Add NIS2 directive + nis2-controls OSS mapping library#23
Open
welcome-archon wants to merge 1 commit into
Open
Add NIS2 directive + nis2-controls OSS mapping library#23welcome-archon wants to merge 1 commit into
welcome-archon wants to merge 1 commit into
Conversation
tristanroth1
pushed a commit
to tristanroth1/awesome-compliance
that referenced
this pull request
Jun 19, 2026
…e-planner-20260510 Add CISA KEV Deadline Planner
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two related additions, both fill genuine gaps in the current list:
1. NIS2 directive — added under
Security, privacy & data protectionNIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity risk-management + incident-reporting directive for essential and important entities. It's in active enforcement across most member states in 2026 and is not currently listed alongside GDPR / HIPAA / ISO 27001 in the security & data-protection section, which I expect is just because the list was built before NIS2 became operational. Same format as the existing entries:
Link points at the official EU Digital Strategy page (canonical for the directive, equivalent to the gdpr.eu / pcisecuritystandards.org pattern other entries use).
2.
nis2-controls— added underRisk & compliance management(OSS library)Machine-readable JSON+YAML control library for NIS2 Article 21(2), with crosswalks to ISO 27001, BSI IT-Grundschutz, CIS Controls v8, NIST CSF 2.0, DORA, and OWASP ASVS. MIT. Slots next to the existing GRR (Google) OSS entry in the same section.
Disclosure: I maintain this library. Including it as an OSS reference because the awesome-compliance list currently has zero open-source NIS2-mapping entries, and this is a permissive, schema-defined dataset rather than a hosted product. Happy to drop it from the PR if it reads as self-promotion — the NIS2 standard add is the primary contribution.
Both inserts placed alphabetically / next to the existing sibling entry, no other changes to the README.