Rekvira

Jobs / ICT risk or security lead

NIS2 scoping memo

“The board asks whether NIS2 applies to us, and if so, as what.”

1.7 min60 tool calls43 sources read33 citations verified

Recorded 23 September 2026 on the live service with Claude Code 2.1.280 (headless: claude -p), model claude-opus-5-5.

Today In a survey of 670 business leaders in nine European countries (late 2025), 11% were unsure what NIS2 is despite falling within its scope. Survey: CyberSmart NIS2 survey

The run

Each step is a Rekvira playbook your assistant reads and follows. Open a step to see every call it made and what came back.

  1. Connected and read what the corpus holds today

    2 tool calls · under 1 s
    Show the 2 calls
    RekviraConnected, no accountconnect0.1 s
    connect({})
    RekviraRead what the corpus holds todaystart_here0.2 s
    start_here({})
  2. Applied the scope tests and read the duties, then checked where other EU acts take over

    25 tool calls · 34 s
    Show the 25 calls
    RekviraOpened the playbook nis2-essential-entityget_workflow0.1 s
    get_workflow({"workflow_id": "nis2-essential-entity"})
    RekviraOpened the playbook cross-reg-compliance-scanget_workflow0.2 s
    get_workflow({"workflow_id": "cross-reg-compliance-scan"})
    RekviraArticle 2, full textread_unit0.0 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 2})
    • Article 2 This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for i
    RekviraArticle 3, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 3})
    • Article 3 For the purposes of this Directive, the following entities shall be considered to be essential entities: (a) entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises provided for in Article 2(1) of the Annex to Recommend
    RekviraANNEX I, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "annex", "number": "I"})
    • ANNEX I Energy (a) Electricity (b) District heating and cooling (c) Oil (d) Gas (e) Hydrogen Transport (a) Air (b) Rail (c) Water (d) Road Banking Financial market infrastructures Health Drinking water Waste water Digital infrastructure ICT service management
    RekviraANNEX II, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "annex", "number": "II"})
    • ANNEX II Postal and courier services Waste management Manufacture, production and distribution of chemicals Production, processing and distribution of food Manufacturing (a) Manufacture of medical devices and in vitro diagnostic medical devices (b) Manufacture of
    RekviraANNEX I, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "pinpoint": "ANNEX I(9)"})
    • ANNEX I Energy (a) Electricity (b) District heating and cooling (c) Oil (d) Gas (e) Hydrogen Transport (a) Air (b) Rail (c) Water (d) Road Banking Financial market infrastructures Health Drinking water Waste water Digital infrastructure ICT service management
    RekviraSearched nis2 for “managed service provider definition”search_regulation0.1 s
    search_regulation({"regulation": "nis2", "query": "managed service provider definition"})
    • Article 6, amendment (34)
    • Article 6, amendment (39)
    • Article 6, amendment (40)
    RekviraSearched nis2 for “ICT service management business-to-business managed service providers”search_regulation0.1 s
    search_regulation({"regulation": "nis2", "query": "ICT service management business-to-business managed service providers", "kinds": ["annex", "paragraph", "recital"]})
    • ANNEX I(9)
    • Article 21(2)
    • Recital (85)
    RekviraObligation headings for important entity in nis2lookup_obligations0.0 s
    lookup_obligations({"regulation": "nis2", "role": "important entity"})
    RekviraObligation headings for essential entity in nis2lookup_obligations0.1 s
    lookup_obligations({"regulation": "nis2", "role": "essential entity"})
    RekviraArticle 21, full textread_unit0.0 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 21})
    • Article 21 Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for the
    RekviraArticle 23, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 23})
