Skip to content
OnTrackio

NIS2 asset management evidence: what the law requires

2026-06-20 · Updated 2026-07-18

NIS2 never uses the phrase “asset inventory” in its articles. That is the first thing that trips up teams preparing for it. The obligation is real, but it is split across three documents: the directive itself, a Commission implementing regulation that adds the technical detail, and ENISA guidance that lists the exact artifacts an assessor expects to see. Read together, they turn one short phrase in Article 21 into a specific, testable set of evidence. This is what that evidence looks like, and where each piece comes from in the law.

Where NIS2 actually names asset management

Asset management is named once, in Article 21(2)(i). The NIS2 Directive (EU) 2022/2555 lists a minimum set of cybersecurity risk-management measures that essential and important entities must take, and point (i) reads: “human resources security, access control policies and asset management.” That is the legal hook. Everything below it is detail the regulators added later.

Two framing points from the same article matter for anyone who already runs a security programme. Article 21(1) requires measures that are “appropriate and proportionate,” taking into account “the state-of-the-art and, where applicable, relevant European and international standards.” If you hold ISO 27001, that clause is talking about you: NIS2 expects you to lean on the standards you already follow. And the directive’s all-hazards approach is broader than cyberattacks. Recital 79 extends it to “the physical environment of those systems,” naming theft, fire, flood, telecommunication or power failures, and unauthorised physical access. Your asset records have to account for physical devices and where they live, not just software.

The directive sets the deadline too. Because NIS2 is a directive rather than a regulation, it does not apply directly. Article 41 required Member States to adopt and publish national transposition law by 17 October 2024 and to apply it from 18 October 2024. Your obligations are defined by your country’s transposition, so the national text is always the version that binds you.

The detail lives in Implementing Regulation 2024/2690

The directive says “asset management.” The specifics come from Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, which lays down the technical and methodological requirements for the Article 21(2) measures and sets them out in an Annex.

One honest caveat here, because most articles skip it. The implementing regulation formally binds a specific set of digital-infrastructure entities: DNS providers, TLD registries, cloud computing and data centre providers, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers. If you are a manufacturer or a hospital rather than a cloud provider, the regulation does not bind you line by line. It is still the clearest statement the EU has published of what good asset management looks like under NIS2, and national authorities and assessors use it as the reference point. Treat it as the bar even when it is not literally your text.

The regulation is also explicit about why asset management sits underneath everything else. Recital 24 states that entities should protect their assets “through a sound asset management which should also serve as the basis for the risk analysis and business continuity management,” covering “both tangible and intangible assets.” In other words, the inventory is not one control among ten. It is the foundation the other controls are built on.

What the inventory has to contain

The operative requirement is Annex point 12.4.1: entities “shall develop and maintain a complete, accurate, up-to-date and consistent inventory of their assets,” and “shall record changes to the entries in the inventory in a traceable manner.” Four adjectives and a change history. Each one is a thing an assessor can check.

Point 12.4.2 says what goes in it, at a granularity appropriate to the entity: the list of operations and services with descriptions, and the list of network and information systems and other assets that support them. Point 12.4.3 adds that entities “shall regularly review and update the inventory” and “document the history of changes.”

For the fields themselves, Recital 26 gives a working schema. A comprehensive inventory “could include, for each asset, at least a unique identifier, the owner of the asset, a description of the asset, the location of the asset, the type of asset, the type and classification of information processed in the asset, the date of last update or patch of the asset, the classification of the asset under the risk assessment, and the end of life of the asset.” If you are choosing what columns your inventory needs, that sentence is the checklist.

As a working table, field by field:

Recital 26 fieldWhat to recordWhat it answers in an audit
Unique identifierAn asset tag that never changes handsWhich exact asset are we talking about?
OwnerA named person, not a teamWho is accountable for this row being true?
DescriptionManufacturer, model, or application nameDo we run the product this advisory names?
LocationSite, remote, or cloud regionWhich sites does this incident touch?
Type of assetHardware, software, or virtualIs the inventory complete across all three?
Information processedThe data classes the asset touchesDoes this asset raise the protection requirement?
Date of last update or patchThe freshness timestampIs the vulnerability-handling loop actually running?
Risk classificationThe grade from your risk assessmentWas protection prioritised by importance?
End of lifeThe support cut-off dateWhich assets are running unpatched by design?

Two more obligations sit alongside the inventory and are often overlooked:

If you want those columns as a working file rather than a sentence, we keep an ungated asset register template (XLSX): the Recital 26 fields as columns, a change-history sheet for the traceability requirement, and a how-to-use sheet that maps the four 12.4.1 adjectives to specific columns. No email gate.

The evidence an auditor will actually ask for

This is the part the keyword is really about, and the answer is unusually concrete. ENISA published its Technical Implementation Guidance, version 1.0 in June 2025 as guidance on the implementing regulation. For the asset inventory requirement, it lists three “examples of evidence”:

  1. Documentation describing the inventory of assets.
  2. An up-to-date inventory of assets.
  3. Records of reviews, or a history of changes.

That third item is the one teams underestimate. A current spreadsheet can satisfy the first two on the day of the audit. Only a system that timestamps every change can produce the third without reconstruction, and reconstruction is exactly what an assessor is trained to spot.

ENISA goes further and effectively endorses tooling. Its guidance tells entities to “use tools that support the comprehensive tracking and management of assets” and, “ideally, consider the use of tools for automated discovery and asset tracking to continuously discover, categorize, and monitor both on-premises and cloud assets.” It then lists “configuration settings of the asset management tool” as evidence in its own right. The guidance also says to list all asset types (hardware, software, data and services), update the inventory promptly for new, decommissioned or changed assets, use standardised naming, and apply validation rules so entries stay complete and consistent.

