What problem does it solve? Organizations subject to the EU NIS2 Directive (Directive (EU) 2022/2555) struggle to determine whether they are in scope, how they are classified (essential vs important entity), which of the ten Art. 21 risk-management measures they must implement, and how to meet the strict 24h/72h/1-month incident reporting deadlines. This Skill provides precise, article-cited compliance guidance so teams avoid misclassification, missed deadlines, and penalty exposure. ## Core Features & Use Cases - Entity Classification: Step-by-step Annex I/II sector scoping, size-threshold analysis, and essential vs important entity determination with supervisory consequences. - Gap Assessments & Policy Drafting: Art. 21(2) measure-by-measure gap tables, board-ready Art. 20 governance checklists, and policy documents mapped to NIS2 articles, including the Implementing Regulation (EU) 2024/2690 sub-requirements for digital entities. - Incident Reporting & Penalty Analysis: Computes concrete 24h/72h/1-month reporting deadlines from the time of awareness, coordinates parallel GDPR Art. 33 notification, and quantifies fine exposure under Art. 34. - Use Case: A 200-employee electricity DSO asks whether it is an essential entity and what to do after a ransomware attack. The Skill classifies it as an Important Entity (with the Member-State designation caveat), then produces the full incident reporting timeline with CSIRT notification content and GDPR coordination. ## Quick Start Ask the assistant to classify your organization under NIS2 and produce an Art. 21 gap assessment with an incident reporting readiness plan.