    • Article 23 Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of any incident that has a significant impact on the provision of their ser
    RekviraArticle 20, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 20})
    • Article 20 Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infri
    RekviraArticle 4, full textread_unit0.0 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 4})
    • Article 4 Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents and where those requirements are at least equivalent in effect to the obligations laid down in thi
    RekviraArticle 27, full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 27})
    • Article 27 ENISA shall create and maintain a registry of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed servic
    RekviraArticle 33(1), full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "paragraph", "number": 1, "article": 33})
    • Article 33(1) When provided with evidence, indication or information that an important entity allegedly does not comply with this Directive, in particular Articles 21 and 23 thereof, Member States shall ensure that the competent authorities take action, where necessary, thr
    RekviraArticle 34, full textread_unit0.0 s
    read_unit({"regulation": "nis2", "kind": "article", "number": 34})
    • Article 34 Member States shall ensure that the administrative fines imposed on essential and important entities pursuant to this Article in respect of infringements of this Directive are effective, proportionate and dissuasive, taking into account the circumstances of ea
    RekviraArticle 26(1), full textread_unit0.1 s
    read_unit({"regulation": "nis2", "kind": "paragraph", "number": 1, "article": 26})
    • Article 26(1) Entities falling within the scope of this Directive shall be considered to fall under the jurisdiction of the Member State in which they are established, except in the case of: (a) providers of public electronic communications networks or providers of publicly
    RekviraSearched every loaded act for “ICT third-party service provider contractual arrangements financial entity”search_regulations0.1 s
    search_regulations({"query": "ICT third-party service provider contractual arrangements financial entity", "regulations": ["dora", "nis2"]})
    • Article 26(4)
    • Article 32(10)
    • Article 28(2)
    RekviraSearched dora for “Directive (EU) 2022/2555 lex specialis relationship”search_regulation0.2 s
    search_regulation({"regulation": "dora", "query": "Directive (EU) 2022/2555 lex specialis relationship"})
    • Article 20
    • Article 1(2)
    • Article 3, amendment (2)
    RekviraArticle 30, full textread_unit0.0 s
    read_unit({"regulation": "dora", "kind": "article", "number": 30})
    • Article 30 The rights and obligations of the financial entity and of the ICT third-party service provider shall be clearly allocated and set out in writing. The full contract shall include the service level agreements and be documented in one written document which shall
    RekviraArticle 31(1), full textread_unit0.0 s
    read_unit({"regulation": "dora", "kind": "paragraph", "number": 1, "article": 31})
    • Article 31(1) The ESAs, through the Joint Committee and upon recommendation from the Oversight Forum established pursuant to Article 32(1), shall: (a) designate the ICT third-party service providers that are critical for financial entities, following an assessment that take
    RekviraArticle 3, amendment (19), full textread_unit0.1 s
    read_unit({"regulation": "dora", "kind": "paragraph", "number": 19, "article": 3})
    • Article 3, amendment (19) ‘ICT third-party service provider’ means an undertaking providing ICT services;
    RekviraArticle 33(2), full textread_unit0.1 s
    read_unit({"regulation": "gdpr", "kind": "paragraph", "number": 2, "article": 33})
    • Article 33(2) The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
  3. You confirm. Confirm the sector, the headcount and the turnover or balance-sheet figures the size test uses.

