Use when reviewing, designing, or modifying Java enterprise systems that may support essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, or cybersecurity incident escalation obligations under NIS2. This should trigger for requests such as Review a Java platform for NIS2 cybersecurity controls; Design operational evidence for critical-sector services; Add incident detection, escalation, continuity, or supply-chain security controls; Assess cybersecurity risk management before production release. Part of Plinth Toolkit
Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.
Apply this Skill to determine what engineering controls, operational evidence, and escalation paths are needed before the system is released, connected to production dependencies, or relied on for essential or important services.
This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when NIS2 concerns may apply and how to translate cybersecurity risk-management expectations into enterprise architecture controls such as asset and service inventories, dependency mapping, secure configuration, vulnerability handling, logging and monitoring, incident detection and escalation, backup and recovery, business continuity, supply-chain security, access control, cryptography, secure development, and change control.
The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.
The main question is:
When does a Java enterprise system require NIS2-aware cybersecurity controls, and what should developers build differently?
External reference: NIS2 Directive (EU) 2022/2555.
NIS2 directive chapters summary reference: NIS2 directive chapters summary.
Java engineering examples reference: NIS2 engineering examples.
Report template asset: NIS2 engineering review report template.
This Skill applies to:
Treat entity classification, member-state applicability, incident-reporting obligations, and regulatory interpretation as governance decisions for legal, compliance, security, risk, resilience, business-continuity, and executive accountability owners.
Engineering teams should still create evidence that makes those decisions reviewable:
Translate NIS2 concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by legal, compliance, security, risk, resilience, business-continuity, procurement, or executive accountability owners.
Read references/804-regulations-eu-nis2-chapters-summary.md, references/804-regulations-eu-nis2-engineering-examples.md, and assets/reports/804-nis2-engineering-review-report-template.md in that order. Use the directive chapters summary for NIS2 chapter, article, annex, scope, reporting, supervision, enforcement, and owner-handoff context. Use the engineering examples for Java control patterns such as asset and service inventory, incident detection and escalation, vulnerability and dependency evidence, backup and continuity evidence, supply-chain risk, secure change control, and Java release-policy controls. Do not start implementation review until the directive chapters summary, examples reference, and report template are understood.
Identify service context, possible essential or important entity signals, sector signals, system owner, security owner, resilience owner, deployment environments, assets, data stores, messaging systems, IAM, secrets, third-party providers, recovery expectations, and incident pathways. Escalate unclear applicability, entity classification, member-state implementation, reporting obligations, or regulatory interpretation to legal, compliance, security, risk, resilience, or executive accountability owners.
Review Java code, configuration, infrastructure descriptors, runbooks, monitoring, logging, tests, deployment workflows, dependency inventories, vulnerability records, incident procedures, backup and restore evidence, business-continuity records, and provider documentation. Check for gaps between claimed controls and reviewable evidence.
Map NIS2 concerns to engineering actions: asset and service inventory, secure configuration, dependency and vulnerability management, incident detection and escalation, evidence-safe logging, monitoring and alerting, backup and restore verification, continuity and rollback plans, supply-chain risk review, access control, cryptography, secure development, and change approval.
Use assets/reports/804-nis2-engineering-review-report-template.md to produce a concise engineering review with scope, evidence reviewed, NIS2 risk signals, potential violation or non-compliance signals, engineering gaps, recommended controls, owner handoffs, residual risks, release decision, and validation steps. State explicitly that legal applicability, entity classification, reporting duties, and regulatory interpretation require qualified owner review.
For detailed guidance, examples, and constraints, see:
a8e5189
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.