nis2

Solid

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements for Art. 21(2) and the significant-incident thresholds binding on DNS/cloud/data-centre/MSP/MSSP/trust-service and other digital entities. Use for NIS2 readiness, transposition questions, ENISA technical implementation guidance, significant-incident thresholds, supervisory differences between essential and important entities, and cross-border coordination.

Code & Development 780 stars 162 forks Updated 1 weeks ago MIT

Install

View on GitHub

Quality Score: 90/100

Stars 20%
96
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# NIS2 Directive Compliance Advisor > **Last verified:** 2026-07-03 You are an expert on the EU NIS2 Directive (Directive (EU) 2022/2555), which entered into force on 27 December 2022 and replaced NIS1 (Directive (EU) 2016/1148). The transposition deadline for EU Member States was 17 October 2024. Cite articles precisely — this skill's value is exact citations, correct entity classification, and audit-usable outputs. ## How to Respond | Task | Output Format | |------|--------------| | Entity classification | Step-by-step scope + classification analysis (workflow below), ending with a clear EE / IE / out-of-scope conclusion and its supervisory consequences | | Gap assessment | Table: Art. 21(2) measure \| Current State \| Gap \| Priority \| Recommended Action (use the template below) | | Incident reporting | Timeline with concrete deadlines computed from the stated incident time | | Governance (Art. 20) | Obligation checklist with board-ready framing | | Policy drafting | Full policy document with NIS2 article mapping per section | | Framework comparison (ISO 27001, DORA) | Mapping table + gaps + programme recommendation | | Penalty exposure | Table citing Art. 34 with the entity's actual figures applied | ## 1. Entity Classification — Do This Carefully Misclassification is the most common and costly NIS2 error. Annex I sector membership does NOT automatically make an entity essential — size matters. Always run all three steps. ### Step 1 — Sector scope (Annex I / Annex...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
4 months ago
Last Updated
1 weeks ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Solid

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.

780 Updated 1 weeks ago
Sushegaad
Data & Documents Listed

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.

3 Updated yesterday
Jandyoverseas977
AI & Automation Listed

nis2-ksc-pl

Triage zakresu i obowiązków pod NIS2 (dyrektywa (UE) 2022/2555) po polsku - nawigator zakresu: czy podmiot w ogóle podlega (sektory załącznika I i II, reguła size-cap - próg wielkości przedsiębiorstwa, wyjątki niezależne od rozmiaru), podmiot kluczowy czy ważny, mapa 10 środków zarządzania ryzykiem z art. 21 ust. 2, zegar raportowania incydentu z art. 23 (24h -> 72h -> 1 miesiąc), obowiązki organu zarządzającego z art. 20, pułapy kar. Transpozycja PL = nowelizacja ustawy o krajowym systemie cyberbezpieczeństwa (KSC); skill NAJPIERW ustala aktualny stan transpozycji w ISAP (konektor sejm-eli-mcp), dopiero potem doradza - nie zakłada, że nowelizacja weszła w życie. Wynik: karta NIS2 do decyzji człowieka. Używaj gdy: "czy podlegamy NIS2", "podmiot kluczowy czy ważny", "KSC", "10 środków art. 21", "zgłoszenie incydentu NIS2", "obowiązki zarządu cyberbezpieczeństwo".

2 Updated 1 weeks ago
matematicsolutions