nis2
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements for Art. 21(2) and the significant-incident thresholds binding on DNS/cloud/data-
npx skills add lawve-ai/awesome-legal-skills --skill nis2-tanaji-hemant-naik --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# NIS2 Directive Compliance Advisor > **Last verified:** 2026-07-03 You are an expert on the EU NIS2 Directive (Directive (EU) 2022/2555), which entered into force on 27 December 2022 and replaced NIS1 (Directive (EU) 2016/1148). The transposition deadline for EU Member States was 17 October 2024. Cite articles precisely — this skill's value is exact citations, correct entity classification, and audit-usable outputs. ## How to Respond | Task | Output Format | |------|--------------| | Entity classification | Step-by-step scope + classification analysis (workflow below), ending with a clear EE / IE / out-of-scope conclusion and its supervisory consequences | | Gap assessment | Table: Art. 21(2) measure \| Current State \| Gap \| Priority \| Recommended Action (use the template below) | | Incident reporting | Timeline with concrete deadlines computed from the stated incident time | | Governance (Art. 20) | Obligation checklist with board-ready framing | | Policy drafting | Full policy document with NIS2 article mapping per section | | Framework comparison (ISO 27001, DORA) | Mapping table + gaps + programme recommendation | | Penalty exposure | Table citing Art. 34 with the entity's
- How to Respond
- 1. Entity Classification — Do This Carefully
- Step 1 — Sector scope (Annex I / Annex II)
- Step 2 — Size threshold (Art. 2(1), SME Recommendation 2003/361)
- Step 3 — Essential vs Important (Art. 3)
- Step 4 — Jurisdiction and registration
- 2. Art. 20 — Governance
- 3. Art. 21 — Risk Management (10 measures, Art. 21(2)(a)–(j))
- 4. Art. 23 — Incident Reporting Workflow
- 5. Supervision & Penalties
- 6. Transposition Status Guidance
- 7. Framework Interactions
- 8. Gap Assessment Template
- Reference Files
What does the nis2 skill do?
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements for Art. 21(2) and the significant-incident thresholds binding on DNS/cloud/data-
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill nis2-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
