Taking measures is half the work; the law also asks you to check that they work. The difference sounds subtle and is not: a backup exists, or a backup was restored this year and turned out to work. Only the second counts in an audit.
What is the difference between having a measure and testing it?
An example per topic: MFA is switched on, or someone has checked that no accounts without MFA remain. Access is withdrawn when people leave, or the account list has been placed next to the staff list this year. The test is always the question: how do I know this still holds today?
A yearly round through your measures, recording per measure what you checked and what came out of it, is an appropriate answer for most suppliers. Put it in a short report; that report is the evidence.
Do I need an external audit or certification?
Not necessarily. An ISO 27001 certificate answers a lot of customer questions in one go, but it is a substantial undertaking and the law does not require it. A thorough internal review, or an external assessment without a certification process, counts too, as long as there is a report you can show.
The trade-off is commercial: if you supply parties that ask for certification in tenders, ISO 27001 pays for itself. For most smaller suppliers, testing demonstrably without a certificate is enough for now.
Why does the board have to be involved?
Because the law explicitly arranges it that way: directors of organisations under the law are personally liable for the duty of care, and that attitude seeps into what customers expect from their suppliers. Cybersecurity on the board agenda at least twice a year, with minuted decisions, is the simplest way to make involvement demonstrable.
The minuting is not the bureaucratic part but the evidence: an auditor asking "does the board discuss this?" does not want to hear a yes, they want to see something.
Which evidence do I keep, and for how long?
Keep the shortest document per measure that answers the question. For backups that is the restore test report, for access control the outcome of the annual review, for training the attendance list, for patch policy the overview of applied updates, and for MFA an export with the number of accounts with and without. Five documents, a page each, and you cover the bulk of any questionnaire.
Two years is enough for most suppliers: then you can show not only the current state but that it happened last year too, and that difference is exactly what "structural" means. Add the date and the name of whoever did it, because a piece of evidence without a date proves nothing.
What if a test shows something does not work?
Then the test worked. This is the point where companies are inclined to leave the outcome out, and that is precisely the wrong reflex: an auditor who only ever sees passed tests starts doubting the tests.
Note what did not work, what you did about it, and when you tested it again. Those three lines together are the strongest piece of evidence you can have, because they show a process that corrects itself. The same goes for the incidents you log under the incident procedure.
Who runs that test if I have no IT person on staff?
Usually your managed service provider, and that is allowed. The law does not ask for independence at every check; that requirement only applies to a real audit. What does count is that the result sits with you and not only with them: ask for the report, read it, and note what you are doing with the findings.
On one point it is wise to have someone else look, and that is the work of that same provider. Anyone testing their own patch policy rarely concludes that it is not in order. A vulnerability scan by a third party, once a year on everything reachable from the internet, covers that for an amount that does not stand out next to the management invoice; see also patch policy.
What else is tested is set out in the ten duty of care measures.