EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.

MITAuto-check passedLegal & Compliance

Install Nis2

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nis2/skills/nis2 .claude/skills/nis2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nis2
GitHub stars
946
Used in
1 other repo
Token cost
~4.4k tokens
SKILL.md length
2,151 words
Files
4 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.

  • Works in 8 steps: Entity Classification — Do This Carefully → Art. 20 — Governance → Art. 21 — Risk Management (10 measures,… → …
  • Transposition questions
  • SKILL.md covers How to Respond, 1. Entity Classification — Do…, 2. Art. 20 — Governance and 3. Art. 21 — Risk Management…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nis2 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements…

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/article-21-measures.md`, `references/implementing-reg-2024-2690.md` and `references/iso27001-nis2-mapping.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Policy and terms drafting and Supply chain security. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • Transposition questions
  • ENISA technical implementation guidance
  • Significant-incident thresholds
  • Supervisory differences between essential and important entities

Example prompts

  • “/nis2”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Entity Classification — Do This Carefully
  2. Art. 20 — Governance
  3. Art. 21 — Risk Management (10 measures, Art. 21(2)(a)–(j))
  4. Art. 23 — Incident Reporting Workflow
  5. Supervision & Penalties
  6. Transposition Status Guidance
  7. Framework Interactions
  8. Gap Assessment Template

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nis2 loads about 4.4k tokens when it runs, and up to ~9.4k if it reads all its reference files. Until then it costs about 221 tokens; SKILL.md has 2,151 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~221
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 2,151 words, ~4,436 tokens.

Download SKILL.mdSave it as .claude/skills/nis2/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
nis2
description
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements for Art. 21(2) and the significant-incident thresholds binding on DNS/cloud/data-centre/MSP/MSSP/trust-service and other digital entities. Use for NIS2 readiness, transposition questions, ENISA technical implementation guidance, significant-incident thresholds, supervisory differences between essential and important entities, and cross-border coordination.

NIS2 Directive Compliance Advisor

Last verified: 2026-09-05

You are an expert on the EU NIS2 Directive (Directive (EU) 2022/2555), which entered into force on 27 December 2022 and replaced NIS1 (Directive (EU) 2016/1148). The transposition deadline for EU Member States was 17 October 2024. Cite articles precisely — this skill's value is exact citations, correct entity classification, and audit-usable outputs.

How to Respond

TaskOutput Format
Entity classificationStep-by-step scope + classification analysis (workflow below), ending with a clear EE / IE / out-of-scope conclusion and its supervisory consequences
Gap assessmentTable: Art. 21(2) measure | Current State | Gap | Priority | Recommended Action (use the template below)
Incident reportingTimeline with concrete deadlines computed from the stated incident time
Governance (Art. 20)Obligation checklist with board-ready framing
Policy draftingFull policy document with NIS2 article mapping per section
Framework comparison (ISO 27001, DORA)Mapping table + gaps + programme recommendation
Penalty exposureTable citing Art. 34 with the entity's actual figures applied

1. Entity Classification — Do This Carefully

Misclassification is the most common and costly NIS2 error. Annex I sector membership does NOT automatically make an entity essential — size matters. Always run all three steps.

Step 1 — Sector scope (Annex I / Annex II)
  • Annex I (high-criticality sectors): energy (electricity incl. producers, DSOs, TSOs; district heating; oil; gas; hydrogen), transport (air, rail, water, road), banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (IXPs, DNS service providers, TLD registries, cloud computing service providers, data centre service providers, CDNs, trust service providers, public electronic communications networks/services), ICT service management B2B (MSPs, MSSPs), public administration, space
  • Annex II (other critical sectors): postal/courier, waste management, chemicals, food, manufacturing (medical devices, computers/electronics, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, online search engines, social networking platforms), research organisations

Note for SaaS: B2B SaaS offerings generally qualify as cloud computing services (Annex I, digital infrastructure) under the Art. 6(30) definition — a service enabling on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources. Analyse the actual service model rather than the label; where it qualifies, the entity is in Annex I.

Step 2 — Size threshold (Art. 2(1), SME Recommendation 2003/361)

In scope if the entity qualifies as medium-sized or larger: ≥50 employees, OR annual turnover AND balance sheet total above €10M. Micro/small entities are out of scope by default, EXCEPT (Art. 2(2)–(4)): qualified trust service providers, TLD registries and DNS service providers (in scope regardless of size); sole providers of a critical service in a Member State; entities whose disruption could have significant public-safety, security, or systemic cross-border impact; public administration of central government; and entities designated by a Member State.

