ComplianceJanuary 2026 · 5 min read

NIS2 and CMMC are turning asset inventories into a compliance requirement

Two major regulatory regimes now name hardware asset inventory as a specific control. Here's what NIS2 and CMMC actually ask for and what 'good enough' looks like.

By AssetPilot Team

Asset inventory used to be something auditors asked about in passing. In two of the biggest regulatory regimes to land recently, it's now a named control. The EU's NIS2 directive and the US Department of Defense's CMMC framework both require organisations in scope to maintain an accurate, current inventory of the hardware and systems that support their operations and both expect it to be more than a spreadsheet somebody updates before the audit.

What does NIS2 actually require?

NIS2 Article 21 requires essential and important entities to maintain an accurate inventory of network and information system assets, covering servers, workstations, network devices and mobile devices. The directive's language assumes the inventory reflects reality: assets actively involved in providing, maintaining or supporting essential operations, not a historical record of what was purchased.

And what does CMMC ask for?

  • An asset inventory organised by CMMC level, covering every asset that interacts with Controlled Unclassified Information (CUI).
  • Documented configurations for those assets as part of the System Security Plan (SSP).
  • CMMC implementation began in phases from November 2025, with Level 1 and Level 2 self-assessments appearing in DoD solicitations from year one.

The common thread across both frameworks is that 'we think we know what we have' doesn't satisfy an auditor anymore. A register that reconciles automatically against Intune, Autopilot and your directory, rather than one maintained by manual updates, is what turns this from a stressful annual scramble into something you can just show someone whenever it's asked for.

Know exactly what you own, who has it and what it costs.