Eight months into NIS2 in Germany, the German internet industry association eco asked companies in its network what the hardest part of implementation had been. Evidence requirements and audits came out top at around 26% of responses, ahead of incident reporting under the 24 and 72 hour clock at around 25%, and ahead of risk analysis and management at around 21%.
Read that ordering again. Companies that are engaged enough with cybersecurity to be in eco's network find it harder to prove what they did about a risk than to work out what the risk was.
This piece covers what NIS2 actually asks for on the IT asset side, why the evidence half is the part that stalls, how the national patchwork changes what applies to you, and what an auditable device record looks like in practice.
What does NIS2 require about IT assets?
Because they're different jobs, and the second one is a systems problem. Risk analysis happens in a room. Somebody with the right knowledge works out that unreturned laptops are a risk, writes it down, and proposes a control. That's a day of good thinking and it's genuinely finishable.
Evidence is continuous. It means being able to say, for a named device, on a named date, who held it and what happened to it, and to say that on demand rather than after a week of reconstruction. Nobody can be expert enough to fix that. It's either a by-product of how your systems already work, or it's a project you run every time someone asks.
Ulrich Plate, who leads eco's KRITIS Competence Group, put the sequencing plainly when the survey came out: "The work does not end with registration. What matters now is that companies translate the regulatory requirements into effective processes: clear responsibilities, robust reporting channels, documented risks and functioning supply chain management."
Is NIS2 the same in every EU country?
No, and this is the part that catches multi-country organisations. NIS2 is a directive, so each member state transposes it into national law with its own scope decisions, thresholds, regulator and timetable. The transposition deadline was 17 October 2024. In November 2024 the Commission opened letters of formal notice against 23 member states at once, and the gap has not fully closed since.
As of this autumn: Belgium, Denmark, Greece, Hungary, Italy, Malta and Slovakia have laws on the books. Germany and France arrived late and are still bedding their regimes in. The Netherlands switched its Cyberbeveiligingswet on 15 August 2026. Ireland was referred to the Court of Justice on 8 July 2026 for not transposing at all, with the Irish Times reporting a 2.8 million euro lump sum plus daily fines in prospect.
For a manufacturer with sites in four countries, that means registering under four entity classifications, reporting incidents to four national teams, and arguing four readings of what counts as significant.

What does an auditable device record look like?
Four properties, and the first one does most of the work.
- It's current without anyone maintaining it. An inventory that depends on somebody updating a sheet is accurate on the day it's touched and drifting every day after. The record has to be fed from the systems that already know: the MDM for devices, the HR system for people and leave dates, the supplier for what was ordered.
- Every asset has an owner, not a location. "In the Stockholm office" isn't an answer to who holds it. Assignment to a named person is what makes the return obligation enforceable.
- Offboarding produces a receipt, not an assumption. The return has to be tracked to confirmed receipt, and the confirmation has to land somewhere a third party could read. This is where most processes quietly stop: the laptop comes back, and the only record of it coming back is somebody's memory.
- Software and subscriptions close with the person. Licences revoked or reassigned, mobile subscriptions terminated. Access that outlives employment is the access-control half of the same requirement.
Assemble those four from nothing and it's a project. Get them as a by-product of running the IT lifecycle in one place and the audit has somewhere defensible to begin.
Where does the Cyber Resilience Act fit?
NIS2 is rarely the only thing on the desk. The Cyber Resilience Act sits next to it and runs the other way round: NIS2 puts duties on the organisations operating the systems, while the CRA puts them on whoever makes the products with digital elements. The Commission has signalled it may align the two, and DORA with them, through a digital omnibus.
For an IT team the practical link is the notification. When a manufacturer discloses an actively exploited vulnerability, that disclosure is only actionable for the organisation that can immediately say which of its people are on the affected product, and which version they are running. Otherwise the notification arrives and starts a week of asking around.
Same register, second regulation. Which is the argument for building it once rather than once per framework.

Where to start if you're in scope
A policy and a register are two different jobs. The policy defines what good looks like, which is often where an external advisor earns their fee. The register is what makes it evidenceable, and a policy is quick to write and impossible to evidence without the register underneath it.
Connect the MDM and HRIS you already have, get every device attached to a named person, then make the leaver process produce a confirmed receipt rather than a completed checklist. That sequence gives you something to show for the asset-management area while the other nine are still being scoped.
NIS2 covers ten areas and this is one of them. It's also the one where the gap between knowing and proving is widest, and the one you can close first.
Read the Swedish version of this article.
Velory runs IT lifecycle management across hardware, software and SaaS, and mobile subscriptions, from provisioning through certified end-of-life. Start with one connector and see your IT estate in days.