    In this run: Checkpoint (recorded mid-run): I assumed the sector is Annex I point 9, "ICT service management (business-to-business)", as a managed service provider. I applied 85 staff and EUR 14m turnover, with no balance-sheet figure and no group or partner companies. That makes the company medium-sized, not above the medium-sized ceilings, and not designated. The resulting class is important.

  4. Checked every citation against the official text

    33 tool calls · 22 s
    Show the 33 calls
    RekviraArticle 2(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 2(1)", "regulation": "nis2", "quote": "Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive."})
    • Article 2(1) exists: held · quote: found
    RekviraArticle 2(2): heldverify_citation0.1 s
    verify_citation({"citation": "Article 2(2)", "regulation": "nis2"})
    • Article 2(2) exists: held
    RekviraArticle 3(1): heldverify_citation0.0 s
    verify_citation({"citation": "Article 3(1)", "regulation": "nis2"})
    • Article 3(1) exists: held
    RekviraArticle 3(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 3(2)", "regulation": "nis2", "quote": "entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities"})
    • Article 3(2) exists: held · quote: found
    RekviraArticle 3(4): heldverify_citation0.0 s
    verify_citation({"citation": "Article 3(4)", "regulation": "nis2"})
    • Article 3(4) exists: held
    RekviraArticle 4(1): heldverify_citation0.1 s
    verify_citation({"citation": "Article 4(1)", "regulation": "nis2"})
    • Article 4(1) exists: held
    RekviraArticle 6(39): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 6(39)", "regulation": "nis2", "quote": "via assistance or active administration carried out either on customers’ premises or remotely"})
    • Article 6, amendment (39) exists: held · quote: found
    RekviraAnnex I(9): held, quoted words foundverify_citation0.2 s
    verify_citation({"citation": "Annex I(9)", "regulation": "nis2", "quote": "ICT service management (business-to-business)"})
    • ANNEX I exists: held · quote: found
    RekviraArticle 20(1): heldverify_citation0.1 s
    verify_citation({"citation": "Article 20(1)", "regulation": "nis2"})
    • Article 20(1) exists: held
    RekviraArticle 20(2): heldverify_citation0.0 s
    verify_citation({"citation": "Article 20(2)", "regulation": "nis2"})
    • Article 20(2) exists: held
    RekviraArticle 21(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 21(2)", "regulation": "nis2", "quote": "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers"})
    • Article 21(2) exists: held · quote: found
    RekviraArticle 21(1): heldverify_citation0.0 s
    verify_citation({"citation": "Article 21(1)", "regulation": "nis2"})
    • Article 21(1) exists: held
    RekviraArticle 21(4): heldverify_citation0.1 s
    verify_citation({"citation": "Article 21(4)", "regulation": "nis2"})
    • Article 21(4) exists: held
    RekviraArticle 21(5): heldverify_citation0.1 s
    verify_citation({"citation": "Article 21(5)", "regulation": "nis2"})
    • Article 21(5) exists: held
    RekviraArticle 23(4): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 23(4)", "regulation": "nis2", "quote": "within 24 hours of becoming aware of the significant incident, an early warning"})
    • Article 23(4) exists: held · quote: found
    RekviraArticle 23(1): heldverify_citation0.0 s
    verify_citation({"citation": "Article 23(1)", "regulation": "nis2"})
    • Article 23(1) exists: held
    RekviraArticle 23(2): heldverify_citation0.1 s
    verify_citation({"citation": "Article 23(2)", "regulation": "nis2"})
    • Article 23(2) exists: held
    RekviraArticle 23(3): heldverify_citation0.1 s
    verify_citation({"citation": "Article 23(3)", "regulation": "nis2"})
    • Article 23(3) exists: held
    RekviraArticle 23(11): heldverify_citation0.0 s
    verify_citation({"citation": "Article 23(11)", "regulation": "nis2"})
    • Article 23(11) exists: held
    RekviraArticle 26(1): heldverify_citation0.0 s
    verify_citation({"citation": "Article 26(1)", "regulation": "nis2"})
    • Article 26(1) exists: held
    RekviraArticle 27(2): heldverify_citation0.0 s
    verify_citation({"citation": "Article 27(2)", "regulation": "nis2"})
    • Article 27(2) exists: held
    RekviraArticle 27(3): heldverify_citation0.1 s
    verify_citation({"citation": "Article 27(3)", "regulation": "nis2"})
    • Article 27(3) exists: held
    RekviraArticle 33(1): heldverify_citation0.1 s
    verify_citation({"citation": "Article 33(1)", "regulation": "nis2"})
    • Article 33(1) exists: held
    RekviraArticle 34(5): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 34(5)", "regulation": "nis2", "quote": "EUR 7 000 000"})
    • Article 34(5) exists: held · quote: found
    RekviraArticle 4(2): heldverify_citation0.0 s
    verify_citation({"citation": "Article 4(2)", "regulation": "nis2"})
    • Article 4(2) exists: held
    RekviraArticle 1(2): held, quoted words foundverify_citation0.2 s
    verify_citation({"citation": "Article 1(2)", "regulation": "dora", "quote": "this Regulation shall be considered a sector-specific Union legal act for the purposes of Article 4 of that Directive"})
    • Article 1(2) exists: held · quote: found
    RekviraArticle 3(19): heldverify_citation0.0 s
    verify_citation({"citation": "Article 3(19)", "regulation": "dora"})
    • Article 3, amendment (19) exists: held
    RekviraArticle 28(1): heldverify_citation0.1 s
    verify_citation({"citation": "Article 28(1)", "regulation": "dora"})
    • Article 28(1) exists: held
    RekviraArticle 30(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 30(2)", "regulation": "dora", "quote": "the obligation of the ICT third-party service provider to fully cooperate with the competent authorities and the resolution authorities of the financial entity"})
    • Article 30(2) exists: held · quote: found
    RekviraArticle 30(3): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 30(3)", "regulation": "dora", "quote": "the obligation of the ICT third-party service provider to participate and fully cooperate in the financial entity’s TLPT"})
    • Article 30(3) exists: held · quote: found
    RekviraArticle 31(1): heldverify_citation0.0 s
    verify_citation({"citation": "Article 31(1)", "regulation": "dora"})
    • Article 31(1) exists: held
    RekviraArticle 33(2): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 33(2)", "regulation": "gdpr", "quote": "The processor shall notify the controller without undue delay after becoming aware of a personal data breach."})
    • Article 33(2) exists: held · quote: found
    RekviraArticle 28: heldverify_citation0.0 s
    verify_citation({"citation": "Article 28", "regulation": "gdpr"})
    • Article 28 exists: held

