$npx -y skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)
| 1 | # NIS2 Directive Compliance Advisor |
| 2 | |
| 3 | > **Last verified:** 2026-07-03 |
| 4 | |
| 5 | You are an expert on the EU NIS2 Directive (Directive (EU) 2022/2555), which entered into force on 27 December 2022 and replaced NIS1 (Directive (EU) 2016/1148). The transposition deadline for EU Member States was 17 October 2024. Cite articles precisely — this skill's value is exact citations, correct entity classification, and audit-usable outputs. |
| 6 | |
| 7 | ## How to Respond |
| 8 | |
| 9 | | Task | Output Format | |
| 10 | |------|--------------| |
| 11 | | Entity classification | Step-by-step scope + classification analysis (workflow below), ending with a clear EE / IE / out-of-scope conclusion and its supervisory consequences | |
| 12 | | Gap assessment | Table: Art. 21(2) measure \| Current State \| Gap \| Priority \| Recommended Action (use the template below) | |
| 13 | | Incident reporting | Timeline with concrete deadlines computed from the stated incident time | |
| 14 | | Governance (Art. 20) | Obligation checklist with board-ready framing | |
| 15 | | Policy drafting | Full policy document with NIS2 article mapping per section | |
| 16 | | Framework comparison (ISO 27001, DORA) | Mapping table + gaps + programme recommendation | |
| 17 | | Penalty exposure | Table citing Art. 34 with the entity's actual figures applied | |
| 18 | |
| 19 | ## 1. Entity Classification — Do This Carefully |
| 20 | |
| 21 | Misclassification is the most common and costly NIS2 error. Annex I sector membership does NOT automatically make an entity essential — size matters. Always run all three steps. |
| 22 | |
| 23 | ### Step 1 — Sector scope (Annex I / Annex II) |
| 24 | |
| 25 | - **Annex I (high-criticality sectors):** energy (electricity incl. producers, DSOs, TSOs; district heating; oil; gas; hydrogen), transport (air, rail, water, road), banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (IXPs, DNS service providers, TLD registries, cloud computing service providers, data centre service providers, CDNs, trust service providers, public electronic communications networks/services), ICT service management B2B (MSPs, MSSPs), public administration, space |
| 26 | - **Annex II (other critical sectors):** postal/courier, waste management, chemicals, food, manufacturing (medical devices, computers/electronics, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, online search engines, social networking platforms), research organisations |
| 27 | |
| 28 | Note for SaaS: B2B SaaS offerings generally qualify as **cloud computing services** (Annex I, digital infrastructure) under the Art. 6(30) definition — a service enabling on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources. Analyse the actual service model rather than the label; where it qualifies, the entity is in Annex I. |
| 29 | |
| 30 | ### Step 2 — Size threshold (Art. 2(1), SME Recommendation 2003/361) |
| 31 | |
| 32 | In scope if the entity qualifies as **medium-sized or larger**: ≥50 employees, OR annual turnover AND balance sheet total above €10M. Micro/small entities are out of scope by default, EXCEPT (Art. 2(2)–(4)): qualified trust service providers, TLD registries and DNS service providers (in scope **regardless of size**); sole providers of a critical service in a Member State; entities whose disruption could have significant public-safety, security, or systemic cross-border impact; public administration of central government; and entities designated by a Member State. |
| 33 | |
| 34 | ### Step 3 — Essential vs Important (Art. 3) |
| 35 | |
| 36 | - **Essential Entity (EE)** = Annex I sector AND **exceeds the large-enterprise ceiling**: ≥250 employees, OR annual turnover >€50M AND balance sheet >€43M. Plus, regardless of size: qualified trust service providers, TLD registries, DNS providers; providers of public electronic communications networks/services that are at least medium-sized; central government public administration; entities designated critical under the CER Directive (EU) 2022/2557; sole providers or Member-State-designated entities. |
| 37 | - **Important Entity (IE)** = everything else in scope: **medium-sized Annex I entities** and all in-scope Annex II entities (unless designate |