Free template
NIS2 asset register template
A ready-to-use XLSX asset register built around the asset-management expectations of the NIS2 Implementing Regulation: 17 columns, three example rows, a change-history sheet, and a how-to sheet that maps each column to the regulation's own wording. Direct download, no email gate.
Want to know when this template changes? Regulations and criteria move. Email sales@ontrackio.com and we will send the new version. Nothing else, no newsletter.
What is inside
- How to use. One page of instructions, including how each column maps to the asset-management language of CIR (EU) 2024/2690.
- Asset register. The 17-column register itself, with three worked example rows you can overwrite: a laptop, a server, and a SaaS subscription.
- Change history. A log sheet for register changes, because reviewers ask not only what the register says but when it last changed and who changed it.
Every column, and why it is there
Nothing in this file is decorative. Each column answers a question a reviewer or an incident will eventually ask:
| Column | Why it is in the register |
|---|---|
| Asset tag | A stable identifier the register can be audited against. Serial numbers change owners; tags do not. |
| Asset type | Hardware, software, or virtual. The Implementing Regulation expects the inventory to cover all three. |
| Category | Laptop, server, network gear, SaaS subscription. Lets you report coverage per class instead of one flat list. |
| Manufacturer / model | Needed the day a vulnerability advisory names a product line and you have to answer: do we run it? |
| Serial number | Ties the row to a physical device for spot checks, warranty claims, and disposal certificates. |
| Owner | The named person accountable for the asset. Ownership is the first thing an auditor probes, because a register without owners cannot be kept accurate. |
| Department | Aggregates risk and cost by function, and tells you who to chase when a review is due. |
| Location | Site or remote. Multi-site operators need this for incident scoping: which site is affected? |
| Status | In use, in storage, in repair, retired. Lifecycle state is what separates a register from a purchase list. |
| Classification | The sensitivity or criticality grade. The Implementing Regulation asks entities to prioritise assets by importance; this column is where that becomes visible. |
| Supports service / operation | The dependency link: which business service stops if this asset fails. This is the column most spreadsheets miss and most auditors ask about. |
| Supplier | Feeds supply-chain questions: who provided it, who maintains it, who to notify. |
| Purchase date | Anchors depreciation, warranty, and age reporting. |
| Warranty end | A renewal you want to see coming, not discover after the failure. |
| End of life | Unsupported assets are unpatched assets. EoL dates turn that from a surprise into a queue. |
| Last verified | When a human last confirmed the row is true. A register nobody re-verifies decays into fiction, and auditors know it. |
| Notes | The overflow field for anything the structure does not capture. |
Where this fits in NIS2, honestly
An asset register is direct evidence for the asset-management slice of NIS2 Article 21(2), a necessary baseline for several other measures, and no help at all for a few. If a vendor tells you a spreadsheet makes you compliant, they are selling you a spreadsheet. The full mapping, measure by measure with honest coverage labels, is on the Article 21(2) checklist, and the reasoning behind the register columns is unpacked in the NIS2 asset evidence guide.
Frequently asked questions
Is the template really free?
Yes. Direct download, no email gate, no watermark. It is a plain XLSX you can edit, rename, and keep. We make an IT asset management platform; the template is useful on its own, and if your register outgrows a spreadsheet you will know where to find us.
Does filling in this template make us NIS2 compliant?
No, and be wary of any template that claims otherwise. NIS2 Article 21 covers ten risk-management areas; an asset inventory is direct evidence for some, a supporting baseline for others, and irrelevant to a few. The register is a necessary artifact, not a compliance certificate.
What is the register based on?
The asset-management expectations in the NIS2 Implementing Regulation (CIR 2024/2690), which asks entities to maintain an inventory of assets with owners, classification by importance, and periodic review. The How to use sheet inside the file maps each column to the language the regulation uses.
How often should the register be reviewed?
The regulation expects periodic verification without fixing a number. In practice, quarterly spot checks plus a full annual review is a defensible cadence for a mid-market fleet, and the Last verified column exists so that cadence leaves evidence.
We have 1,000+ assets. Will a spreadsheet hold?
It will hold data; it will not hold truth. Past a few hundred assets, rows drift from reality faster than anyone re-verifies them. That is the point where an agent-fed register that reconciles itself daily earns its place. Until then, this file plus discipline works.
When the spreadsheet stops being true
OnTrackio keeps the same register agent-fed and reconciled daily, with the NIS2 evidence exports on top. Public pricing, 30-minute demo.