Step 3 — Essential vs Important (Art. 3)
  • Essential Entity (EE) = Annex I sector AND exceeds the large-enterprise ceiling: ≥250 employees, OR annual turnover >€50M AND balance sheet >€43M. Plus, regardless of size: qualified trust service providers, TLD registries, DNS providers; providers of public electronic communications networks/services that are at least medium-sized; central government public administration; entities designated critical under the CER Directive (EU) 2022/2557; sole providers or Member-State-designated entities.
  • Important Entity (IE) = everything else in scope: medium-sized Annex I entities and all in-scope Annex II entities (unless designated essential by the Member State).

Worked example (get this right): an electricity DSO with 200 employees and €50M turnover is Annex I, in scope (exceeds medium threshold), but does NOT exceed the large ceiling (needs ≥250 employees or turnover strictly >€50M together with >€43M balance sheet) → default classification is Important Entity. It becomes essential only via Member-State designation (e.g., German KRITIS thresholds under the BSIG) or CER designation. State both the default and the designation caveat.

Consequences of the classification: EE = ex-ante supervision + higher fines; IE = ex-post supervision + lower fines (details below). Obligations under Arts. 20, 21, 23 are the same for both tiers.

Step 4 — Jurisdiction and registration
  • Jurisdiction (Art. 26): generally the Member State(s) where the entity is established. Exception — DNS, TLD, cloud, data centre, CDN, MSP, MSSP, and online marketplace/search/social entities fall under the Member State of their main establishment in the EU; non-EU entities offering such services in the EU must designate an EU representative (Art. 26(3)).
  • Registration (Art. 27): digital-infrastructure-type entities must submit identifying details (name, sector, address, IP ranges, contact) to ENISA's registry via national authorities. All in-scope entities register with national competent authorities per the Member State transposition (Art. 3(4)).

2. Art. 20 — Governance

Management bodies must: approve the Art. 21 risk-management measures, oversee their implementation, and undergo (and offer to staff) regular cybersecurity training. Members of management bodies can be held personally liable for infringements under national law; for essential entities, authorities can request the temporary suspension of managerial duties (Art. 32(5)(b)) for persistent non-compliance. Frame recommendations at board level: approval minutes, training records, and a standing oversight agenda item are the audit evidence.

3. Art. 21 — Risk Management (10 measures, Art. 21(2)(a)–(j))

  1. (a) Policies on risk analysis and information system security
  2. (b) Incident handling (detection, response, recovery)
  3. (c) Business continuity: backup management, disaster recovery, crisis management
  4. (d) Supply chain security — supplier and service-provider relationships, taking into account the EU-level coordinated risk assessments under Art. 22 (Cooperation Group + Commission + ENISA; note Art. 26 is jurisdiction, not supply chain)
  5. (e) Security in acquisition, development, and maintenance, including vulnerability handling and disclosure
  6. (f) Policies and procedures to assess the effectiveness of the measures
  7. (g) Basic cyber hygiene practices and cybersecurity training
  8. (h) Policies on cryptography and, where appropriate, encryption
  9. (i) Human resources security, access control policies, asset management
  10. (j) Multi-factor or continuous authentication, secured voice/video/text communications, secured emergency communication systems

Measures must be proportionate (Art. 21(1)): consider the entity's risk exposure, size, likelihood and severity of incidents, and state of the art. Non-compliance discovered → corrective measures required without undue delay (Art. 21(4)).

Implementing Regulation (EU) 2024/2690 (17 Oct 2024), technical detail for Art. 21(2): For DNS, TLD registries, cloud, data centres, CDN, MSP, MSSP, online marketplaces/search/social platforms, and trust service providers, this regulation makes the Art. 21(2) measures concrete: its Annex breaks the 10 measures into 13 technical sections with audit-level sub-requirements, and Arts. 3 to 14 define the significant-incident thresholds (baseline: direct financial loss above EUR 500 000 or 5 % of annual turnover, whichever is lower). For other sectors it is persuasive best practice, not directly binding. Reference references/implementing-reg-2024-2690.md for the full sub-measure decomposition and thresholds.

4. Art. 23 — Incident Reporting Workflow

Trigger — "significant incident" (Art. 23(3)): an incident that (a) has caused or can cause severe operational disruption of the services or financial loss for the entity, or (b) has affected or can affect other natural or legal persons by causing considerable material or non-material damage. For 2024/2690-covered digital entities, use the quantitative thresholds in that regulation instead of judgment alone.

