simpletagASSET TRACKING
Compliance

The control everyone asks about is an inventory.

Four separate frameworks ask the same question in slightly different words: what hardware do you have, and can you show it. Simpletag produces the evidence. It does not certify you — nothing can, except an assessor.

CMMC and NIST SP 800-171

If you sell to the US defence supply chain, this is the one with a date on it. Certification requirements began appearing in contracts in November 2025, and the second phase lands 10 November 2026.

3.4.1NIST SP 800-171 Rev. 2 · Configuration Management

“Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.”

The assessment objectives ask for manufacturer, device type, model, serial number and physical location. That is the Simpletag record, field for field. Rev. 3 promotes it to a control of its own, 03.04.10 System Component Inventory, and adds that it must be reviewed on a defined frequency and updated on every install and removal — which is the part a spreadsheet fails, not the fields.

You will usually meet this as a supplier questionnaire rather than as an assessment. Lockheed Martin's supplier cybersecurity questionnaire, hosted on Exostar, carries 3.4.1 as a line item you answer Implemented, Addressed with SSP & POAM, Approved Exception, or Not Implemented. Prime contractors are required to flow the DFARS clauses down to subcontractors who handle covered defence information, so the question arrives from your customer long before any assessor does.

What Simpletag gives you for it

A current hardware inventory with the required fields, a record of when each machine was last seen, and a dated reconciliation showing the register was actually maintained rather than assembled the week the questionnaire arrived. The last one is what distinguishes a maintained inventory from a produced one.

The same question, in four other places

FrameworkWhere it asksWhat it wants
SOC 2CC6.1An asset inventory, plus evidence of periodic review. Auditors expect it to cover the whole audit period, not a snapshot taken at the end.
ISO 27001:2022Annex A 5.9“An inventory of information and other associated assets, including owners, should be developed and maintained.” A named owner per asset.
PCI DSS 4.0.1Req 12.5.1An inventory of in-scope system components with a description of function and use, kept current.
Cyber insuranceUnderwritingHardware and software inventory is now its own scored category on renewal questionnaires — typically two direct questions about whether you track deployed assets.

What we will not tell you.

Simpletag does not make you compliant.No software does. Frameworks are assessed against people and process as well as records. Simpletag produces one input — an accurate hardware inventory and the evidence it has been maintained — which happens to be the input most often missing.
We do not claim a HIPAA inventory requirement.A rule proposing a technology asset inventory and network map was published for comment in January 2025. It is a proposal. Until it is final we will not sell against it, and you should be wary of anyone who does.
We do not quote statistics we cannot source.This market is full of confident percentages that trace back to a vendor blog. Where we cite a number, we cite where it came from.

Answer it before you are asked.

Install the agent on the machines you already own and import the list you already keep. Free for 25 computers.

Start free Ask a question