Do I have to follow the Microsoft SDL Process Guidance exactly in order to be SDL compliant?
Organizations can be compliant with the SDL if they follow the Simplified Implementation of the Microsoft SDL. This paper helps organizations understand the core concepts of the Microsoft SDL and the individual security activities that should be performed. The SDL Process guidance shares the way Microsoft applies the SDL to its own products. Organizations wishing to know more details about how Microsoft has applied the SDL are encouraged to download the process guidance as a supplement to the Simplified SDL.