Knowledge base

August 27, 2026

The Four Documents That Help a Small Organization Handle Any Supply Chain Challenge

“We’re not covered by that law, are we?” said the owner of an estate administration firm. And he was right: his firm isn’t mentioned anywhere in the Cybersecurity Act. So we took a closer look at his work. Clients’ BSNs, complete financial records, municipalities as clients. And since the law took effect, those municipalities have been required to vet their suppliers.

The law doesn’t apply to him, but the questions still come: from the municipality, from the auditor who reports to the court annually, and from every supply chain partner who must demonstrate that their suppliers operate safely. There’s no such thing as “too small for the law.” There’s no such thing as “too small” when it comes to the questions. You can read about why that’s the case in our earlier blog post on supply chain pressure; this blog post is about the solution.

Specifically: the four documents a small organization needs, the six topics every auditor will ask about, how to answer a questionnaire with evidence rather than promises, and why you don’t need to buy the most expensive package to do so.

The four documents

A small organization usually doesn’t need more than four documents to get through the first round of questions from a municipality or an accountant. An information security policy: what to protect and how. User guidelines for IT resources: what employees are and aren’t allowed to do. An incident response plan: who does what when things go wrong. And a data breach procedure: when and how to report it. Four documents, not tomes; each can fit on a few sheets of A4 paper, as long as it includes a date and a designated person in charge.

And here’s the tip we give every client before we bill them: check with your trade association first. For administrators, healthcare providers, and many other sectors, there are standard documents that you can adapt to your own organization. The wheel has often already been invented. Whatever is still missing or needs to be technically verified after that is a job for your IT partner. But don’t start paying for something you can get for free.

Six themes, one question

Every security assessment we conduct covers the same six areas: policy, access, devices, continuity, supply chain, and awareness. And for each theme, we ask the same question: Can you prove it in writing? That’s exactly what happened recently at a financial services firm. Is MFA enabled? Yes. Can it be proven? No. Is the backup running? Yes. Is the recovery test documented with the date and result? No. Data processing agreements? Partially, scattered across email inboxes.

That’s not a bad score; it’s the normal score. Almost every organization does more than it can demonstrate. But an accountant won’t accept a verbal answer, and neither will a municipality. The good news: the gap between doing and demonstrating is usually a minor task. Documenting what already exists takes days. Building what isn’t there takes months. Most small organizations only need to do the former.

Answering the questionnaire: cite the source for each answer

When the questionnaire is received, there’s one rule: every answer must reference a document or a report. An answer without a source is a promise; an answer with a source is proof. And if you don’t have a document, state that honestly and include a date when it will be available. A visible gap with a plan is better than a made-up answer, because the latter will be exposed during the next audit.

Our free analysis at keten.alta-ict.nl helps you get started: you upload the questionnaire you received, and the tool identifies the themes and shows you how far along you are. Just to be clear up front: the tool doesn’t fill out the questionnaire for you. Each answer requires a source, and where one is missing, it remains visible as a gap; nothing is made up. This is intentional, because your name will appear under the answers.

The package we didn’t sell

An office handling sensitive data asked us a logical question: Shouldn’t we aim for the highest level of security, with all the enterprise tools that come with it? Our answer: no. For an organization of that size, those tools are more of a burden than the problem itself. What was actually needed: secure email with the ability to recall a message sent in error, and security on the phones that separates personal and business use. Two targeted additions to the existing package. Done.

Why this story appears in a blog about supply chain issues: the IT industry profits from overselling, and customers know it. Any recommendation is viewed with suspicion as soon as it happens to be the most expensive one. Our rule, therefore, is that the advice must fit the organization, not the bottom line. The next time you receive an IT quote, try asking: “What do you advise against?” The answer speaks volumes.

What’s Not Necessary

Just to be clear, because the alarmist content suggests otherwise: no one expects a small organization to have certifications, thick policy manuals, or enterprise-level tools. Not even the law does. What matters is that the basics are demonstrably in order: MFA on every account, a tested backup, a ready incident response plan, visibility into who has access to your systems, and proof of each of those four elements. For organizations that handle sensitive data, GDPR Article 32 is an additional requirement separate from the above; the four documents and the six topics largely cover that requirement as well.

How ALTA-ICT helps

We can help in two ways. If you receive a questionnaire from the supply chain, forward it to us: we’ll provide the technical supporting documentation based on your own operations, in the form of reports that you can forward directly to a municipality, accountant, or insurer. And if the supporting documents are missing, we’ll review what you’ve drafted yourself or through your trade association, or we’ll draft them with you. No more than necessary, but verifiable. We operate under ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024; the evidence your supply chain requires is part of our daily work.

Frequently Asked Questions

I am a guardian or a healthcare provider. Does the Cybersecurity Act apply to me?

Almost certainly not directly. But your clients—such as municipalities and healthcare institutions—are subject to these requirements and must assess their suppliers. That’s how the questions end up with you, in addition to what the accountant and the GDPR already require.

Do the four documents need to be drafted by a lawyer or an advisor?

No. Start with the standard documents from your trade association and adapt them to your own organization. Then have them reviewed to ensure the technical details are correct and nothing is missing; that’s a few hours’ work, not a lengthy process.

What if I can’t answer a question on the questionnaire?

Write down what’s already there, honestly identify what’s missing, and include a date for when it will be available. A gap with a plan is an acceptable answer; a made-up answer never is.

Do I need a certification to pass the exam?

No. Virtually no assessor asks small organizations for a certificate; they ask for demonstrable measures. The four documents, plus evidence from your own organization, go a long way.

How can I avoid buying too much IT to solve this problem?

With every quote, ask the supplier what they advise against, and evaluate each proposal against the six themes: does it resolve a demonstrability gap, or does it add tools that are more cumbersome than the problem itself? Targeted additions built on a suitable foundation almost always outperform the most comprehensive package.

Conclusion

The supply chain doesn’t demand perfection from small organizations; it demands verifiability. Four documents with dates and owners, covering the six themes, bridging the gap between action and proof, and answering every questionnaire with a source. Those who have this in order will hardly notice the questions; those who don’t will have to explain it all over again every time. The difference is preparation time.

Want to know where your organization stands? Schedule a check-in with ALTA-ICT: for each topic, we’ll provide the answer to the question every auditor asks: Can you prove it?

Want to know more?

Get in touch
Hero bij informatiebeveiliging voor kleine organisaties: een basisdossier met de vier documenten voor de eerste ketenvraag