Skip to content

Add NIS2 directive + nis2-controls OSS mapping library#23

Open
welcome-archon wants to merge 1 commit into
getprobo:mainfrom
welcome-archon:add-nis2-and-oss-control-library
Open

Add NIS2 directive + nis2-controls OSS mapping library#23
welcome-archon wants to merge 1 commit into
getprobo:mainfrom
welcome-archon:add-nis2-and-oss-control-library

Conversation

@welcome-archon

Copy link
Copy Markdown

Two related additions, both fill genuine gaps in the current list:

1. NIS2 directive — added under Security, privacy & data protection

NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity risk-management + incident-reporting directive for essential and important entities. It's in active enforcement across most member states in 2026 and is not currently listed alongside GDPR / HIPAA / ISO 27001 in the security & data-protection section, which I expect is just because the list was built before NIS2 became operational. Same format as the existing entries:

- [NIS2](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive) - EU directive on cybersecurity risk-management and incident-reporting for essential and important entities (Annual evidence; first formal audits expected from 2027 in most member states).

Link points at the official EU Digital Strategy page (canonical for the directive, equivalent to the gdpr.eu / pcisecuritystandards.org pattern other entries use).

2. nis2-controls — added under Risk & compliance management (OSS library)

Machine-readable JSON+YAML control library for NIS2 Article 21(2), with crosswalks to ISO 27001, BSI IT-Grundschutz, CIS Controls v8, NIST CSF 2.0, DORA, and OWASP ASVS. MIT. Slots next to the existing GRR (Google) OSS entry in the same section.

Disclosure: I maintain this library. Including it as an OSS reference because the awesome-compliance list currently has zero open-source NIS2-mapping entries, and this is a permissive, schema-defined dataset rather than a hosted product. Happy to drop it from the PR if it reads as self-promotion — the NIS2 standard add is the primary contribution.

Both inserts placed alphabetically / next to the existing sibling entry, no other changes to the README.

tristanroth1 pushed a commit to tristanroth1/awesome-compliance that referenced this pull request Jun 19, 2026
…e-planner-20260510

Add CISA KEV Deadline Planner
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant