewal process can be started anytime by clicking Renew.

Phase 2: Microsoft 365 Certification Renewal

The app’s certification information needs to be resubmitted on an annual basis. It requires revalidation of the in-scope controls of your current environment. When the Certification nears the one-year mark, an email notification is sent encouraging a resubmission of the documents and evidence.

Certification Renewal

Certification Renewal Approve/Reject Scenarios:

Scenario 1:

Certification renewal is started and under review.

Certification Renewal under review

Scenario 1A:

Certification renewal rejection: Certification might be rejected if:

  • The app doesn't have the required tooling, processes, or configurations in place and isn't able to implement required changes within the certification window.
  • The app has outstanding vulnerabilities in place and can't be fixed within the certification window.

Certification Rejection

Scenario 1B:

Certification renewal is approved

Certification Renewal Approved

Certification Expiration:

The app’s information needs to be renewed before the expiration date to maintain app’s Certification page on the Microsoft docs. Timely renewal also ensures continued badging and icons for the app in AppSource, Teams Store, Office Store, and other storefronts.

Certification Renewal Expired

Note: Once expired, Publisher Attestation and Certification process can be started anytime by clicking Renew.