NIS2 asset management evidence: what the law requires
2026-06-20 · Updated 2026-07-18
NIS2 never uses the phrase “asset inventory” in its articles. That is the first thing that trips up teams preparing for it. The obligation is real, but it is split across three documents: the directive itself, a Commission implementing regulation that adds the technical detail, and ENISA guidance that lists the exact artifacts an assessor expects to see. Read together, they turn one short phrase in Article 21 into a specific, testable set of evidence. This is what that evidence looks like, and where each piece comes from in the law.
Where NIS2 actually names asset management
Asset management is named once, in Article 21(2)(i). The NIS2 Directive (EU) 2022/2555 lists a minimum set of cybersecurity risk-management measures that essential and important entities must take, and point (i) reads: “human resources security, access control policies and asset management.” That is the legal hook. Everything below it is detail the regulators added later.
Two framing points from the same article matter for anyone who already runs a security programme. Article 21(1) requires measures that are “appropriate and proportionate,” taking into account “the state-of-the-art and, where applicable, relevant European and international standards.” If you hold ISO 27001, that clause is talking about you: NIS2 expects you to lean on the standards you already follow. And the directive’s all-hazards approach is broader than cyberattacks. Recital 79 extends it to “the physical environment of those systems,” naming theft, fire, flood, telecommunication or power failures, and unauthorised physical access. Your asset records have to account for physical devices and where they live, not just software.
The directive sets the deadline too. Because NIS2 is a directive rather than a regulation, it does not apply directly. Article 41 required Member States to adopt and publish national transposition law by 17 October 2024 and to apply it from 18 October 2024. Your obligations are defined by your country’s transposition, so the national text is always the version that binds you.
The detail lives in Implementing Regulation 2024/2690
The directive says “asset management.” The specifics come from Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, which lays down the technical and methodological requirements for the Article 21(2) measures and sets them out in an Annex.
One honest caveat here, because most articles skip it. The implementing regulation formally binds a specific set of digital-infrastructure entities: DNS providers, TLD registries, cloud computing and data centre providers, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers. If you are a manufacturer or a hospital rather than a cloud provider, the regulation does not bind you line by line. It is still the clearest statement the EU has published of what good asset management looks like under NIS2, and national authorities and assessors use it as the reference point. Treat it as the bar even when it is not literally your text.
The regulation is also explicit about why asset management sits underneath everything else. Recital 24 states that entities should protect their assets “through a sound asset management which should also serve as the basis for the risk analysis and business continuity management,” covering “both tangible and intangible assets.” In other words, the inventory is not one control among ten. It is the foundation the other controls are built on.
What the inventory has to contain
The operative requirement is Annex point 12.4.1: entities “shall develop and maintain a complete, accurate, up-to-date and consistent inventory of their assets,” and “shall record changes to the entries in the inventory in a traceable manner.” Four adjectives and a change history. Each one is a thing an assessor can check.
Point 12.4.2 says what goes in it, at a granularity appropriate to the entity: the list of operations and services with descriptions, and the list of network and information systems and other assets that support them. Point 12.4.3 adds that entities “shall regularly review and update the inventory” and “document the history of changes.”
For the fields themselves, Recital 26 gives a working schema. A comprehensive inventory “could include, for each asset, at least a unique identifier, the owner of the asset, a description of the asset, the location of the asset, the type of asset, the type and classification of information processed in the asset, the date of last update or patch of the asset, the classification of the asset under the risk assessment, and the end of life of the asset.” If you are choosing what columns your inventory needs, that sentence is the checklist.
As a working table, field by field:
| Recital 26 field | What to record | What it answers in an audit |
|---|---|---|
| Unique identifier | An asset tag that never changes hands | Which exact asset are we talking about? |
| Owner | A named person, not a team | Who is accountable for this row being true? |
| Description | Manufacturer, model, or application name | Do we run the product this advisory names? |
| Location | Site, remote, or cloud region | Which sites does this incident touch? |
| Type of asset | Hardware, software, or virtual | Is the inventory complete across all three? |
| Information processed | The data classes the asset touches | Does this asset raise the protection requirement? |
| Date of last update or patch | The freshness timestamp | Is the vulnerability-handling loop actually running? |
| Risk classification | The grade from your risk assessment | Was protection prioritised by importance? |
| End of life | The support cut-off date | Which assets are running unpatched by design? |
Two more obligations sit alongside the inventory and are often overlooked:
- Classification. Annex point 12.1 requires entities to classify all assets by confidentiality, integrity, authenticity and availability, “to indicate the protection required,” and to review those classifications periodically. Classification is not optional decoration on the record.
