That security questionnaire from your biggest customer
August 25, 2026
There is a spreadsheet in your inbox. Eighty questions, three tabs, sent by the procurement team at your biggest customer. Back within two weeks, please.
You are not alone. Since the Dutch cybersecurity act took effect in August, organisations in scope also have to secure their supply chain. That is measure four of the ten in the duty of care, and there is only one way for them to act on it: by asking you.
Samen Digitaal Veilig, the initiative run by the Dutch employers' organisations VNO-NCW and MKB-Nederland, estimates that around fifty thousand smaller companies are pulled in this way, against just over ten thousand that fall under the law directly and have to secure their chain, counted slightly more broadly than the eight thousand the NCSC names. Run that ratio through your head and it becomes clear why so many spreadsheets are going around right now.
What is actually being asked
Behind those eighty questions sit about six. They follow your customer's own duty of care, so get those six straight and you can fill in any sheet.
Who can reach what. How many people hold admin rights, how do they lose them when they leave, and is strong authentication in place. This is the question that comes back most often and where most answers hurt.
What happens during an incident. Who calls whom, how fast, and have you ever practised it. An honest "we have one page and we walked through it once" beats a thick plan nobody has read.
Backup and recovery. Not whether you take backups, because everyone says yes. When you last restored one.
What you buy and from whom. Which parties sit behind you. Your customer asks because their own duty of care asks it of them, and from that moment your suppliers are their problem too.
How you know it still holds. A setting that was right last year may be off today. What checks that, and how often. This is measure ten of the duty of care, and the question that most often gets a silence. What that slide looks like in practice is a story of its own.
What you can prove. This is the hard one. Not what your policy says, but evidence with a date on it.
Why the spreadsheet is the problem, not the fix
A completed questionnaire is a photo of one moment. Two weeks later it is already wrong, and nobody sends a correction. At the next customer you start over, because their sheet has different columns. After a year you have five versions of the truth floating around and you no longer know which one was last.
What does work is turning it around. One place that says how things are arranged at your company, that stays current because it is connected to your real environment, and that your customers look at themselves. The large software vendors have worked this way for years. You send a link instead of a file, and that link sits on your own domain.
That saves more than time. It changes the conversation. A page updated today says something different than a spreadsheet you typed up last night.
And there is a certificate for it now
If you would rather have a document than a page: Stichting Kwaliteitsinnovatie runs the NIS2 Supply Chain mark, backed by MKB-Nederland and VNO-NCW. It has three levels. SC10 is the base level for suppliers with a limited risk profile, SC20 covers parties with raised risk because of their role or their access, such as IT service providers, and SC30 is for critical links in the chain.
Whether it is worth it depends on your customers. If one of them asks for a certificate, the answer is easy. If they only want answers, a current page is faster and cheaper.
Where to start
Take the sheet sitting in your inbox and find the ten questions about access, backup and incidents. Answer those honestly, including where the answer is "not yet". That is your baseline right there.
Then put those answers somewhere they can stay and be kept current, rather than in a file that leaves the building. The next customer will ask the same things, only phrased differently.
And do not let the length scare you. Eighty questions look threatening, but six of them matter. The rest are variations.
Sources
All sources were consulted on 8 September 2026. These sources are published in Dutch.
MKB-Nederland. (2024, October 28). Samen Digitaal Veilig lanceert NIS2 Keurmerk. https://www.mkb.nl/artikelen/samen-digitaal-veilig-lanceert-nis2-keurmerk
Nationaal Cyber Security Centrum. (2026). Zorgplicht. https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht
Samen Digitaal Veilig. (2026). Partnernet. https://samendigitaalveilig.nl/partnernet/
Stichting Kwaliteitsinnovatie. (2026). NIS2 Supply Chain Certificering voor Europa. https://www.stichting-kwaliteitsinnovatie.nl/nis2-supply-chain-certificering-voor-europa/
