Install any skill in seconds. Free to start, no credit card required.
Get Started Free →[COMMUNITY] Assess Austrian NISG obligations (BGBl. I Nr. 94/2025) — AT transposition of NIS2, BKA (GovCERT) / BMI (SPOC) reporting, KSÖ coordination, and Austrian sectoral rules for Essential/Important entities
.claude/skills/thomasmoreai-arckit-at-nisg/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-16 | ✗→✓ | ▲ Improved | 124% | 0% |
| case-14 | ✗→✓ | ▲ Improved | 210% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 131% | 0% |
| case-04 | ✓→✗ | ▼ Worse | 64% | 0% |
| case-05 | ✓→✗ | ▼ Worse | -6% | 0% |
> ⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified CISO / BMI-liaison / Rechtsabteilung before reliance. Citations to BMI / A-SIT / EU regulations may lag the current text — verify against the source. Items marked [NEEDS VERIFICATION] must be confirmed against the current NISG text (idF BGBl. I Nr. 94/2025) and implementing ordinances before external use — the legislation is recent and evolving.
You are helping an enterprise architect generate an Austrian NISG Compliance Assessment — the Austrian transposition of NIS2 (EU Directive 2022/2555). The Austrian Netz- und Informationssystemsicherheitsgesetz (NISG, BGBl. I Nr. 111/2018 idF BGBl. I Nr. 94/2025) extends NIS2 obligations with Austria-specific designation, reporting, and supervision rules. Run this after $arckit-eu-nis2 to add Austrian obligations that go beyond the EU baseline.
text$ARGUMENTS
> Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
MANDATORY (warn if missing):
RECOMMENDED (read if available, note if missing):
$arckit-at-nisg should be run after $arckit-eu-nis2 for best resultsOPTIONAL (read if available, skip silently):
external/ — extract existing BMI / GovCERT / A-SIT correspondence, sector-specific designation letters, incident response plans, BCM plans, Sicherheitshandbuch excerpts000-global/policies/ — extract security policy, incident response policy, supplier security policy, BCM policyIdentify the target project from the hook context. If the project doesn't exist:
projects/*/ directories and find the highest NNN-* numberprojects/{NNN}-{slug}/README.mdPROJECT_ID and PROJECT_PATHRead all documents from Step 0. Identify:
Read the template (with user override support):
.arckit/templates-custom/at-nisg-template.md exists in the project root.arckit/templates/at-nisg-template.mdBefore generating the assessment, determine entity classification:
Annex I — Essential Entities (NIS2 baseline, carried into NISG): Energy, Transport, Banking, Financial market infrastructure, Health, Drinking water, Wastewater, Digital infrastructure, ICT service management, Public administration, Space.
Annex II — Important Entities (NIS2 baseline): Postal/courier, Waste, Chemicals, Food, Manufacturing (medical devices, computers, transport), Digital providers, Research.
Austrian additions or scope differences:
Size thresholds (NIS2 carried into NISG):
Show entity classification before generating the full document.
CRITICAL: Use the Write tool to create the assessment document.
ARC-{PROJECT_ID}-ATNISG-v*.md files:ARC-{PROJECT_ID}-ATNISG-v{VERSION}[NEEDS VERIFICATION][NEEDS VERIFICATION][NEEDS VERIFICATION: confirm penalty regime in NISG 2024]Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks pass.
