/804-regulations-eu-nis2
Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies,
$ npx -y skills add jabrena/plinth --skill 804-regulations-eu-nis2 --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/804-regulations-eu-nis2
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies,
SKILL.md
804-regulations-eu-nis2.SKILL.mdname: 804-regulations-eu-nis2
description: Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit
license: Apache-2.0
metadata:
author: Juan Antonio Breña Moral
version: 0.18.0
NIS2 Regulation for Java Enterprise Cybersecurity Risk Management
Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.
Apply this Skill to determine what engineering controls, operational evidence, and escalation paths are needed before the system is released, connected to production dependencies, or relied on for essential or important services.
Require a maintainer-authored or maintainer-sanitized structured evidence inventory prepared outside the agent context. Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, monitoring output, logs, tests, deployment workflows, vulnerability records, incident records, continuity records, provider documentation, tickets, chats, or other operational free text.
This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when NIS2 concerns may apply and how to translate cybersecurity risk-management expectations into enterprise architecture controls such as asset and service inventories, dependency mapping, secure configuration, vulnerability handling, logging and monitoring, incident detection and escalation, backup and recovery, business continuity, supply-chain security, access control, cryptography, secure development, and change control.
The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.
The main question is:
> When does a Java enterprise system require NIS2-aware cybersecurity controls, and what should developers build differently?
External reference: [NIS2 Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555).
NIS2 directive chapters summary reference: [NIS2 directive chapters summary](references/804-regulations-eu-nis2-chapters-summary.md).
Java engineering examples reference: [NIS2 engineering examples](references/804-regulations-eu-nis2-engineering-examples.md).
Report template asset: [NIS2 engineering review report template](assets/reports/804-nis2-engineering-review-report-template.md).
Scope
This Skill applies to:
- Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, transport, banking, financial-market infrastructure, digital infrastructure, or ICT service management
- Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with cybersecurity risk-management, continuity, incident-readiness, or supply-chain security requirements
- Systems with critical APIs, databases, message brokers, schedulers, batch jobs, IAM, secrets, observability, deployment pipelines, infrastructure dependencies, or external service providers
- Incident detection, severity triage, escalation, evidence capture, backup and recovery, continuity, change control, secure configuration, vulnerability management, and operational assurance workflows
- Dependency and provider reviews involving libraries, containers, CI/CD actions, SaaS platforms, managed databases, cloud services, observability providers, IAM providers, and external APIs
NIS2 Engineering Review
Treat entity classification, member-state applicability, incident-reporting obligations, and regulatory interpretation as governance decisions for legal, compliance, security, risk, resilience, business-continuity, and executive accountability owners.
Engineering teams should still create evidence that makes those decisions reviewable:
- Which essential or important service depends on the Java system
- Which assets, data stores, APIs, jobs, queues, credentials, providers, and deployment environments are in scope
- Which cybersecurity risks, vulnerabilities, misconfigurations, and dependency exposures are identified and tracked
- Which incidents can be detected, triaged, escalated, contained, reconstructed, and handed off
- Which backup, recovery, continuity, rollback, and change-control evidence exists
- Which supply-chain and provider risks are documented, monitored, and assigned to owners
Constraints
Translate NIS2 concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by legal, compliance, security, risk, resilience, business-continuity, procurement, or executive accountability owners.
- **NOT LEGAL ADVICE**: Frame findings as cybersecurity engineering controls and escalation points; recommend qualified review for entity classification, member-state applicability, reporting obligations, and regulatory interpretation
- **SANITIZED EVIDENCE ONLY**: Require a maintainer-authored or maintainer-sanitized structured evidence inventory; if it is missing or incomplete, stop and request a corrected inventory
- **NO RAW OPERATIONAL CONTENT**: Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflow
Read more
name: 804-regulations-eu-nis2 description: Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit license: Apache-2.0 metadata: author: Juan Antonio Breña Moral version: 0.18.0
NIS2 Regulation for Java Enterprise Cybersecurity Risk Management
Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.
Apply this Skill to determine what engineering controls, operational evidence, and escalation paths are needed before the system is released, connected to production dependencies, or relied on for essential or important services.
Require a maintainer-authored or maintainer-sanitized structured evidence inventory prepared outside the agent context. Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, monitoring output, logs, tests, deployment workflows, vulnerability records, incident records, continuity records, provider documentation, tickets, chats, or other operational free text.