So the evidence requirement is not “a list.” It is a maintained, classified, owner-attributed record, backed by discovery data and a change history that shows the record is alive.

Why the inventory proves the other controls

The reason asset management deserves its own attention is that the inventory is load-bearing. The same record produces evidence across several other Article 21(2) measures.

Get the inventory right and you are part way to evidencing five other things. Get it wrong and the gaps cascade.

How much of Article 21 the inventory covers

This section sizes the coverage, because the inference “we bought an ITAM tool, so Article 21 is handled” fails an audit. Applying the same evidence-class labels our product prints in its evidence pack, only three of the ten Article 21(2) sub-controls get native evidence from an asset platform; the rest split between baselines your programme builds on, proxy metrics an assessor treats as partial, and one, business continuity, that gets nothing useful at all. The sub-control-by-sub-control version, including exactly what you still have to produce yourself for each, is the Article 21(2) checklist.

MeasureAreaEvidence class
21(2)(a)Risk analysis and security policiesHygiene floor
21(2)(b)Incident handlingNative evidence
21(2)(c)Business continuity and crisis managementOutside ITAM scope
21(2)(d)Supply chain securityHygiene floor
21(2)(e)Security in acquisition and maintenanceProxy metric
21(2)(f)Effectiveness assessmentNative evidence
21(2)(g)Cyber hygiene and trainingHygiene floor
21(2)(h)CryptographyProxy metric
21(2)(i)HR security, access control, asset managementHygiene floor
21(2)(j)MFA and secure communicationsNative evidence

If you already hold ISO 27001

You are closer than you think on the control, and further than you think on the evidence. ISO 27001:2022 control A.5.9, inventory of information and other associated assets, is the direct counterpart to the NIS2 asset management measure, and the standard’s acceptable-use and return-of-assets controls cover the handling and offboarding obligations. The policy and the register are largely there.

The gap is freshness and reach. A certification audit can accept a register reviewed annually. The NIS2 evidence model rewards a register that reconciles continuously, because “records of reviews or a history of changes” is one of the three named artifacts. And NIS2 adds an obligation ISO 27001 does not touch at all: the Article 23 incident reporting timeline, with its 24-hour early warning and 72-hour notification. Asset data feeds that reporting, but the workflow is yours to build.

How OnTrackio produces this evidence

OnTrackio is a compliance-first, EU-based IT asset management platform, and the asset-management slice of NIS2 evidence falls out of normal use rather than a separate audit project. An endpoint agent discovers hardware and software and keeps the inventory reconciled, so the record stays current and every change is timestamped. That directly answers the three ENISA artifacts: documentation of the inventory, an up-to-date inventory, and a history of changes. Ownership, classification, location, last-seen and end-of-life map onto the Recital 26 field list, and the data lives in eu-central-1 (Frankfurt), which keeps the question of where your evidence sits inside the EU.

The honest part matters as much as the coverage. OnTrackio labels each data point by how directly it serves as evidence: asset, user and access records are native evidence for the asset-management measure; some signals are a hygiene floor; some are a proxy; and plenty sits outside ITAM scope entirely. Article 23 reporting, supply-chain risk programmes and board governance are not things an asset platform can prove for you. The product tells you where ITAM stops so you do not infer fuller coverage than the data supports. The full sub-control map is public on the Article 21(2) checklist. You can see exactly how we frame all of this on our NIS2 evidence and security page, the Business tier that bundles the NIS2 evidence pack, or by booking a 30-minute demo.

Frequently asked questions

Does NIS2 explicitly require an asset inventory? Not as a named clause. Article 21(2)(i) of Directive (EU) 2022/2555 lists asset management among the baseline measures, and Commission Implementing Regulation (EU) 2024/2690 turns that into a concrete obligation: point 12.4.1 of its Annex requires a complete, accurate, up-to-date and consistent inventory, with changes recorded in a traceable way. So the inventory itself is the practical requirement behind the asset management measure.

We already hold ISO 27001. Do we still have an asset management gap under NIS2? On the control itself, mostly no. ISO 27001:2022 control A.5.9, inventory of information and other associated assets, maps directly to what NIS2 expects. The gap is usually freshness and reporting. A once-a-year inventory is weaker evidence than one that reconciles continuously, and Article 23 incident reporting sits outside ISO 27001 entirely.

What asset management evidence would a NIS2 auditor actually ask for? ENISA’s Technical Implementation Guidance lists three artifacts for the inventory requirement: documentation describing the inventory, an up-to-date inventory of assets, and records of reviews or a history of changes. It also names the configuration settings of the asset management tool as evidence. In practice an assessor wants to see ownership and classification populated, and discovery data reconciling the record against what is actually on the network.

Does using OnTrackio make us NIS2 compliant? No. Compliance is a determination against the directive and your national transposition law, not something a tool confers. OnTrackio produces the ITAM-derived evidence for the asset, user, and access portions of Article 21, with each data point mapped to its sub-control. Article 23 reporting, supply-chain risk programmes, and governance still need your own processes and, in places, dedicated GRC tooling.

Is there a template for the asset register? Yes. Download the XLSX; the second sheet is the change history that point 12.4.1’s traceability clause asks for, and nothing about it is gated.

What is the Article 21(2)(f) effectiveness assessment, and how does asset data feed it? Article 21(2)(f) requires policies and procedures to assess whether your risk-management measures actually work, which means producing measurable indicators rather than asserting controls exist. Asset and user data give you concrete numbers for that assessment: the share of assets classified, the share of endpoints reporting in, MFA enrolment across users. Those figures come straight from the inventory.

Doing this by hand today? The free templates carry the same structure this guide describes: NIS2 register, SOC 2 inventory, offboarding checklist. Or see the register that maintains itself: book a 30-minute demo.