From eu-nis2
Determine NIS2 applicability and entity classification (essential / important / out-of-scope)
How this command is triggered — by the user, by Claude, or both
Slash command
/eu-nis2:scopeThe summary Claude sees in its command listing — used to decide when to auto-load this command
# EU NIS2 Scope Determines whether the **EU NIS2 Directive** (Directive (EU) 2022/2555) applies to the organisation, and if so whether the organisation is classified as **essential** (Annex I) or **important** (Annex II). Reference-depth scope is a structured walkthrough of the Article 2 and Article 3 decision tree; Full-depth plugins extend this with national-law-aware logic per Member State. NIS2 is a **Directive**, not a Regulation. The substantive rules a regulator can enforce against the organisation live in the **national transposition law** of each EU Member State. This command giv...
Determines whether the EU NIS2 Directive (Directive (EU) 2022/2555) applies to the organisation, and if so whether the organisation is classified as essential (Annex I) or important (Annex II). Reference-depth scope is a structured walkthrough of the Article 2 and Article 3 decision tree; Full-depth plugins extend this with national-law-aware logic per Member State.
NIS2 is a Directive, not a Regulation. The substantive rules a regulator can enforce against the organisation live in the national transposition law of each EU Member State. This command gives the directive-level verdict; for definitive in-or-out determinations always consult the national transposition law of every Member State in which the organisation operates a NIS2-covered service.
/eu-nis2:scope
/eu-nis2:evidence-checklist to enumerate Article 21 evidence requirements and /eu-nis2:assess to run the SCF-backed gap assessment.The plugin walks through these checks in order. Stop at the first definitive verdict.
Ask: "Which of the NIS2 sectors does the organisation operate in?" Multiple sectors are common — capture all of them.
Annex I sectors (default classification: essential):
Annex II sectors (default classification: important):
If the organisation is in none of these sectors, it is out of scope under the directive baseline. (Member States may widen scope under Article 2(2)(d)–(e); flag this as a residual risk and re-check the national law.)
Ask: "Does the entity meet the medium-enterprise threshold?"
Apply the threshold at the entity level, not at the corporate group level (with the group-aggregation rules in Recommendation 2003/361/EC for partner and linked enterprises). If the entity meets the medium threshold:
If the entity is below the medium threshold, do not stop yet — go to Step 3.
The size threshold is overridden for any of the following — these entities are in scope regardless of size:
If any of these applies, the entity is in scope regardless of headcount or turnover. Most are classified as essential, but verify via Annex I vs II for the sector.
Member States may classify additional entities as essential or important based on the role they play in the national economy. Examples in early transposition laws:
Check the national transposition law of each Member State the organisation operates in. The plugin cannot give a definitive answer at the directive level for these discretionary categories.
Limited carve-outs are available for entities providing services exclusively to defence or national security. National security is outside the EU's competence, so Member States can choose to exclude or apply a different regime to entities supporting national-security functions. This is narrow — most dual-use organisations do not qualify.
NIS2 applies wherever the entity is established in the Union. Article 26 sets jurisdiction:
For each Member State of operation, the plugin records: competent authority, CSIRT, transposition-law citation, registration deadline, and any national-specific obligations (mandatory CISO appointment, sectoral reporting portals, etc.).
emea-eu-nis2-annex-2024 SCF crosswalk.npx claudepluginhub mrcodechef/claude-grc-engineering --plugin eu-nis2/scopePre-flight scope gate: deterministically verifies assets (hosts, URLs, CIDRs, regexes) against an engagement's scope.md before any active testing. Deny-wins, default-deny.
/scopeForces explicit project boundary-setting by defining what is in and out of scope, preventing scope creep before work begins.
/scopeEstimates GitHub issue complexity before development — surfaces affected files, blast radius, dependency risks, and decomposition recommendations.
/scopeExecutes upgrade procedures defined in an upgrade.md file, automating dependency and migration steps.
/scopeAuthors a task-level or phase-level scope contract (alignment.md) through a structured four-field conversation about goals, results, success criteria, and non-goals.
/scopeScopes a vague request into an MVP boundary with must/should/won't categories and a non-empty cut list.