Article
24 Aug 2026
The supplier questionnaire is coming. Three questions to have ready answers for
In-scope clients are starting to survey their staffing suppliers on cyber readiness. The questionnaires vary; the underlying questions repeat.

Supplier questionnaires are how new compliance duties travel down a supply chain, and the Cyberbeveiligingswet has started the newest wave. The formats will vary from two lines in an email to a twenty-page annex, but underneath, three questions repeat, and an agency that prepares three answers is prepared for every variant.
Question one is about policy: what does the agency have in place? The strong answer is short and factual. Which training placed workers complete, in which languages, how testing works and when renewal happens. One paragraph that is true outperforms three pages that impress.
Question two is about records: can you show it per person? This is where administration decides the outcome. Who was trained, when, with what result and valid until when. A policy without per-person records is a promise; clients are being asked by law for control, and control shows up in records.
Question three is about verification, and it is the one that separates suppliers: can the client check it themselves, including next month? An attached list is out of date from the moment it is sent. Evidence the client can verify live, showing current status per worker throughout the placement, keeps answering the question after the email thread is forgotten.
Two boundaries protect the answering agency. Share status, never files: a client needs valid or lapsed, not personnel dossiers, and privacy law is on the side of the agency that keeps that line. And claim precisely: an agency makes the cyber hygiene of its workers demonstrable; it does not declare its client compliant, because that judgement belongs to the client and its advisers.