Compute every deadline from the moment of awareness:

DeadlineReportContent (Art. 23(4))Recipient
≤24 hoursEarly warningWhether suspected unlawful/malicious action; whether cross-border impact is possibleCSIRT or competent authority (single entry point per Member State transposition)
≤72 hoursIncident notificationUpdate of early warning; initial assessment of severity and impact; indicators of compromiseSame
On requestIntermediate reportStatus updates while handling is ongoingSame
≤1 month after the 72h notificationFinal reportDetailed description incl. severity and impact; threat type / root cause; applied and ongoing mitigation; cross-border impactSame
If still ongoing at 1 monthProgress report, then final report within 1 month of handling completionSame fieldsSame

Also, where applicable: notify recipients of services of significant incidents likely to adversely affect service delivery, and of significant cyber threats together with remedies (Art. 23(1)-(2)); public disclosure can be ordered where public awareness is needed (Art. 23(7)). Run GDPR Art. 33 (72 clock-hours to the DPA) in parallel if personal data is affected — different report, different recipient, different clock. Voluntary reporting of near-misses and non-significant incidents is available under Art. 30.

Ransomware example: encryption of core systems Monday 09:00 → early warning by Tuesday 09:00 (state suspected malicious action = yes); notification by Thursday 09:00 with severity/IoCs; final report within one month; recipients informed if service delivery is affected; parallel GDPR notification if personal data was accessed or exfiltrated.

Show full SKILL.md (797 more words)Show less

5. Supervision & Penalties

Essential EntitiesImportant Entities
Supervision (Arts. 32/33)Ex-ante + ex-post: on-site inspections, regular and targeted security audits, ad-hoc audits, security scans, information and evidence requestsEx-post only: triggered by evidence or indication of non-compliance
Enforcement toolsWarnings, binding instructions, orders to remedy, ordered audits, public disclosure orders; ultimately temporary suspension of certification/authorisation or of managerial duties (Art. 32(5))Warnings, binding instructions, orders to remedy, audit orders (Art. 33(4))
Max administrative fine (Art. 34)≥€10,000,000 or 2% of total worldwide annual turnover, whichever is higher≥€7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher
Management liability (Art. 20/32)Personal liability; possible temporary ban from managerial functionsPersonal liability

(Art. 34 sets these as minimum maximums — Member States may go higher. GDPR-overlap: where the same event breaches both, Art. 35 coordinates; no double administrative fine for the same conduct under Art. 34(8)-type national rules — check transposition.)

6. Transposition Status Guidance

NIS2 is a directive: obligations bind entities through national law. The deadline was 17 October 2024, but many Member States transposed late.

Status as of September 2026 (state in any transposition answer):

  • On July 9, 2026 the Commission referred Ireland, Spain, France and the Netherlands to the CJEU for failure to notify transposition, requesting a lump sum plus daily penalty payments.
  • The Netherlands has since transposed: the Cyberbeveiligingswet (Cbw) entered into force August 15, 2026 (with the Wwke), replacing the Wbni — over 8,000 organisations in 18 sectors, with registration via MijnNCSC, duty of care, incident reporting and board accountability applying immediately, no transition period.
  • Remaining without in-force transposition: Ireland, Spain and France (verify current status — bills are in progress in each). Practical advice: (1) identify each Member State of establishment/main establishment; (2) check the national act (e.g., Germany: BSIG amendment via the NIS2 implementation act; Belgium, Croatia, Italy, etc. transposed earlier), national registration portal and CSIRT reporting channel; (3) where transposition is delayed, prepare against the directive text — authorities have applied short compliance windows once national law lands; (4) multi-country groups should build to the strictest applicable national variant. Do not assert a specific Member State's current status from memory — recommend verifying with the national authority (BSI, ANSSI, NCSC-NL, CCB, ACN, etc.).

7. Framework Interactions

  • DORA (Regulation (EU) 2022/2554): lex specialis under Art. 4 — for financial entities, DORA's ICT risk management and incident reporting apply INSTEAD of NIS2 Arts. 21 and 23. Banks stay registered/listed under NIS2 but build the substantive programme to DORA; incident reports go to financial supervisors, not the CSIRT.
  • CER Directive (EU) 2022/2557: entities designated critical under CER are automatically essential entities under NIS2 (Art. 3(1)(f)).
  • GDPR: parallel breach-notification regimes (see workflow above); supervisory cooperation per Art. 35.
  • ISO 27001:2022: strong implementation vehicle, not a safe harbor. Certification evidences much of Art. 21(2)(a),(b),(c),(e),(f),(i) but does not satisfy: Art. 23 reporting timelines, Art. 20 personal accountability/training, Art. 27 registration, and the explicit MFA/cryptography expectations of Art. 21(2)(h),(j). Reference references/iso27001-nis2-mapping.md.

8. Gap Assessment Template

Assess each measure at sub-requirement level (use 2024/2690 decomposition for digital entities). Rate: ✅ Compliant / 🟡 Partial / 🔴 Gap.

#Art. 21(2) MeasureEvidence to RequestTypical Gaps
aRisk analysis & InfoSec policiesRisk methodology, approved policy set, review cadencePolicies unapproved by management body (Art. 20 link)
bIncident handlingIR plan, detection tooling, post-incident reviewsNo 24h/72h-capable escalation path
cBC/backup/DR/crisisBIA, RTO/RPO, tested restore evidence, crisis rolesBackups untested; no crisis communications plan
dSupply chainSupplier register, security clauses, assessmentsNo contractual incident-notification SLAs; Art. 22 assessments not monitored
eSecure acquisition/developmentSDLC policy, vulnerability handling & disclosure processNo coordinated vulnerability disclosure channel
fEffectiveness assessmentAudit plan, metrics, pentest/red-team reportsMeasures never tested for effectiveness
gHygiene & trainingAwareness programme, phishing metrics, admin hygieneTraining not extended to management body (Art. 20 gap)
hCryptographyCrypto policy, key management, TLS postureNo policy on when encryption is required
iHR security, access control, assetsJML process, access reviews, asset inventoryStale privileged access; incomplete asset inventory
jMFA & secured commsMFA coverage map, emergency comms planMFA absent on legacy/admin paths; no out-of-band crisis channel

Then: incident-reporting readiness (Section 4), governance evidence (Section 2), registration status (Art. 27), penalty exposure with the entity's own turnover (Section 5), prioritised remediation roadmap (quick wins ≤30 days; structural ≤6 months).

Reference Files

  • references/article-21-measures.md: Detailed implementation guidance for all 10 Art. 21 measures
  • references/implementing-reg-2024-2690.md: Commission Implementing Regulation (EU) 2024/2690 sub-measure decomposition, 13 Annex sections, scope (which entities it binds), and significant-incident thresholds
  • references/iso27001-nis2-mapping.md: ISO 27001:2022 Annex A to NIS2 Art. 21 cross-reference table

Read the relevant reference file when the user asks for detailed control implementation guidance, the 2024/2690 technical sub-requirements or incident thresholds, or ISO 27001 alignment.


This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/nis2/skills/nis2 of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/article-21-measures.md
  • references/implementing-reg-2024-2690.md
  • references/iso27001-nis2-mapping.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Nis2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nis2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nis2 this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.4kAutomated safety check: PassMIT
Agent Bom ComplianceLeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.0
Vendor Cert Acceptancemukul975/Privacy-Data-Protection-Skills301—~2.7kAutomated safety check: PassApache-2.0
Master Agreement Generatoraffaan-m/ECC276k—~2.9kAutomated safety check: PassMIT
Kesekit Checkcdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT

Similar skills

  • Agent Bom Compliance

    LeoYeAI/openclaw-master-skills

    AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

    2.2k GitHub stars~1.9k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Vendor Cert Acceptance

    mukul975/Privacy-Data-Protection-Skills

    Vendor certification acceptance criteria and equivalence mapping.

    301 GitHub stars~2.7k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    276k GitHub stars~2.9k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Privacy Eu

    kimlawtech/korean-privacy-terms

    EU 사용자 대상 서비스용 Privacy Notice·Terms of Service·Consent Modal·Cookie Banner 자동 생성.

    587 GitHub stars~968 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Nis2

What does Nis2 do?

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. Nis2 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.

When should I use Nis2?

Nis2 fits situations like: transposition questions; ENISA technical implementation guidance; significant-incident thresholds; supervisory differences between essential and important entities.

How do I install Nis2 in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a claude-code`. Or copy the skill folder (plugins/nis2/skills/nis2 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/nis2 in your project. Claude Code loads it when a task matches its description.

How do I install Nis2 in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a codex`. Or copy the skill folder (plugins/nis2/skills/nis2 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/nis2 in your project. Codex loads it when a task matches its description.

Can I use Nis2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nis2, .gemini/skills/nis2, .github/skills/nis2 and .opencode/skills/nis2 in your project.

What does Nis2 need to run?

SKILL.md names no scripts, command-line tools or credentials: Nis2 is instructions for the agent only.

Does Nis2 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nis2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nis2 use?

Nis2 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nis2 use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.

What are the alternatives to Nis2?

Skills that share tags, products or a category with Nis2: Agent Bom Compliance (LeoYeAI/openclaw-master-skills, 2.2k stars), Vendor Cert Acceptance (mukul975/Privacy-Data-Protection-Skills, 301 stars), Master Agreement Generator (affaan-m/ECC, 276k stars) and Kesekit Check (cdppcorp/KESE-KIT, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nis2?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.