Mmcp.market

arckit-at-nisg skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

[COMMUNITY] Assess Austrian NISG obligations (BGBl. I Nr. 94/2025) — AT transposition of NIS2, BKA (GovCERT) / BMI (SPOC) reporting, KSÖ coordination, and Austrian sectoral rules for Essential/Important entities

A100/100content scan

Is the arckit-at-nisg skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the arckit-at-nisg skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/at/cybersecurity/skills/arckit-at-nisg ~/.claude/skills/arckit-at-nisg
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified CISO / BMI-liaison / Rechtsabteilung before reliance. Citations to BMI / A-SIT / EU regulations may lag the current text — verify against the source. Items marked [NEEDS VERIFICATION] must be confirmed against the current NISG text (idF BGBl. I Nr. 94/2025) and implementing ordinances before external use — the legislation is recent and evolving.

You are helping an enterprise architect generate an Austrian NISG Compliance Assessment — the Austrian transposition of NIS2 (EU Directive 2022/2555). The Austrian Netz- und Informationssystemsicherheitsgesetz (NISG, BGBl. I Nr. 111/2018 idF BGBl. I Nr. 94/2025) extends NIS2 obligations with Austria-specific designation, reporting, and supervision rules. Run this after $arckit-eu-nis2 to add Austrian obligations that go beyond the EU baseline.

User Input

$ARGUMENTS

Instructions

Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.

Step 0: Read existing artifacts from the project context

MANDATORY (warn if missing):

  • REQ (Requirements) — Extract: security requirements (NFR-SEC-xxx), operational requirements, integration requirements (INT-xxx), sector and entity type information, criticality thresholds
  • If missing: proceed with user-provided entity description, but note that requirements analysis would strengthen the gap assessment

RECOMMENDED (read if available, note if missing):

  • NIS2 (EU NIS2 Assessment) — Extract: Annex I / Annex II classification, size threshold results, Article 21 ten-measure status, incident reporting baseline
  • If missing: warn that $arckit-at-nisg should be run after $arckit-eu-nis2 for best results
  • RISK (Risk Register) — Extract: existing security risks, supply chain risks, third-party risks, business continuity risks
  • SECD (Secure by Design) — Extract: existing security controls, maturity assessments, security architecture decisions
  • PRIN (Architecture Principles, 000-global) — Extract: security baseline, incident response principles, supply chain policy

OPTIONAL (read if available, skip silently):

  • ATDSG (AT DSG Assessment) — Extract: overlap where security monitoring processes personal data
  • DORA (DORA Assessment) — Extract: overlapping ICT resilience obligations if financial sector

Step 0b: Read external documents and policies

  • Read any external documents in external/ — extract existing BMI / GovCERT / A-SIT correspondence, sector-specific designation letters, incident response plans, BCM plans, Sicherheitshandbuch excerpts
  • Read any global policies in 000-global/policies/ — extract security policy, incident response policy, supplier security policy, BCM policy
  • If BMI designation documents found, use them to pre-populate the Essential/Important status.

Step 1: Identify or Create Project

Identify the target project from the hook context. If the project doesn't exist:

  1. Use Glob to list projects// directories and find the highest NNN- number
  2. Calculate the next number (zero-padded to 3 digits)
  3. Slugify the project name
  4. Use the Write tool to create projects/{NNN}-{slug}/README.md
  5. Set PROJECTID and PROJECTPATH

Step 2: Read Source Artifacts

Read all documents from Step 0. Identify:

  • Sector (NIS2 Annex I Essential / Annex II Important / out of scope)
  • Organisation size (>250 employees / 50–250 / <50)
  • Operation in Austria (seat, subsidiary, critical service delivery in AT)
  • Sector-specific Austrian designation status (E-Control for energy, FMA for finance, BMSGPK for health, BMK for transport, RTR for digital infrastructure, BMI for federal public admin)
  • Financial sector involvement (DORA overlap)

Step 3: Template Reading

Read the template (with user override support):

  • First, check if .arckit/templates-custom/at-nisg-template.md exists in the project root
  • If found: Read the user's customized template
  • If not found: Read .arckit/templates/at-nisg-template.md

Step 4: Entity Classification (Austrian specifics)

Before generating the assessment, determine entity classification:

Annex I — Essential Entities (NIS2 baseline, carried into NISG): Energy, Transport, Banking, Financial market infrastructure, Health, Drinking water, Wastewater, Digital infrastructure, ICT service management, Public administration, Space.

Annex II — Important Entities (NIS2 baseline): Postal/courier, Waste, Chemicals, Food, Manufacturing (medical devices, computers, transport), Digital providers, Research.

Austrian additions or scope differences:

  • Austria may designate additional entities under NISG based on criticality assessment (§3 Abs. 4: Bundeskanzler can designate regardless of size threshold)
  • Public-administration scope: Federal bodies in scope by default; Land-level bodies can opt in via Landeshauptmann declaration (§22 Abs. 5-6) — check whether the relevant Land has opted in
  • Special regimes continue for previously designated Betreiber wesentlicher Dienste under NISG 2018 — entities designated under old §16 transition automatically; new Essential/Important classification applies from entry into force of BGBl. I Nr. 94/2025

Size thresholds (NIS2 carried into NISG):

  • Essential Entity: sector-qualified AND (>250 employees OR >€50M revenue)
  • Important Entity: sector-qualified AND (50–250 employees OR €10–50M revenue)
  • Microenterprises may fall out of scope unless sector-specific designation applies

Show entity classification before generating the full document.

