The control everyone asks about is an inventory.
Four separate frameworks ask the same question in slightly different words: what hardware do you have, and can you show it. Simpletag produces the evidence. It does not certify you — nothing can, except an assessor.
CMMC and NIST SP 800-171
If you sell to the US defence supply chain, this is the one with a date on it. Certification requirements began appearing in contracts in November 2025, and the second phase lands 10 November 2026.
“Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.”
The assessment objectives ask for manufacturer, device type, model, serial number and physical location. That is the Simpletag record, field for field. Rev. 3 promotes it to a control of its own, 03.04.10 System Component Inventory, and adds that it must be reviewed on a defined frequency and updated on every install and removal — which is the part a spreadsheet fails, not the fields.
You will usually meet this as a supplier questionnaire rather than as an assessment. Lockheed Martin's supplier cybersecurity questionnaire, hosted on Exostar, carries 3.4.1 as a line item you answer Implemented, Addressed with SSP & POAM, Approved Exception, or Not Implemented. Prime contractors are required to flow the DFARS clauses down to subcontractors who handle covered defence information, so the question arrives from your customer long before any assessor does.
What Simpletag gives you for it
A current hardware inventory with the required fields, a record of when each machine was last seen, and a dated reconciliation showing the register was actually maintained rather than assembled the week the questionnaire arrived. The last one is what distinguishes a maintained inventory from a produced one.
The same question, in four other places
| Framework | Where it asks | What it wants |
|---|---|---|
| SOC 2 | CC6.1 | An asset inventory, plus evidence of periodic review. Auditors expect it to cover the whole audit period, not a snapshot taken at the end. |
| ISO 27001:2022 | Annex A 5.9 | “An inventory of information and other associated assets, including owners, should be developed and maintained.” A named owner per asset. |
| PCI DSS 4.0.1 | Req 12.5.1 | An inventory of in-scope system components with a description of function and use, kept current. |
| Cyber insurance | Underwriting | Hardware and software inventory is now its own scored category on renewal questionnaires — typically two direct questions about whether you track deployed assets. |
What we will not tell you.
Answer it before you are asked.
Install the agent on the machines you already own and import the list you already keep. Free for 25 computers.