nis2

Advises on EU NIS2 Directive compliance including entity classification, incident reporting, and gap assessments.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nis2-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nis2
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/nis2
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nis2-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Organizations subject to the EU NIS2 Directive (Directive (EU) 2022/2555) struggle to determine whether they are in scope, how they are classified (essential vs important entity), which of the ten Art. 21 risk-management measures they must implement, and how to meet the strict 24h/72h/1-month incident reporting deadlines. This Skill provides precise, article-cited compliance guidance so teams avoid misclassification, missed deadlines, and penalty exposure. ## Core Features & Use Cases - Entity Classification: Step-by-step Annex I/II sector scoping, size-threshold analysis, and essential vs important entity determination with supervisory consequences. - Gap Assessments & Policy Drafting: Art. 21(2) measure-by-measure gap tables, board-ready Art. 20 governance checklists, and policy documents mapped to NIS2 articles, including the Implementing Regulation (EU) 2024/2690 sub-requirements for digital entities. - Incident Reporting & Penalty Analysis: Computes concrete 24h/72h/1-month reporting deadlines from the time of awareness, coordinates parallel GDPR Art. 33 notification, and quantifies fine exposure under Art. 34. - Use Case: A 200-employee electricity DSO asks whether it is an essential entity and what to do after a ransomware attack. The Skill classifies it as an Important Entity (with the Member-State designation caveat), then produces the full incident reporting timeline with CSIRT notification content and GDPR coordination. ## Quick Start Ask the assistant to classify your organization under NIS2 and produce an Art. 21 gap assessment with an incident reporting readiness plan.

Frequently Asked Questions about nis2

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I know if my company is an essential or important entity under NIS2?

Classification under NIS2 Art. 3 depends on sector and size. Annex I entities exceeding the large-enterprise ceiling (250+ employees, or turnover above €50M with balance sheet above €43M) are essential; medium-sized Annex I and in-scope Annex II entities are important. Some entities like DNS providers and TLD registries are essential regardless of size.

What are the NIS2 incident reporting deadlines?

NIS2 Art. 23 requires an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report within one month. Reports go to the national CSIRT or competent authority, and a parallel GDPR Art. 33 notification may be required if personal data is affected.

Does ISO 27001 certification satisfy NIS2 requirements?

ISO 27001:2022 certification evidences much of Art. 21 but does not satisfy all NIS2 obligations. Gaps remain for Art. 23 reporting timelines, Art. 20 management body accountability and training, Art. 27 registration, and the explicit MFA and cryptography expectations of Art. 21(2)(h) and (j).

Does the Implementing Regulation (EU) 2024/2690 apply to all NIS2 entities?

No, Regulation 2024/2690 binds only DNS providers, TLD registries, cloud, data centre, CDN, MSP, MSSP, online marketplace, search, social platform, and trust service providers. For other sectors it is persuasive best practice rather than directly binding law.

What are the maximum fines for NIS2 non-compliance?

Under Art. 34, essential entities face fines of at least €10,000,000 or 2% of worldwide annual turnover, whichever is higher. Important entities face at least €7,000,000 or 1.4% of turnover, and Member States may set higher maximums in national transposition.

How does NIS2 interact with DORA for financial entities?

DORA (Regulation (EU) 2022/2554) is lex specialis under its Art. 4, so financial entities follow DORA's ICT risk management and incident reporting instead of NIS2 Arts. 21 and 23. They remain registered under NIS2 but report incidents to financial supervisors rather than the CSIRT.