nis2

Classify network security scope and assess control gaps under EU NIS2 standards.

811|169|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nis2
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps organizations understand and implement the EU NIS2 Directive's cybersecurity requirements, including entity classification, risk management, and incident reporting timelines.

Core Features & Use Cases

  • Entity Classification & Gap Assessment: Identify if an organization qualifies as an essential or important entity under NIS2 and evaluate control gaps.
  • Incident Reporting & Workflow Guidance: Provide step-by-step assistance for timely incident detection, notification, and final reporting within the specified 24-hour, 72-hour, and one-month windows.
  • Policy & Governance Support: Assist in drafting policies aligned with NIS2 governance and management obligations, including compliance with Art. 20, 21, and supply chain security mandates.
  • ISO 27001 Alignment: Map existing controls to NIS2 requirements, offering recommendations for strengthening security posture.

Quick Start

Ask the NIS2 Skill to help draft incident response policies and run risk assessments for compliance readiness.

Frequently Asked Questions about nis2

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I know if my organization qualifies as an essential or important entity under EU NIS2?

To determine NIS2 entity classification, you must evaluate your organization's sector, size, and criticality against the directive's scope definitions. This Skill guides compliance teams through network security scope classification to identify whether the organization qualifies as an essential or important entity.

What are the NIS2 incident reporting timelines and how do I manage the notification workflow?

NIS2 incident reporting requires early warning within 24 hours, detailed notification within 72 hours, and a final report within one month. This Skill provides step-by-step workflow guidance for timely incident detection, notification, and final reporting to meet these strict deadlines.

How do I map ISO 27001 controls to NIS2 requirements for a gap assessment?

You can map existing ISO 27001 controls to NIS2 requirements by evaluating control gaps within your network security scope. This Skill requires a detailed understanding of NIS2 Articles and ISO 27001 mappings to offer recommendations for strengthening your security posture.

How do I draft cybersecurity policies aligned with NIS2 governance and supply chain security mandates?

Drafting NIS2 compliant policies involves aligning governance and management obligations with Articles 20 and 21, alongside supply chain security mandates. This Skill assists in policy development and guides compliance teams through the necessary governance obligations.

Does NIS2 compliance require a formal risk assessment for essential and important entities?

NIS2 compliance requires essential and important entities to implement formal risk management processes and assess control gaps. This Skill helps organizations run risk assessments for compliance readiness and evaluate network security scope according to EU standards.

What is the best way to prepare for a NIS2 compliance audit?

The best way to prepare for a NIS2 compliance audit is to classify your entity status, assess control gaps against ISO 27001 mappings, and finalize incident reporting policies. This Skill guides compliance teams through governance obligations and supply chain security management for comprehensive readiness.