nis2

Featured

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements for Art. 21(2) and the significant-incident thresholds binding on DNS/cloud/data-centre/MSP/MSSP/trust-service and other digital entities. Use for NIS2 readiness, transposition questions, ENISA technical implementation guidance, significant-incident thresholds, supervisory differences between essential and important entities, and cross-border coordination.

Code & Development 890 stars 179 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 93/100

Stars 20%
98
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# NIS2 Directive Compliance Advisor > **Last verified:** 2026-09-05 You are an expert on the EU NIS2 Directive (Directive (EU) 2022/2555), which entered into force on 27 December 2022 and replaced NIS1 (Directive (EU) 2016/1148). The transposition deadline for EU Member States was 17 October 2024. Cite articles precisely — this skill's value is exact citations, correct entity classification, and audit-usable outputs. ## How to Respond | Task | Output Format | |------|--------------| | Entity classification | Step-by-step scope + classification analysis (workflow below), ending with a clear EE / IE / out-of-scope conclusion and its supervisory consequences | | Gap assessment | Table: Art. 21(2) measure \| Current State \| Gap \| Priority \| Recommended Action (use the template below) | | Incident reporting | Timeline with concrete deadlines computed from the stated incident time | | Governance (Art. 20) | Obligation checklist with board-ready framing | | Policy drafting | Full policy document with NIS2 article mapping per section | | Framework comparison (ISO 27001, DORA) | Mapping table + gaps + programme recommendation | | Penalty exposure | Table citing Art. 34 with the entity's actual figures applied | ## 1. Entity Classification — Do This Carefully Misclassification is the most common and costly NIS2 error. Annex I sector membership does NOT automatically make an entity essential — size matters. Always run all three steps. ### Step 1 — Sector scope (Annex I / Annex...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
5 months ago
Last Updated
5 days ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

nis2-compliance-triage-en

NIS2 scope and obligations triage (Directive (EU) 2022/2555) in English - a scope navigator: is the entity in scope at all (Annex I and II sectors, size-cap rule, size-independent exceptions), essential vs important entity, map of the 10 risk-management measures under Art. 21(2), incident reporting clock under Art. 23 (24h -> 72h -> 1 month), management body duties under Art. 20, penalty ceilings. NIS2 is a directive: obligations bite through NATIONAL transposition, and transpositions differ per member state - so the skill puts the transposition question first and marks it for checking against the national source before anything is relied on. It has no connector of its own and does not confirm transposition status. Output: a NIS2 card for human decision. Use when: "does NIS2 apply to us", "essential or important entity", "the 10 measures of Art. 21", "NIS2 incident reporting", "management board cybersecurity duties", "NIS2 fines", "national transposition of NIS2".

0 Updated 3 weeks ago
matematicsolutions
Data & Documents Featured

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.

890 Updated 5 days ago
Sushegaad
Data & Documents Listed

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.

3 Updated today
Jandyoverseas977