- Lifecycle and offboarding. Point 12.2 requires an asset-handling policy covering the full lifecycle, from acquisition through use, storage, transport and disposal, including “irretrievable deletion and destruction.” Point 12.5 requires procedures so that assets held by staff are deposited, returned or deleted when employment ends, with that return documented.
If you want those columns as a working file rather than a sentence, we keep an ungated asset register template (XLSX): the Recital 26 fields as columns, a change-history sheet for the traceability requirement, and a how-to-use sheet that maps the four 12.4.1 adjectives to specific columns. No email gate.
The evidence an auditor will actually ask for
This is the part the keyword is really about, and the answer is unusually concrete. ENISA published its Technical Implementation Guidance, version 1.0 in June 2025 as guidance on the implementing regulation. For the asset inventory requirement, it lists three “examples of evidence”:
- Documentation describing the inventory of assets.
- An up-to-date inventory of assets.
- Records of reviews, or a history of changes.
That third item is the one teams underestimate. A current spreadsheet can satisfy the first two on the day of the audit. Only a system that timestamps every change can produce the third without reconstruction, and reconstruction is exactly what an assessor is trained to spot.
ENISA goes further and effectively endorses tooling. Its guidance tells entities to “use tools that support the comprehensive tracking and management of assets” and, “ideally, consider the use of tools for automated discovery and asset tracking to continuously discover, categorize, and monitor both on-premises and cloud assets.” It then lists “configuration settings of the asset management tool” as evidence in its own right. The guidance also says to list all asset types (hardware, software, data and services), update the inventory promptly for new, decommissioned or changed assets, use standardised naming, and apply validation rules so entries stay complete and consistent.
So the evidence requirement is not “a list.” It is a maintained, classified, owner-attributed record, backed by discovery data and a change history that shows the record is alive.
Why the inventory proves the other controls
The reason asset management deserves its own attention is that the inventory is load-bearing. The same record produces evidence across several other Article 21(2) measures.
- (a) Risk analysis assumes you know what exists to analyse. The asset register is the input.
- (e) Vulnerability handling depends on the “date of last update or patch” field from Recital 26. Patch evidence is asset evidence.
- (f) Effectiveness assessment needs measurable indicators. The share of assets classified, or of endpoints reporting in, comes from the inventory.
- Offboarding ties back explicitly: ENISA’s guidance says to identify all assets to be returned “according to the asset inventory.”
- Logging ties back too: ENISA says assets being logged “should be marked as such in the asset inventory.”
Get the inventory right and you are part way to evidencing five other things. Get it wrong and the gaps cascade.
How much of Article 21 the inventory covers
This section sizes the coverage, because the inference “we bought an ITAM tool, so Article 21 is handled” fails an audit. Applying the same evidence-class labels our product prints in its evidence pack, only three of the ten Article 21(2) sub-controls get native evidence from an asset platform; the rest split between baselines your programme builds on, proxy metrics an assessor treats as partial, and one, business continuity, that gets nothing useful at all. The sub-control-by-sub-control version, including exactly what you still have to produce yourself for each, is the Article 21(2) checklist.
| Measure | Area | Evidence class |
|---|---|---|
| 21(2)(a) | Risk analysis and security policies | Hygiene floor |
| 21(2)(b) | Incident handling | Native evidence |
| 21(2)(c) | Business continuity and crisis management | Outside ITAM scope |
| 21(2)(d) | Supply chain security | Hygiene floor |
| 21(2)(e) | Security in acquisition and maintenance | Proxy metric |
| 21(2)(f) | Effectiveness assessment | Native evidence |
| 21(2)(g) | Cyber hygiene and training | Hygiene floor |
| 21(2)(h) | Cryptography | Proxy metric |
| 21(2)(i) | HR security, access control, asset management | Hygiene floor |
| 21(2)(j) | MFA and secure communications | Native evidence |
If you already hold ISO 27001
You are closer than you think on the control, and further than you think on the evidence. ISO 27001:2022 control A.5.9, inventory of information and other associated assets, is the direct counterpart to the NIS2 asset management measure, and the standard’s acceptable-use and return-of-assets controls cover the handling and offboarding obligations. The policy and the register are largely there.
