nis2 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited nis2 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Disclaimer: this skill is not legal advice. It helps with scoping and a technical gap analysis against the directive's text. Final legal qualification (entity classification, sanctions risk, contractual consequences) requires advice from a lawyer with NIS2 experience, possibly together with a compliance department or external counsel.
The NIS2 directive (EU 2022/2555) replaces NIS1 and entered into force on 17 October 2024. The Netherlands implements it through the Cyberbeveiligingswet ([verify current status — the legislative track has been in motion through 2024 and 2025]). This skill covers both: the EU directive text as the primary source, the NL implementation as the application.
Triggers on:
iso27001 or risk-register: NIS2 Art 21 maps onto ISO 27001 Annex A and onto NIST CSF.secure-coding, sast-orchestrator, ir-runbook, etc.). NIS2 demands that you do things; how you do them lives in those skills.dora. DORA is lex specialis for financial; NIS2 is horizontal. Both can apply at financial organizations.gdpr-pia plus AVG Art 33/34. NIS2 incident reporting is additive, not a replacement.iso27001. NIS2 does not require certification.vendor-questionnaire and supply-chain.policy-drafter.Six phases. Phase 1 is the heaviest legally (scope determination), phases 2–4 are the core obligations, phase 5 translates into the NL implementation, phase 6 is the verification-loop.
NIS2 distinguishes two categories with different supervisory regimes:
Within those, size caps apply (Art 2): in principle only medium and large organizations (>50 FTE or >€10M turnover), with exceptions for critical small organizations (DNS providers, TLD registries, trust service providers, etc. are in scope regardless of size).
Reviewer checks:
Document edge cases with references to specific Annex entries. Ambiguity over essential vs important has real consequences (proactive vs reactive supervision, fine ceilings).
Management is liable for cybersecurity. This is a substantial shift from NIS1.
Document requirements for the reviewer:
NIS2 Art 21(2) lists ten categories of minimum measures. Every in-scope organization must demonstrably address these ten:
These ten are deliberately framework-agnostic. Mapping to concrete frameworks:
Gap-analysis workflow: per measure name the current state (policy + evidence + gaps), tie to a framework control ID, owner, and deadline.
A three-phase timeline for "significant incidents" (apparent impact on service delivery, or exploitation of a third-party vulnerability):
NL-specific: CSIRT-NL (Computer Security Incident Response Team, under NCSC-NL / Ministerie JenV). Competent authority differs per sector — for most non-government entities supervision falls to the Rijksinspectie Digitale Infrastructuur (RDI) once the Cyberbeveiligingswet enters into force. [verify the current competent authority per sector].
Reviewer workflow for IR runbooks:
The Cyberbeveiligingswet transposes NIS2 into Dutch law. [verify current status — at the time this skill was published the legislative track was still in motion; check the parliamentary documents overview at tweedekamer.nl]. Practical consequences to watch:
For verification, consult the current version of the law (wetten.overheid.nl once in force) and, in parallel, NCTV/NCSC-NL publications on implementation guidance.
Layer 1: scope (all relevant entities within the organization included? all 10 measures addressed, no silent gaps?), assumptions (Cyberbeveiligingswet status correct as of the report date?), gap analysis (which measures would an auditor consider weakest?). Layer 2: article numbers from directive 2022/2555 correct, no invented Annex entries, NL-specific names (RDI, CSIRT-NL, NCSC-NL, NCTV) correctly spelled and currently scoped, [verify] markers in place where legislation is in motion.
NIS2 gap analysis — <organization/entity>
Date: YYYY-MM-DD | NIS2 entered into force: 2024-10-17 | NL CBW status: [verify]
Scope:
Sector (Annex I/II): <sector + sub-code>
Size criterion: <medium | large | small with exception>
Classification: <essential | important | out of scope>
Rationale: <1-3 sentences, article references>
Governance (Art 20):
Board-approved cyber charter: <yes/no + date>
Annual board briefing: <yes/no + last date>
Awareness training employees: <coverage%, log present>
Ten baseline measures (Art 21):
1. Risk analysis + infosec policy: <state | evidence | gap>
2. Incident handling: ...
3. Business continuity: ...
4. Supply-chain security: ...
5. Acquisition/development/maintenance: ...
6. Effectiveness evaluation: ...
7. Cyber hygiene + training: ...
8. Cryptography: ...
9. Personnel + access + assets: ...
10. MFA + secure comms: ...
Incident reporting (Art 23):
24h procedure: <present | gap>
72h notification: <template present | gap>
1-month final report: <procedure present | gap>
CSIRT-NL contact: <registered | pending>
NL implementation:
RDI registration: <required + done | n/a>
Sector supervisor: <which>
Sanctions scope: <max fines per category>
Priorities (fix-now/fix-sprint/fix-quarter):
<list>
Verification-loop: ...~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.