Step 5: Generate NISG Assessment

CRITICAL: Use the Write tool to create the assessment document.

  1. Detect version: Check for existing ARC-{PROJECTID}-ATNISG-v.md files:
  • No existing file → VERSION="1.0"
  • Existing file → minor increment if refreshed, major if scope changed
  1. Auto-populate Document Control:
  • Document ID: ARC-{PROJECT_ID}-ATNISG-v{VERSION}
  • Status: DRAFT
  • Created Date: {current_date}
  • Next Review Date: {current_date + 12 months}
  • Entity Designation: from Step 4 classification
  • Note: "This document supplements ARC-{PROJECTID}-NIS2-v.md with Austrian-specific NISG 2024 obligations"
  1. Section 1: Austrian Scope and Designation
  • Sector classification with AT sectoral authority mapping (E-Control, FMA, ELGA/BMSGPK, BMK for transport, etc.) [NEEDS VERIFICATION]
  • Entity designation: Essential / Important / Out of scope under NISG
  • Previous NISG 2018 designation (Betreiber wesentlicher Dienste) and transition status
  • Cross-border operations treatment (main establishment rules from NIS2)
  • Federal vs Land competence — confirm venue for supervision [NEEDS VERIFICATION]
  1. Section 2: Governance (NIS2 Art. 20 — as transposed)
  • Geschäftsleitung (management body) approval of security measures
  • Management body personal liability for non-compliance — AT practice [NEEDS VERIFICATION: confirm penalty regime in NISG 2024]
  • Management body cybersecurity training requirement
  • Compliance status for each obligation
  1. Section 3: Risk Management Measures (NIS2 Art. 21 — as transposed)
  • All ten minimum security measures with current status and gaps:
  1. Risk analysis policy
  2. Incident handling
  3. Business continuity / BCM
  4. Supply chain security
  5. Secure acquisition, development, maintenance
  6. Policies to assess effectiveness
  7. Cyber hygiene and training
  8. Cryptography policy
  9. HR security and access control
  10. MFA and secure communications
  • A-SIT guidance alignment where applicable (A-SIT publishes sector-agnostic security guidance; not a regulatory body but commonly referenced by BMI and sectoral authorities)
  • Proportionality assessment: measures proportionate to entity size and risk
  • Extract existing controls from SECD artifact to pre-populate status
  1. Section 4: Incident Reporting — Austrian Channel
  • Three-tier CERT reporting: Sectoral CERT (if designated, e.g. Energy-CERT) → National CERT (CERT.at, operative under BMI §5) → GovCERT (BKA §4(4), public-admin entities only). Non-public entities report to CERT.at / sectoral CERT; GovCERT handles federal and Land public-admin entities
  • Four-stage NIS2 reporting timeline (24h early warning, 72h notification, intermediate on request, 1-month final report)
  • Austrian form and language requirements for reports
  • Cross-reporting to DSB if personal data breach (Art. 33 GDPR + NISG)
  • Tabletop / exercise expectations from BMI (§25 Cyberkrise exercises; BMI coordinates nationally)
  1. Section 5: Supply Chain Security
  • Supplier inventory and risk assessment requirements
  • Contractual security clause requirements
  • Software supply chain requirements
  • ENISA supply chain framework plus AT-specific sectoral guidance (e.g. E-Control Verordnungen for energy sector, FMA Rundschreiben for financial sector)
  • EU coordinated risk assessment outcomes (5G, high-risk vendors)
  1. Section 6: Business Continuity and Resilience
  • BCP documentation status
  • Backup and restoration testing
  • Crisis management procedures
  • RTO / RPO definition aligned with sectoral criticality expectations
  1. Section 7: Supervision, Inspections, and Penalties
  • Supervisory regime: BMI / competent sectoral authority inspections
  • Ex ante (Essential) vs ex post (Important) supervision posture
  • Maximum penalties — NIS2 Art. 34 floor: Essential ≥ €10,000,000 or 2% worldwide annual turnover; Important ≥ €7,000,000 or 1.4% worldwide annual turnover (old NISG §26 €50K/€100K replaced by 2025 amendment)
  • Right to be heard / appeals (BVwG pathway)
  • Responsible entities for internal governance (CISO / Sicherheitsbeauftragter designation)
  1. Section 8: KSÖ and National Cyber Coordination (informational)
  • KSÖ (Kuratorium Sicheres Österreich) as national PPP forum — voluntary but influential
  • NCSC-AT (part of BKA) / GovCERT (BKA §4(4)) — strategic coordination and public-admin CERT; BMI (§5-6) — operative CERT.at, SPOC toward EU, and enforcement authority
  • Participation options and information-sharing expectations
  1. Section 9: Gap Analysis and Roadmap
  • Domain maturity matrix (L1–L5 scale)
  • Priority actions with effort estimates
  • Mermaid Gantt roadmap (0–3 months immediate, 3–6 months short-term, 6–12 months medium-term)
  • Related frameworks crosswalk (ISO 27001, NIST CSF, ISO 22301, BSI IT-Grundschutz — commonly used in AT)

Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks pass.

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway

All agent skills → · MCP servers