For most mid-size companies, the strictest security and AI rules they face come not from government but from their largest customers. Enterprise obligations flow downhill into vendor contracts, security addenda and questionnaires - and they arrive with a deal attached.
A $175M manufacturer selling to aerospace primes. A $45M MSP serving banks. A $100M healthcare provider billing insurers. A logistics firm hauling for retailers. None of these companies are heavily regulated in their own right — and all of them live under security regimes stricter than most regulation, imposed by contract.
Enterprises are accountable for their vendors, and they discharge that accountability downward: questionnaires, addenda, evidence requests, now AI-use disclosures. Texas's AI law sharpened the pattern — many mid-size firms fall under its small-business exemption, but their covered enterprise customers do not, and those customers' obligations arrive at the vendor's door as contract language. The details are here.
Every hard question in a security addendum has three honest answers: evidence it, commit to it with a date, or say it does not apply. The expensive mistakes are the dishonest fourth and fifth options — overclaiming, which becomes contract risk the day an incident happens, and underclaiming, which quietly loses deals you should have won. Triage is the skill, and it is learnable. We wrote up the how.
Here is the part the complaint-mode conversation misses: most of your competitors handle these documents badly. The mid-size firm that answers fast, evidenced and honestly gets remembered by procurement teams for exactly that. The evidence pack built for your insurer largely reuses for your customers; the AI policy answers both. One afternoon of assembly, many uses.
When the requirements have piled past what an afternoon covers, the review ranks the whole picture, and the retainer exists for the quarter when three questionnaires and a renewal all land at once.