
Knowledge base
August 07, 2026
Too Small for the Cybersecurity Act? The Questions Are Still Coming
The Cybersecurity Act will take effect on August 15, 2026. On July 7, 2026, the Senate approved the Act, which implements the European NIS2 Directive into Dutch law. Large organizations and critical sectors are directly subject to its provisions.
Your company probably isn’t. And yet, something is changing for you. The law imposes a duty of care on organizations that fall under its scope, and that duty of care doesn’t stop at their own doorstep: they must also manage the risks in their supply chain. They do this in the only way that’s scalable: by sending questionnaires to their suppliers.
In this blog post, you’ll learn why you’re receiving that questionnaire even though the law doesn’t apply to you, what it usually contains, and how to respond with evidence rather than promises.
What’s Changing on August 15
The Cybersecurity Act requires organizations in essential and critical sectors to demonstrate that their information security is in order. Part of this duty of care involves their own supply chain: those subject to the law must be aware of the risks posed by suppliers and establish agreements to address them.
For those organizations, this is something they need to work on. For their suppliers—and that’s you if you supply a healthcare institution, municipality, transportation company, or larger enterprise—it means something else: your customer is going to ask you questions. Not because they don’t trust you, but because the law requires them to do so.
Why the questions end up with you
An organization with a hundred suppliers isn’t going to conduct a hundred audits. Instead, it sends out a questionnaire. Sometimes it’s a document it has created itself, sometimes an industry standard, and sometimes a portal where you have to log in and check boxes, providing supporting documentation.
The questions come up at times you don’t choose: during a contract renewal, during a bidding process, or suddenly, because your client’s compliance department has a deadline. If you wait until then to start documenting, you’ll be writing answers under time pressure. That leads to two undesirable outcomes: you’ll make promises you can’t keep, or you’ll leave fields blank, and your client will draw their own conclusions.
What People Usually Ask
The questionnaires vary by client, but the themes are consistent:
– Policy: Is there an information security policy, and who is responsible for it?
– Access: Who has access to which data, and how are accounts for former employees closed?
– Continuity: Are there backups, and have they been tested?
– Incidents: What happens when things go wrong, and when will your customer be notified?
– Proof: Can you demonstrate what you said above, or is it just in your head?
That last question is the deciding factor. In practice, virtually every company implements some form of security. The difference lies in whether it can be demonstrated: a document with a date and an owner counts, but a verbal agreement does not.
Here’s how to prepare without turning it into a project
Start with your customers, not with the standard. Go through your customer list and identify those who are likely to be subject to the law: healthcare, government, transportation, energy, and larger companies. These are the recipients of future questionnaires.
Next, set out the framework on paper. Not a 100-page set of standards, but documents that cover the recurring themes listed above, each with a date and a person in charge.
Always respond to questionnaires by citing a document. An answer without a source is a promise; an answer with a source is proof. If you don’t have a document, state that honestly and include a date for when it will be available. That answer is better than leaving the field blank.
Our free analysis at keten.alta-ict.nl helps you take the first step. Let’s be clear from the start: the tool reads your questionnaire, identifies the themes, and shows you how far along you are, but it doesn’t write your answers for you. Any missing information remains visible as a gap. This is intentional: a made-up answer in a supplier assessment will be exposed sooner or later.
How ALTA-ICT Does This Itself
We’re on both sides of this table. As an MSP, we receive supplier evaluations from our own clients, and we’re certified to ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024. Our responses to questionnaires refer to documents from our own management system, including the document number and date. That same approach—documenting what you do and referring to existing documentation—works just as well even without certification.
Frequently Asked Questions
Does the Cybersecurity Act apply to my small or medium-sized business?
Often not directly. The law focuses on essential and critical sectors. If you supply organizations that are covered by the law, it affects you through their duty of care.
Can I just ignore a survey?
That’s possible, but your customer must be able to demonstrate control over its supply chain. A supplier that doesn’t respond becomes a risk on paper. This is taken into account when renewing a contract.
Do I need a certification to be able to answer?
No. A certificate makes it easier to provide answers, but most questionnaires ask for evidence of measures taken, not for a certificate. Documents that include the date and the owner’s name go a long way.
What if I really can’t answer a question?
Write down what’s already in place, identify what’s missing, and include a date. An honest assessment of the gaps, along with a plan, is a better answer than a promise without proof.
When does this need to be done by?
The law takes effect on August 15, 2026, but your deadline is determined by your clients: the next contract renewal or bid. Starting early means you can respond without time pressure.
Conclusion
The Cybersecurity Act probably doesn’t impose any obligations on you. But it does on your customers, and their obligations will become your checklist. If you lay the groundwork now, you’ll be able to complete that checklist in an afternoon rather than during a week of panic.
Would you like to know where you stand before the first questionnaire arrives? Schedule a brief session with ALTA-ICT, and we’ll go over your situation together.
Source: Debate on the Cybersecurity Act and the Wwke, Senate, July 7, 2026. Verified on July 10, 2026.
Want to know more?

Related
blogs
Tech Updates: Microsoft 365, Azure, Cybersecurity & AI – Wekelijks in je Mailbox.