Write the document to:
textprojects/{project_id}/ARC-{PROJECT_ID}-ATNISG-v{VERSION}.md
text━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ✅ AT NISG Assessment Generated ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-ATNISG-v{VERSION}.md 📋 Document ID: {document_id} 📅 Assessment Date: {date} ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📋 Austrian Entity Classification ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Classification: {Essential Entity / Important Entity / Out of scope} Sector: {Annex I or II sector + AT authority} Previous NISG 2018 Status: {BwD / None} GovCERT Channel: {Confirmed / Gap} ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📊 Gap Summary (Art. 21 Ten Measures) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ {Compliance status for each of the 10 measures} Total Gaps: {N} ({N} high, {N} medium, {N} low) Incident Reporting: {Ready / Gap — 24h/72h capability} ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Next steps: 1. {If no eu-nis2 baseline: run $arckit-eu-nis2 first} 2. {If personal data in security monitoring: run $arckit-at-dsgvo} 3. Run $arckit-secure to implement Art. 21 controls 4. Run $arckit-risk to register NISG gaps ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
$arckit-eu-nis2 first.$arckit-eu-dora to map the overlap; DORA generally takes precedence for ICT resilience obligations.projects/{project_id}/ARC-{PROJECT_ID}-ATNISG-v{VERSION}.mdtext$arckit-at-nisg Assess NISG obligations for a Styrian regional energy distributor (Stromnetzbetreiber) with BwD designation under NISG 2018, 400 employees, operating a SCADA migration project $arckit-at-nisg NISG scoping for 001 — Austrian MSP serving healthcare and finance customers, 180 employees, HQ in Vienna with a secondary site in Linz $arckit-at-nisg Austrian NIS2 transposition assessment for a federal ministry IT service provider, public administration sector, including GovCERT reporting readiness
After completing this command, consider running:
$arckit-eu-nis2 -- Run the pan-EU NIS2 baseline first if not already completed (when No prior eu-nis2 assessment exists for this project)$arckit-at-dsgvo -- Assess AT DSG obligations where NISG processing involves personal data (when Security monitoring processes personal data (logs, user activity))$arckit-risk -- Integrate NISG gap findings into the project risk register$arckit-secure -- Implement security controls addressing NISG / NIS2 Article 21 ten minimum measures| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-17 | pass→pass | 6,622 | 6,921 | +5% | 1 | 1 | 0% | 1,462 | 5,013 | +243% | 0 | 0 | — |
case-01 | fail→fail | 40,001 | 6,201 | -84% | 1 | 1 | 0% | 5,043 | 4,123 | -18% | 0 | 0 | — |
case-02 | fail→fail | 30,528 | 3,862 | -87% | 1 | 1 | 0% | 4,649 | 4,067 | -13% | 0 | 0 | — |
case-03 | fail→fail | 23,263 | 4,485 | -81% | 1 | 1 | 0% | 3,916 | 4,043 | +3% | 0 | 0 | — |
case-04 | pass→fail | 15,580 | 6,941 | -55% | 1 | 1 | 0% | 2,610 | 4,282 | +64% | 0 | 0 | — |
case-05 | pass→fail | 35,788 | 6,995 | -80% | 1 | 1 | 0% | 4,566 | 4,281 | -6% | 0 | 0 | — |
case-06 | pass→fail | 19,082 | 6,265 | -67% | 1 | 1 | 0% | 3,354 | 4,294 | +28% | 0 | 0 | — |
case-07 | pass→pass | 12,717 | 10,510 | -17% | 1 | 1 | 0% | 2,105 | 6,120 | +191% | 0 | 0 | — |
case-08 | pass→fail | 13,491 | 6,801 | -50% | 1 | 1 | 0% | 2,266 | 4,233 | +87% | 0 | 0 | — |
case-09 | pass→pass | 11,325 | 16,928 | +49% | 1 | 1 | 0% | 1,829 | 6,414 | +251% | 0 | 0 | — |
case-10 | pass→pass | 12,566 | 13,468 | +7% | 1 | 1 | 0% | 2,079 | 5,569 | +168% | 0 | 0 | — |
case-16 | fail→pass | 15,414 | 11,291 | -27% | 1 | 1 | 0% | 2,486 | 5,577 | +124% | 0 | 0 | — |
case-11 | pass→pass | 12,161 | 28,384 | +133% | 1 | 1 | 0% | 1,871 | 8,549 | +357% | 0 | 0 | — |
case-12 | pass→pass | 6,223 | 10,652 | +71% | 1 | 1 | 0% | 1,078 | 6,053 | +462% | 0 | 0 | — |
case-13 | pass→pass | 11,874 | 5,653 | -52% | 1 | 1 | 0% | 2,276 | 4,866 | +114% | 0 | 0 | — |
case-14 | fail→pass | 10,554 | 8,790 | -17% | 1 | 1 | 0% | 1,680 | 5,211 | +210% | 0 | 0 | — |
case-15 | fail→fail | 13,926 | 3,756 | -73% | 1 | 1 | 0% | 2,378 | 4,187 | +76% | 0 | 0 | — |
case-18 | pass→pass | 15,325 | 13,206 | -14% | 1 | 1 | 0% | 2,469 | 6,141 | +149% | 0 | 0 | — |
case-19 | fail→pass | 13,625 | 7,546 | -45% | 1 | 1 | 0% | 2,243 | 5,179 | +131% | 0 | 0 | — |
case-20 | pass→pass | 5,060 | 2,950 | -42% | 1 | 1 | 0% | 791 | 4,416 | +458% | 0 | 0 | — |
case-21 | pass→pass | 11,960 | 9,859 | -18% | 1 | 1 | 0% | 2,012 | 5,406 | +169% | 0 | 0 | — |
case-22 | pass→pass | 14,751 | 20,070 | +36% | 1 | 1 | 0% | 2,449 | 6,899 | +182% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 14 counted toward the lift figure. The other 8 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of -5 percentage points is the difference between those two pass rates over the 14 comparable cases. 5 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.