NIS2 and CMMC are turning asset inventories into a compliance requirement
Two major regulatory regimes now name hardware asset inventory as a specific control. Here's what NIS2 and CMMC actually ask for and what 'good enough' looks like.
Two major regulatory regimes now name hardware asset inventory as a specific control. Here's what NIS2 and CMMC actually ask for and what 'good enough' looks like.
Asset inventory used to be something auditors asked about in passing. In two of the biggest regulatory regimes to land recently, it's now a named control. The EU's NIS2 directive and the US Department of Defense's CMMC framework both require organisations in scope to maintain an accurate, current inventory of the hardware and systems that support their operations and both expect it to be more than a spreadsheet somebody updates before the audit.
NIS2 Article 21 requires essential and important entities to maintain an accurate inventory of network and information system assets, covering servers, workstations, network devices and mobile devices. The directive's language assumes the inventory reflects reality: assets actively involved in providing, maintaining or supporting essential operations, not a historical record of what was purchased.
The common thread across both frameworks is that 'we think we know what we have' doesn't satisfy an auditor anymore. A register that reconciles automatically against Intune, Autopilot and your directory, rather than one maintained by manual updates, is what turns this from a stressful annual scramble into something you can just show someone whenever it's asked for.