Knowledge base

September 14, 2026

Tackling a supply chain questionnaire without a compliance team: Don’t start with question one

One Tuesday afternoon, it lands on your desk. The questionnaire from your biggest client—a full Excel sheet—with a request for a response within three weeks. No compliance team, no security officer. Just you, a calendar that’s already full, and pages of jargon you only half understand.

We’re seeing these lists come from more and more sources: administrators receive them from banks and courts, healthcare providers from institutions, and carriers from shippers. Why a small organization receives this request even though the law doesn’t apply to it is explained in our blog about supply chain pressure. The blog post on the “basic file” explains which four documents account for the majority of these requests. This blog post focuses on what happens next: the list is on the table, the clock is ticking—how do you tackle it without getting overwhelmed?

The short answer: treat it like a project, not an exam. The long answer is below, in the order we follow ourselves.

Step One: Read the list; don’t answer it just yet

Most of the panic doesn’t come from the questions themselves. It comes from the idea that you have to start with question one. Don’t do that. First, read through the entire list and answer three questions for yourself: how many questions are there really (duplicate questions and explanations don’t count), what themes does the author address, and which questions are about you and which are about one of your suppliers.

When reading these, almost the same thing stands out. The questions are less unique than they seem. They cluster around the same themes as any other supply chain checklist: policy, access, equipment, continuity, supply chain, and awareness. Anyone who has prepared their answers for each theme can largely answer the second list using the same documents. The first list takes some work. The second takes a morning.

Step Two: Lay your documents out next to it

Only after reading should you start searching—not for answers, but for documents. What’s already available, even if it’s called something else or scattered across emails, a manual, and a procedure someone wrote at some point. A backup provision in the contract with your IT partner is a source. A dated screenshot of the MFA settings is a source. An internal email from two years ago is not.

Most of the items on a supply chain checklist can be addressed with four basic documents; you can read about which ones those are and what they should contain in the blog post about the basic file. Once you have those four, filling out the checklist is just a matter of filling in the blanks. If you don’t have them, each question requires a separate investigation, and that’s exactly where the weeks go.

Step 3: Write down your answers, citing the source for each one

AI can fill out any security questionnaire—fluently, convincingly, and partly made up. That’s why we follow one strict rule when answering: no source means a gap. Every answer references the document excerpt on which it is based. If that’s not possible, we don’t write an answer; instead, we note a gap.

That sounds strict. It’s mainly practical. An auditor will ask for proof, and a made-up “yes”—with your signature underneath—will be immediately exposed. An honest “not yet arranged, planned for November” wins out over a smooth lie with serious clients. Not because they’re lenient, but because they, too, have to demonstrate that their suppliers work safely—and they can explain an honest oversight.

What remains is a list of actions, not a list of leftover items

After step three, you’ll have two piles: answered questions with sources, and gaps. That second pile isn’t a list to be ashamed of. It’s a to-do list with due dates, and you simply send it along. Sorting through the questions, determining for each one whether a source exists, and honestly acknowledging the gaps in the plan—that’s just part of the job. And the response “we have this, we don’t have that yet, and here’s how we’ll fix it” beats a list that looks perfect but lacks evidence.

Then flip it over. That list tells you exactly what your client considers important. Market research, straight from their procurement process, and it’s sent right to you. The supplier with their paperwork in order uses the list as a calling card. This fall, being able to demonstrate compliance isn’t a cost center—it’s a selling point.

The Other List: The Entity Registry

There’s another list, and you might be on it yourself. Organizations subject to the Cybersecurity Act have been required since August 15 to register in the NCSC’s entity registry via mijn.ncsc.nl using eHerkenning. There is no specific deadline: the requirement has been in effect since the law took effect. At the start, fewer than half of the estimated 8,000 to 10,000 organizations required to register had done so.

Registration does not prove compliance. It proves that you know you are subject to the law, and that is the first question a regulator and a major client will ask. If you’re unsure whether you’re subject to it, the RDI’s self-assessment will provide the answer.

First, get a good grasp of the list yourself—for free

You can let a tool handle Step One. Keten-Antwoord reads your questionnaire (Excel, Word, or PDF), counts how many questions there actually are, shows which topics are relevant to your client, and identifies which questions can be answered using the four basic documents. You just upload the list—no need to upload your own documents. Results appear on screen, and you’ll receive a report via email—all for free.

One thing to note up front: the tool doesn’t make anything up. If there’s no supporting document, it will display a gap instead of an answer. This is intentional. A made-up answer will cost you more than an honest gap when you’re asked to provide further details.

How ALTA-ICT helps

The free analysis tells you where you stand. Sometimes that’s enough. Other times, there’s a deadline and you need a helping hand. That’s when we take over: you provide the questionnaire and your documents, we draft a response for each question with a source citation, and you retain control and the final say. Anything that can’t be substantiated is turned into a straightforward action list to help you move forward. Request a quote and send us your list. We operate in accordance with ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024, and therefore also complete these lists for our own clients.

Frequently Asked Questions

Do I have to answer every question before I send the list back?

No. You need to show where you stand. A list of sources for what’s already there and dates for what isn’t yet is more useful to a grader than a list full of “yes” answers without evidence.

Can I use AI to fill in the list?

For reading and organizing information: yes. For writing answers without a source: no. Anything AI writes without an underlying document is a promise with your signature on it.

My client is subject to the law, but I’m not. So why am I getting a list?

Because the law requires organizations to screen their suppliers. So the requirement comes through the contract, not from the government. The blog post on supply chain pressure explains how that works.

What does Keten-Antwoord do with my list?

It reads the list, counts and categorizes the items, and displays the results. You only upload the list—no other documents—and it shows a gap where there is no source. The report is sent to the email address you provide.

Do I need to register with the Entity Registry?

Only if your organization is subject to the Cybersecurity Act. If you’re unsure, complete the RDI self-assessment. Registration has been mandatory since August 15 and has no specific end date.

Conclusion

A supply chain questionnaire is not an exam. It’s a project with a deadline: read, compare your documents to the questions, write your answers citing sources, and include the gaps as an action list. If you work this way, you’ll complete the second list in a morning and use the third as your calling card.

Do you have a list? Upload it to keten.alta-ict.nl and find out how big it really is in just a few minutes. If there’s a deadline, we’ll help you meet it.

Want to know more?

Get in touch
Hero bij de aanpak van een ketenvragenlijst: een kaart met drie stappen, lezen, documenten erlangs en antwoorden met bron.