This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when NIS2 concerns may apply and how to translate cybersecurity risk-management expectations into enterprise architecture controls such as asset and service inventories, dependency mapping, secure configuration, vulnerability handling, logging and monitoring, incident detection and escalation, backup and recovery, business continuity, supply-chain security, access control, cryptography, secure development, and change control.
The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.
The main question is:
> When does a Java enterprise system require NIS2-aware cybersecurity controls, and what should developers build differently?
External reference: [NIS2 Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555).
NIS2 directive chapters summary reference: [NIS2 directive chapters summary](references/804-regulations-eu-nis2-chapters-summary.md).
Java engineering examples reference: [NIS2 engineering examples](references/804-regulations-eu-nis2-engineering-examples.md).
Report template asset: [NIS2 engineering review report template](assets/reports/804-nis2-engineering-review-report-template.md).
Scope
This Skill applies to:
- Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, transport, banking, financial-market infrastructure, digital infrastructure, or ICT service management
- Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with cybersecurity risk-management, continuity, incident-readiness, or supply-chain security requirements
- Systems with critical APIs, databases, message brokers, schedulers, batch jobs, IAM, secrets, observability, deployment pipelines, infrastructure dependencies, or external service providers
- Incident detection, severity triage, escalation, evidence capture, backup and recovery, continuity, change control, secure configuration, vulnerability management, and operational assurance workflows
- Dependency and provider reviews involving libraries, containers, CI/CD actions, SaaS platforms, managed databases, cloud services, observability providers, IAM providers, and external APIs
NIS2 Engineering Review
Treat entity classification, member-state applicability, incident-reporting obligations, and regulatory interpretation as governance decisions for legal, compliance, security, risk, resilience, business-continuity, and executive accountability owners.
Engineering teams should still create evidence that makes those decisions reviewable:
- Which essential or important service depends on the Java system
- Which assets, data stores, APIs, jobs, queues, credentials, providers, and deployment environments are in scope
- Which cybersecurity risks, vulnerabilities, misconfigurations, and dependency exposures are identified and tracked
- Which incidents can be detected, triaged, escalated, contained, reconstructed, and handed off
- Which backup, recovery, continuity, rollback, and change-control evidence exists
- Which supply-chain and provider risks are documented, monitored, and assigned to owners
Constraints
Translate NIS2 concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by legal, compliance, security, risk, resilience, business-continuity, procurement, or executive accountability owners.
- **NOT LEGAL ADVICE**: Frame findings as cybersecurity engineering controls and escalation points; recommend qualified review for entity classification, member-state applicability, reporting obligations, and regulatory interpretation
- **SANITIZED EVIDENCE ONLY**: Require a maintainer-authored or maintainer-sanitized structured evidence inventory; if it is missing or incomplete, stop and request a corrected inventory
- **NO RAW OPERATIONAL CONTENT**: Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflow
Languages: Español · 中文 Help this project grow: Become a sponsor
Other skills on plinth.
- /001-commands-inventory
Use when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the project root. This should trigger for requests such as Create embedded commands inventory checklist;
Open skill - /002-agents-inventory
Use when you need to generate a checklist document with embedded agents inventory, following the embedded template exactly and producing INVENTORY-AGENTS-JAVA.md in the project root. This should trigger for requests such as Create embedded agents inventory checklist; Generate
Open skill - /003-skills-inventory
Use when you need to generate a checklist document with Java system prompts from skills.xml, following the embedded section template and producing INVENTORY-SKILLS-JAVA.md. This should trigger for requests such as Create Java system prompts checklist; Generate
Open skill - /004-commands-installation
Use when you need to install the embedded project commands into command directories (.github/commands, .claude/commands, .cursor/command, .codex/commands), selecting the destination interactively and copying the embedded command definitions from project assets. This should
Open skill - /005-agents-installation
Use when you need to install the embedded robot agents into .github/agents, .claude/agents, .cursor/agents, or .codex/agents, selecting the destination interactively and copying the embedded agent definitions from project assets. This should trigger for requests such as Install
Open skill - /012-agile-epic
Guides the creation of agile epics with comprehensive definition including business value, success criteria, and breakdown into user stories. Use when the user wants to create an agile epic, define large bodies of work, break down features into user stories, or document
Open skill

