nis2 scope audit

    by Elyas Shukri Elmi

    1

    Determines NIS2 scope, entity classification, and readiness gaps based on sector, size, and EU Member State law.

    Secure checkout via Stripe

    0 installsSecurity scanned

    Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurf+15 more

    See it in action

    You say

    We are a German-based energy provider with 200 employees and €45M turnover. Are we in scope for NIS2, and what is our classification?

    Your agent does

    Classification: Important Entity (Annex I sector, Medium-sized). Jurisdiction: Germany (BSIG/NIS2UmsuCG). Key Gaps: Article 21 risk policies and Article 23 incident reporting (24h/72h/1m). Note: Confirm German transposition status as national laws may lower the 'Essential' threshold.

    What you get

    Categorize entities as Essential or Important based on Annex I/II criteria.Navigate the DORA lex specialis carve-out for financial institutions.Map jurisdictional obligations based on the main-establishment rule.Audit readiness against Article 21 and 23 regulatory baselines.

    About this skill

    The problem

    Most NIS2 compliance assessments fail by treating the directive as a uniform EU regulation. They often miss critical national transposition variances and incorrectly assume financial entities have a blanket exemption due to DORA.

    What it does

    • Determines NIS2 scope by mapping entity activities against Annex I and II criticality sectors.
    • Classifies entities as Essential or Important based on staff count, turnover, and balance sheet thresholds.
    • Identifies jurisdictional conflicts by determining which EU Member State's specific transposition law applies.
    • Performs a DORA equivalence test to verify which obligations are displaced and which remain under NIS2.
    • Generates a baseline readiness gap map against Article 21 risk measures and Article 23 reporting timelines.

    Why this beats prompting it yourself

    Generic prompts treat NIS2 as a static checklist. This skill accounts for the directive's nature as a national-law floor, preventing expensive classification errors and ensuring border entities don't overlook sub-threshold exceptions or Member State specific gold-plating.

    Use cases

    • Determining if a medium-sized ICT provider is an "Essential" or "Important" entity.
    • Audit preparation for cross-border entities needing to identify their lead supervisory authority.
    • Pre-screening financial institutions to map the overlap between DORA and NIS2 Article 4.
    • Conducting a baseline gap analysis for Article 21 cybersecurity risk-management measures.

    Known limitations

    Does not cover Cyber Resilience Act product requirements. Classification remains advisory, as national authorities are the ultimate arbiters of legal status.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    Listedtoday

    Creator

    Frequently Asked Questions

    Popular in Business & Operations