Endpoint management covers unified endpoint management (UEM), mobile device management (MDM), software distribution and workplace policy. IT departments use it to set up, update and secure laptops, phones and tablets, and to wipe them remotely if a device is lost. Microsoft Intune and Jamf are well-known non-European reference points.
Such a management environment holds rights few other systems have: it can install software on any device, change settings and erase data. Whoever takes over the management console or channel reaches the whole fleet at once. The inventory, device location and app usage are also personal data about employees. The policy you build up over the years, such as profiles, compliance rules and installation packages, is often shaped around one vendor's model. NIS2 expects organisations in covered sectors to take risk-management measures, and a management layer with this much reach belongs in that assessment.
When choosing a European option, look for a variant you can host yourself, support for several operating systems, policy you can export as code or in an open format, strict separation of administrator roles with full audit logs, and operation in an isolated network. Also ask what data about employees is collected and whether you can limit it.