May 22, 2026

Asset Inventory Automation: How Managed Services Solve CMMC's Hardest Control title card

Asset Inventory Automation: How Managed Services Solve CMMC’s Hardest Control

If you’ve asked defense contractors what their hardest CMMC control is to implement, asset inventory comes up consistently. CM.2.061 and CM.2.062 require organizations to establish and maintain baseline configurations for all operational technology, and that starts with knowing exactly what’s in your environment. For most contractors, the gap between what they think is in their network and what actually is can be significant—and that gap is a direct assessment risk.

A visual of an asset inventory dashboard showing discovered devices, operating systems, and compliance status.

Why Asset Inventory Is Genuinely Hard

Most defense contractors don’t have pristine, fully documented environments. Over years of growth, mergers, remote work expansions, and contractor access, shadow assets accumulate: laptops that weren’t formally onboarded, IoT devices on the network, cloud resources spun up and forgotten, test systems running outdated configurations. Manually inventorying a real-world environment is a painful, time-consuming exercise that produces a result that’s already outdated by the time it’s finished.

The CMMC requirement isn’t just to have an inventory—it’s to maintain an accurate, current inventory. That’s where manual approaches fundamentally fail.

What Automated Asset Discovery Looks Like

Modern managed services platforms include automated asset discovery tools that continuously scan your network and cloud environments, identifying every connected device, its hardware and software configuration, and its network behavior. This produces a living asset inventory that updates in real time—not a spreadsheet that reflects the state of your network three months ago.

For Azure Government environments, Microsoft Defender for Cloud and Microsoft Defender for Endpoint both include asset discovery capabilities that integrate natively with your GCC-High tenant. Combined with Microsoft Sentinel for visibility across your full environment, these tools provide continuous asset awareness without manual intervention.

Integrating Asset Inventory with Your CMMC SSP

The asset inventory isn’t just an operational tool—it’s a CMMC evidence artifact. Your SSP should reference your asset inventory methodology, the tool(s) you use to maintain it, and the cadence at which it’s reviewed and validated. C3PAO assessors will expect to see a current, complete asset inventory and evidence that it’s actively maintained.

Automated asset discovery tools typically generate reports that can be directly included in your evidence package—export formats, timestamps, and scan configurations all serve as evidence of the continuous monitoring approach CMMC requires.

Handling Unauthorized Devices

Asset inventory isn’t just about knowing what’s there—it’s about detecting what shouldn’t be. CMMC CM.2.062 requires detecting unauthorized hardware and software. Automated monitoring alerts when previously unknown devices connect to your network, when unauthorized software is installed on managed endpoints, or when devices fall out of compliance with your baseline configuration.

Your managed SOC should receive these alerts in real time and investigate them as potential security incidents. A device that’s not in your inventory and not authorized is, by definition, an anomaly that requires investigation.

Software Inventory: The Often-Overlooked Component

Hardware gets most of the attention in asset inventory discussions, but CMMC requires software inventory as well—both authorized software lists and detection of unauthorized software. Application whitelisting and software inventory capabilities from your endpoint management platform (Microsoft Intune in GCC-High environments) provide the software inventory evidence CMMC requires.

VSO manages hardware and software asset inventory as part of our endpoint management services—maintaining the baseline, detecting deviations, and generating evidence packages for CMMC assessments.

Conclusion

Asset inventory is hard to do manually and impossible to maintain manually at scale. Automated asset discovery, integrated with your managed services and monitoring environment, converts the hardest CMMC control into a managed, continuous capability.

🟢 VSO’s managed services include automated asset discovery and inventory management as a standard component. Contact us to see how we’d approach your environment. — CMMC Managed Services | Contact VSO

Frequently Asked Questions

What CMMC practices does asset inventory directly address?

Asset inventory primarily addresses CM.2.061 (establish baseline configurations) and CM.2.062 (establish operational policies for managing hardware and software), but also supports practices in the Access Control and Configuration Management domains that depend on knowing your environment’s full scope.

How frequently does CMMC require asset inventory to be updated?

The requirement is for a current, maintained inventory—not a specific update frequency. Continuous automated discovery is the best practice and the most defensible approach in an assessment. Manual quarterly inventories may be accepted but are harder to evidence as ‘current.’

How do we handle personally owned devices (BYOD) in our asset inventory?

BYOD is strongly discouraged for environments handling CUI. If you do allow BYOD for non-CUI work, those devices should still appear in your inventory and have clear policy documentation about what they’re permitted to access. For CUI access, company-managed devices with enrollment in your MDM solution are strongly recommended.

What if we discover an unauthorized device during asset inventory?

Treat it as a potential security incident: isolate the device from CUI-accessible network segments, investigate its origin and access history, determine whether CUI was accessed, and document the investigation in accordance with your incident response procedures.

Can we use open-source tools for CMMC asset inventory?

Open-source tools like Nmap can support asset discovery, but they require significant expertise to deploy, maintain, and integrate with your evidence management process. Commercial tools integrated within your managed services platform generally produce more assessment-ready evidence with less operational overhead.

Author Ethan Watts

Share This Story, Choose Your Platform!