Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DPO / RSSI / legal counsel before reliance. Citations to ANSSI / CNIL / EU regulations may lag the current text — verify against the source.
You are helping an enterprise architect generate a NIS2 Compliance Assessment (EU Directive 2022/2555) for an organisation that may qualify as an Essential Entity or Important Entity under the NIS2 framework. NIS2 is transposed into national law by all EU member states (deadline October 2024).
User Input
$ARGUMENTS
Instructions
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
Step 0: Read existing artifacts from the project context
MANDATORY (warn if missing):
REQ (Requirements) — Extract: security requirements (NFR-SEC-xxx), operational requirements, integration requirements (INT-xxx), sector and entity type information
If missing: proceed with user-provided entity description, but note that requirements analysis would strengthen the gap assessment
First, check if .arckit/templates-custom/eu-nis2-template.md exists in the project root
If found: Read the user's customized template
If not found: Read .arckit/templates/eu-nis2-template.md
Step 4: Entity Classification (Article 3)
Before generating the assessment, determine entity classification:
Annex I — Essential Entities: Energy (electricity, gas, oil, hydrogen), Transport (air, rail, water, road), Banking, Financial market infrastructure, Health, Drinking water, Wastewater, Digital infrastructure (IXPs, DNS, TLD, cloud, CDN, datacentres), ICT service management (B2B MSPs), Public administration, Space
Annex II — Important Entities: Postal and courier, Waste management, Chemicals, Food, Manufacturing (medical devices, computers, transport equipment), Digital providers (online marketplaces, search engines, social networks), Research
Size thresholds:
Essential Entity: sector-qualified AND (> 250 employees OR > €50M revenue)
Important Entity: sector-qualified AND (50–250 employees OR €10–50M revenue)
Microenterprises (< 10 employees, < €2M) may benefit from simplified obligations
Show entity classification before generating the full document.
Step 5: Generate NIS2 Assessment
CRITICAL: Use the Write tool to create the assessment document.
Detect version: Check for existing ARC-{PROJECT_ID}-NIS2-v*.md files:
No existing file → VERSION="1.0"
Existing file → minor increment if refreshed, major if scope changed
Auto-populate Document Control:
Document ID: ARC-{PROJECT_ID}-NIS2-v{VERSION}
Status: DRAFT
Created Date: {current_date}
Next Review Date: {current_date + 12 months}
Member State: from user input
Entity Designation: from Step 4 classification
Section 1: Entity Scoping
Sector classification table (Annex I vs Annex II)
Size threshold assessment
Entity classification result: Essential / Important / Out of scope
Supervision consequences table (ex ante vs ex post, max penalties)
Member state national competent authority
Section 2: Governance Obligations (Article 20)
Management body approval of security measures
Management body liability for non-compliance
Management body cybersecurity training requirement
Compliance status for each obligation
Section 3: Risk Management Measures (Article 21)
All ten minimum security measures with current status and gaps:
Risk analysis policy
Incident handling
Business continuity / BCM
Supply chain security
Secure acquisition, development, maintenance
Policies to assess effectiveness
Cyber hygiene and training
Cryptography policy
HR security and access control
MFA and secure communications
Proportionality assessment: measures proportionate to entity size and risk
Extract existing controls from SECD artifact to pre-populate status
Section 4: Incident Reporting (Articles 23–24)
Significant incident definition and classification criteria
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ NIS2 Assessment Generated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-NIS2-v{VERSION}.md
📋 Document ID: {document_id}
📅 Assessment Date: {date}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📋 Entity Classification
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Classification: {Essential Entity / Important Entity / Out of scope}
Sector: {Annex I or II sector}
Competent Authority: {National authority}
Max Penalty: {€10M/2% or €7M/1.4%}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📊 Gap Summary (Article 21 — Ten Measures)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
{Compliance status for each of the 10 measures}
Total Gaps: {N} ({N} high, {N} medium, {N} low)
Incident Reporting: {Ready / Gap — 24h/72h capability needed}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Next steps:
1. {If OIV/OSE (France): Run $arckit-fr-secnumcloud}
2. {If financial sector: Run $arckit-eu-dora for DORA overlap}
3. Run $arckit-secure to implement Article 21 controls
4. Run $arckit-risk to register NIS2 gaps
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Important Notes
Management body liability: NIS2 explicitly makes management body members personally liable for non-compliance. This is a new and significant change from NIS1. Flag this prominently.
24-hour reporting capability: The 24-hour early warning window is very tight. Flag if no 24/7 incident detection and reporting capability exists.
OIV/OSE and NIS2 in France: French OIV entities are subject to stricter obligations under LPM that supplement NIS2. OIV/SIIV systems must comply with both. ANSSI is the single competent authority for both regimes.
Member state variations: NIS2 transposition varies. Germany (NIS2UmsuCG) and France have extended scope beyond EU minimum. Verify national transposition law for each member state of operation.
Use Write Tool: NIS2 assessments cover 8 sections with technical and regulatory depth. Always use the Write tool.
Note for reviewers: NIS2 replaced the original NIS Directive (2016/1148) in January 2023, with member state transposition deadline of October 2024. France transposed NIS2 through amendments to the Loi de Programmation Militaire (LPM), building on an existing OIV/OSE framework — ANSSI is the single competent authority for both regimes. "OIV" (Opérateurs d'Importance Vitale — critical infrastructure operators) is a French national designation that predates NIS2 and carries stricter obligations; "OSE" (Opérateurs de Services Essentiels) is the NIS/NIS2 designation. Entities can be both.
Success Criteria
✅ Assessment document created at projects/{project_id}/ARC-{PROJECT_ID}-NIS2-v{VERSION}.md
✅ Entity classification determined (Essential / Important / Out of scope)
✅ Sector (Annex I or II) identified
✅ National competent authority and CSIRT identified
✅ All ten Article 21 minimum measures assessed with status and gaps
✅ Management body accountability obligations flagged
✅ National transposition specifics for relevant member states included
✅ Gap analysis with maturity levels (L1–L5) and roadmap generated
Example Usage
$arckit-eu-nis2 Assess NIS2 obligations for a French regional energy distribution operator (DSO), Essential Entity under Annex I Energy sector, existing OIV designation, planning cloud migration to SecNumCloud-qualified provider
$arckit-eu-nis2 NIS2 scoping for 001 — Dutch healthcare provider with 300 employees, operating across NL and BE, considering Essential Entity classification under health sector
$arckit-eu-nis2 NIS2 assessment for a managed service provider (MSP) operating across 6 EU member states, ICT service management Annex I
Suggested Next Steps
After completing this command, consider running:
$arckit-fr-secnumcloud -- Assess SecNumCloud alignment for French entities with OIV/OSE designation (when Entity is French and has OIV or OSE designation)
$arckit-eu-dora -- Map overlapping ICT resilience obligations for financial sector entities (when Entity is in the financial sector and subject to both NIS2 and DORA)
$arckit-risk -- Integrate NIS2 gap findings into the project risk register