The gap is freshness and reach. A certification audit can accept a register reviewed annually. The NIS2 evidence model rewards a register that reconciles continuously, because “records of reviews or a history of changes” is one of the three named artifacts. And NIS2 adds an obligation ISO 27001 does not touch at all: the Article 23 incident reporting timeline, with its 24-hour early warning and 72-hour notification. Asset data feeds that reporting, but the workflow is yours to build.
How OnTrackio produces this evidence
OnTrackio is a compliance-first, EU-based IT asset management platform, and the asset-management slice of NIS2 evidence falls out of normal use rather than a separate audit project. An endpoint agent discovers hardware and software and keeps the inventory reconciled, so the record stays current and every change is timestamped. That directly answers the three ENISA artifacts: documentation of the inventory, an up-to-date inventory, and a history of changes. Ownership, classification, location, last-seen and end-of-life map onto the Recital 26 field list, and the data lives in eu-central-1 (Frankfurt), which keeps the question of where your evidence sits inside the EU.
The honest part matters as much as the coverage. OnTrackio labels each data point by how directly it serves as evidence: asset, user and access records are native evidence for the asset-management measure; some signals are a hygiene floor; some are a proxy; and plenty sits outside ITAM scope entirely. Article 23 reporting, supply-chain risk programmes and board governance are not things an asset platform can prove for you. The product tells you where ITAM stops so you do not infer fuller coverage than the data supports. The full sub-control map is public on the Article 21(2) checklist. You can see exactly how we frame all of this on our NIS2 evidence and security page, the Business tier that bundles the NIS2 evidence pack, or by booking a 30-minute demo.
Frequently asked questions
Does NIS2 explicitly require an asset inventory? Not as a named clause. Article 21(2)(i) of Directive (EU) 2022/2555 lists asset management among the baseline measures, and Commission Implementing Regulation (EU) 2024/2690 turns that into a concrete obligation: point 12.4.1 of its Annex requires a complete, accurate, up-to-date and consistent inventory, with changes recorded in a traceable way. So the inventory itself is the practical requirement behind the asset management measure.
We already hold ISO 27001. Do we still have an asset management gap under NIS2? On the control itself, mostly no. ISO 27001:2022 control A.5.9, inventory of information and other associated assets, maps directly to what NIS2 expects. The gap is usually freshness and reporting. A once-a-year inventory is weaker evidence than one that reconciles continuously, and Article 23 incident reporting sits outside ISO 27001 entirely.
What asset management evidence would a NIS2 auditor actually ask for? ENISA’s Technical Implementation Guidance lists three artifacts for the inventory requirement: documentation describing the inventory, an up-to-date inventory of assets, and records of reviews or a history of changes. It also names the configuration settings of the asset management tool as evidence. In practice an assessor wants to see ownership and classification populated, and discovery data reconciling the record against what is actually on the network.
Does using OnTrackio make us NIS2 compliant? No. Compliance is a determination against the directive and your national transposition law, not something a tool confers. OnTrackio produces the ITAM-derived evidence for the asset, user, and access portions of Article 21, with each data point mapped to its sub-control. Article 23 reporting, supply-chain risk programmes, and governance still need your own processes and, in places, dedicated GRC tooling.
Is there a template for the asset register? Yes. Download the XLSX; the second sheet is the change history that point 12.4.1’s traceability clause asks for, and nothing about it is gated.
What is the Article 21(2)(f) effectiveness assessment, and how does asset data feed it? Article 21(2)(f) requires policies and procedures to assess whether your risk-management measures actually work, which means producing measurable indicators rather than asserting controls exist. Asset and user data give you concrete numbers for that assessment: the share of assets classified, the share of endpoints reporting in, MFA enrolment across users. Those figures come straight from the inventory.