The asset register your certification asks for
What Cyber Essentials and ISO 27001 expect you to know about your devices and information assets, how a register helps you show it, and what a register does not do.
Both start with knowing what you have
Cyber Essentials and ISO 27001 differ in scale. One is a fixed set of technical controls with a yearly assessment; the other is a management system with a certification audit and a much wider set of controls. They begin in the same place, though: you cannot patch, protect or govern a device you do not know you own. An asset register is the record that answers that question, and it is one of the first things an assessor asks to see.
A caution before the detail. A register on its own does not make you compliant with either scheme, and nothing on this page replaces the scheme's own requirements or a conversation with your assessor. What a register gives you is an accurate, dated inventory to build the other controls on.
What Cyber Essentials expects
In general terms, and without quoting the scheme.
- Know which devices are in scope: the laptops, desktops, servers, phones, tablets and network equipment that can reach your organisation's data, including devices used away from the office.
- Know what each device runs, so you can say whether its operating system and software are still supported by the vendor and still receiving security updates.
- Keep those devices updated, and remove software that is unsupported or no longer needed.
- Decommission devices that are no longer needed, rather than leaving them connected and forgotten.
The assessor is interested in how you know. "We think there are about forty laptops" is a weaker answer than a list with serial numbers, models, operating systems and named users, dated from the last time somebody checked it against the shelves.
What ISO 27001 expects
ISO 27001 takes a broader view of assets. The standard expects an inventory of information and associated assets, with an owner for each, together with rules for acceptable use and for returning assets when someone leaves. The inventory is expected to be maintained, so evidence that it is reviewed and kept current matters as much as the list itself.
Hardware is one part of that inventory, alongside information, software and services. A device register covers the hardware part well, and it can hold the software licences and warranties attached to each device. The wider information inventory usually lives with the management system's own documentation.
How a register helps you evidence it
What Tagaris records, and where it lines up with the questions above.
- One record per device with the serial number, model, category, status and, where you record it, the operating system. Device sync fills the name, serial, model and operating system from Microsoft Intune or Jamf without typing (free beta).
- A named person or location on every asset. For ISO purposes the owner can be the assignee, or a custom field if the accountable owner is not the day-to-day user.
- A dated history of every change: assignment, status, location, check-out and check-in, audit and disposal. This is the "how do you know" answer.
- Check-out and check-in for joiners and leavers, so the return of equipment is recorded rather than assumed. See check-out and audits.
- The physical audit workflow: an audit interval per category, a stock-take list of what is due, and a dated confirmation on each asset when it is checked.
- Warranty expiry and replacement-due flags on the dashboard and in the daily digest, which is where end-of-life kit tends to surface first.
- A disposal record with the date, method and proceeds, so a decommissioned device leaves the in-scope list with a trail. See asset lifecycle.
- Export at any time: the assets list to CSV, any report to CSV, or a full organisation export to JSON, so the assessor gets a file.
- On Team plans, an audit log of who changed what across the register, with CSV export.
For the assessor the practical output is usually three things: the current in-scope list, the history showing it is maintained, and evidence of the last physical check. All three are exports from the register. The working with assets guide in the documentation covers the day-to-day mechanics.
What a register does not do
A register records; it does not enforce. It is not a vulnerability scanner and will not tell you that a device is missing a patch. It is not mobile device management and will not push a configuration, wipe a lost phone or block an unsupported operating system. It does not know when a vendor ends support for an operating system unless you record that date yourself. And it has nothing to say about firewalls, access control or malware protection, which the schemes also assess.
Treat it as the inventory the other controls hang off. The patching tool works its list, the MDM enrols its list, and the register is where you check that those lists agree with what you actually own. If devices are in Intune or Jamf, syncing them into the register is the quickest way to find the ones that are enrolled but unrecorded, or recorded but never enrolled. The security page covers how Tagaris itself is built and run, for the part of the questionnaire that asks about the tool.
Related guides: all guides, how to run a physical IT asset audit and how to create an IT asset register.
See what the evidence looks like
The live demo is a full register with history, audits and exports on a realistic dataset. No sign-up, and it resets nightly.