nis2-directive-specialist
NIS2 Directive (EU 2022/2555) compliance automation. Analyzes organizational scope, assesses compliance against all 10 minimum security measures, validates incident reporting readiness, and generates gap analysis reports. Use for NIS2 compliance assessments, critical infrastructure cybersecurity planning, supply chain security evaluation, and incident reporting preparation.
What this skill does
# NIS2 Directive Specialist Tools and guidance for EU Directive 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). --- ## Table of Contents - [NIS2 Overview](#nis2-overview) - [Scope and Applicability](#scope-and-applicability) - [10 Minimum Security Measures](#10-minimum-security-measures-article-21) - [Incident Reporting Requirements](#incident-reporting-requirements) - [Management Accountability](#management-accountability-article-20) - [Supply Chain Security](#supply-chain-security-deep-dive) - [Penalties](#penalties) - [NIS2 vs NIS1 Comparison](#nis2-vs-nis1-comparison) - [Infrastructure Security Checks](#infrastructure-security-checks) - [Tools](#tools) - [Reference Guides](#reference-guides) - [Compliance Assessment Workflow](#compliance-assessment-workflow) - [NIS2 Implementation Roadmap](#nis2-implementation-roadmap) --- ## NIS2 Overview The **NIS2 Directive (EU 2022/2555)** is the EU's updated framework for cybersecurity, replacing the original NIS Directive (EU 2016/1148). It entered into force on January 16, 2023, with Member States required to transpose it into national law by **October 17, 2024**. **Key objectives:** - Establish a high common level of cybersecurity across the EU - Harmonize cybersecurity requirements and enforcement - Expand scope to cover more sectors and entities - Strengthen incident reporting obligations - Introduce management accountability for cybersecurity - Enhance supply chain security requirements **Legal basis:** Article 114 TFEU (internal market harmonization) **Relationship to other frameworks:** | Framework | Relationship | |-----------|-------------| | ISO 27001 | NIS2 measures map closely to ISO 27001 controls | | GDPR | NIS2 complements GDPR for security of processing | | CER Directive | Critical Entities Resilience — physical security complement | | DORA | Lex specialis for financial sector entities | | Cyber Resilience Act | Product security requirements for hardware/software | --- ## Scope and Applicability ### Essential Entities (Annex I — High Criticality Sectors) | Sector | Sub-sectors | |--------|------------| | **Energy** | Electricity (DSOs, TSOs, producers, storage), oil (pipelines, production, refineries, storage), gas (DSOs, TSOs, LNG, storage), hydrogen, district heating/cooling | | **Transport** | Air (carriers, airports, traffic management), rail (infrastructure managers, operators), water (inland, maritime, port operators), road (traffic management, ITS operators) | | **Banking** | Credit institutions as defined in Regulation (EU) No 575/2013 | | **Financial market infrastructure** | Trading venues, central counterparties | | **Health** | Healthcare providers, EU reference laboratories, entities manufacturing pharmaceutical products, entities manufacturing medical devices considered critical during public health emergencies | | **Drinking water** | Suppliers and distributors of water intended for human consumption | | **Waste water** | Entities collecting, disposing, or treating urban waste water, domestic waste water, or industrial waste water | | **Digital infrastructure** | IXPs, DNS providers, TLD registries, cloud computing providers, data center operators, CDN providers, trust service providers, public electronic communications networks, publicly available electronic communications services | | **ICT service management (B2B)** | Managed service providers, managed security service providers | | **Public administration** | Central government entities, regional government entities at NUTS level 1 and 2 | | **Space** | Operators of ground-based infrastructure supporting space-based services | ### Important Entities (Annex II — Other Critical Sectors) | Sector | Sub-sectors | |--------|------------| | **Postal and courier services** | Providers of postal services including courier services | | **Waste management** | Entities carrying out waste management (excluding those for whom waste management is not their principal economic activity) | | **Chemicals** | Entities manufacturing, producing, or distributing chemical substances and mixtures | | **Food** | Food businesses engaged in wholesale distribution, industrial production, and processing | | **Manufacturing** | Medical devices and in vitro diagnostics, computer/electronic/optical products, electrical equipment, machinery and equipment, motor vehicles/trailers, other transport equipment | | **Digital providers** | Online marketplaces, online search engines, social networking services platforms | | **Research** | Research organizations | ### Size Thresholds | Category | Employees | Annual Turnover | Annual Balance Sheet | |----------|-----------|----------------|---------------------| | **Medium enterprise** | 50–249 | €10M–€50M | €10M–€43M | | **Large enterprise** | 250+ | €50M+ | €43M+ | **Automatic inclusion regardless of size:** - Trust service providers - TLD name registries - DNS service providers - Public electronic communications networks/services - Public administration entities - Sole provider of a service in a Member State - Entity whose disruption could have significant impact on public safety, security, or health - Entity whose disruption could induce systemic risk (especially cross-border) **Exclusions:** - Micro and small enterprises (generally excluded unless specifically designated) - National security, public security, defense, law enforcement - Judiciary, parliaments, central banks --- ## 10 Minimum Security Measures (Article 21) All essential and important entities must implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. These measures must be based on an **all-hazards approach** and cover at minimum: ### 1. Risk Analysis and Information System Security Policies Establish and maintain comprehensive risk analysis processes and information security policies covering all information systems. **Requirements:** - Formal risk assessment methodology - Asset inventory and classification - Security policy framework (approved by management body) - Regular policy review cycles (at least annually) - Risk appetite and tolerance definitions - Documented risk treatment plans ### 2. Incident Handling Implement procedures for detecting, managing, and responding to cybersecurity incidents. **Requirements:** - Incident detection capabilities - Incident classification and triage procedures - Incident response plans and playbooks - Incident escalation procedures - Post-incident review process - Integration with CSIRT reporting (see Incident Reporting section) ### 3. Business Continuity and Crisis Management Ensure service continuity during and after cybersecurity incidents. **Requirements:** - Business impact analysis (BIA) - Business continuity plans (BCP) - Disaster recovery plans (DRP) - Backup management policies - Crisis management procedures - Regular testing of continuity plans (at least annually) - Recovery time objectives (RTO) and recovery point objectives (RPO) ### 4. Supply Chain Security Address security risks in relationships with direct suppliers and service providers. **Requirements:** - Supplier risk assessment process - Security requirements in contracts with suppliers - Monitoring of supplier security posture - Supplier incident notification requirements - Assessment of aggregate supply chain risks - Product/service quality and cybersecurity practices of suppliers ### 5. Security in Network and Information Systems Acquisition, Development, and Maintenance Integrate security throughout the system lifecycle. **Requirements:** - Secure development lifecycle (SDLC) practices - Vulnerability management procedures - Security testing (SAST, DAST, penetration testing) - Patch management processes - Change management with security review - Secure configuration management ### 6. Policies and Procedures for Assessing Effectiveness Evaluate whether cybersecurity risk
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.