Glossary · Term

Asset inventory explained

An asset inventory is a complete register of all IT and OT systems, applications, devices, data and services in an organisation – the basis for every risk analysis.

At a glance
Meaning
A complete register of every asset worth protecting
Purpose
The basis for risk analysis, protection and evidence
Relation to NIS2
The first practical implementation step
Upkeep
Keep it current at all times
Updated
June 2026
Editorial team
Compliance Compass

What is an asset inventory?

An Asset inventory lists every one of your Assets systematically – hardware, software, cloud services, data and networks. Where the term assets describes what is worth protecting, the asset inventory is the concrete tool that records those values, classifies them and keeps them current. Think of it as a complete, living inventory of the whole IT and OT landscape, giving every asset an owner, a protection requirement and a list of its dependencies.

Why it is the foundation

You can only protect what you know about. Without a current asset inventory you can judge neither which risks exist nor which protective measures are needed. That is exactly why it is the first practical step in any NIS2 implementation – ahead of the risk analysis itself. It also creates the ability to produce evidence, which NIS2 expects from essential and important entities alike. You have to be able to show your competent authority that the measures you have taken really do cover every relevant asset.

What belongs in it

The asset inventory and risk management

The inventory is the starting point: for every asset the risks are assessed and the matching Controls are chosen. Within the ISMS it forms the central body of data that risk assessment, planning of measures and audit evidence all draw on.

In concrete terms: While building its inventory, a hospital discovers that several medical devices hang off the network unplanned and belong to nobody in particular. Only once they are recorded in the asset inventory do those devices become visible, get an owner and feed into the risk analysis – instead of remaining unnoticed ways in.

Further reading: BSI IT-Grundschutz, the German baseline security standard

Frequently asked questions

What belongs in an asset inventory?

An asset inventory holds all IT and OT systems, applications, devices, cloud services, data and networks in an organisation, each with a named owner, its protection requirement and its location. The dependencies between individual assets matter just as much, such as which application runs on which server. Only then do you get a complete, living register of the whole IT and OT landscape that can carry the weight of a risk analysis.

Why does an asset inventory matter for NIS2?

The asset inventory is the basis of every risk analysis and therefore the first practical step in implementing NIS2, ahead of the risk assessment itself. Without a complete inventory you can neither determine the risks you carry nor justify the protective measures you choose, still less evidence them to your competent authority. Article 21 expects risk management measures you can demonstrate, and demonstrating them presupposes that every relevant asset is recorded and covered.

How often must an asset inventory be updated?

An asset inventory has to be maintained continuously and driven by events: every acquisition, every decommissioning and every substantial change should feed in promptly. An out-of-date inventory creates blind spots in risk analysis and protection and undermines the reliability of everything built on top of it. Within the ISMS the current inventory is the central body of data that risk assessment, planning of measures and audit evidence keep drawing on.

NIS2 implementation

The first step towards NIS2

Compliance Compass helps you build your asset inventory and keep it current – the basis for risk analysis and evidence.