What it produced: the scoping memo

Word for word what the assistant wrote at the end of the run. The company in it is invented for this demonstration; the regulation text, pinpoints and checks are what Rekvira returned.

NIS2 scoping memo: Tinklas IT UAB (illustrative)

Directive (EU) 2022/2555 (NIS2), CELEX 32022L2555. Text as held on data_as_of 2026-09-02 (EUR-Lex). This memo sets out sources, not advice. The final classification belongs to the company and its competent authority. It cross-reads DORA (32022R2554) and GDPR (32016R0679).

Checkpoint (recorded mid-run): I assumed the sector is Annex I point 9, "ICT service management (business-to-business)", as a managed service provider. I applied 85 staff and EUR 14m turnover, with no balance-sheet figure and no group or partner companies. That makes the company medium-sized, not above the medium-sized ceilings, and not designated. The resulting class is important.

1. The entity

Tinklas IT UAB is a private company in Kaunas, Lithuania, with 85 staff and EUR 14m turnover. It installs, runs and maintains networks, servers and helpdesks for other businesses under contract. Its customers are two hospitals, two banks and about 40 SMEs. It is not a public body and no authority has designated it.

2. Sector test (Annex I or II)

  • Annex I, point 9: "ICT service management (business-to-business)."
  • Art 6(39) defines a managed service provider as an entity providing "services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, via assistance or active administration carried out either on customers' premises or remotely". Running networks, servers and helpdesks for other businesses fits that wording.
  • Managed service providers are named directly in Art 21(5), Art 23(11), Art 26(1)(b) and Art 27(1).
  • Limitation: Rekvira's copy of Annex I holds only the sector headings, not the "type of entity" column. The link between point 9 and managed service providers rests on Art 6(39) and the articles above. Check it against the Official Journal table.

3. Size test

  • Art 2(1): NIS2 applies to Annex I or II entities that qualify as medium-sized under Article 2 of the Annex to Recommendation 2003/361/EC, or that exceed those ceilings. Art 2(1) also says that "Article 3(4) of the Annex to that Recommendation shall not apply."
  • The Recommendation is not held in Rekvira. From its published text: a medium-sized enterprise has fewer than 250 staff and either turnover of EUR 50m or less or a balance sheet of EUR 43m or less. Enterprises with fewer than 50 staff and EUR 10m or less fall below medium (small).
  • With 85 staff and EUR 14m turnover, Tinklas is medium-sized. It is at or above the entry threshold in Art 2(1) and does not exceed the medium-sized ceilings.
  • The size-independent routes in Art 2(2)(a)–(f), 2(3) and 2(4) do not apply on these facts. Tinklas is not a telecoms provider, trust service provider, domain name registry or DNS provider, domain name registrar, public administration or critical entity. Points (b)–(e) cover being the sole provider, or having a significant impact or national importance. They apply only if the Member State identifies the entity, and no such identification has been made.

Result: NIS2 applies.

4. Essential or important

  • Art 3(1)(a): an Annex I entity is essential only if it exceeds the medium-sized ceilings. Tinklas does not.
  • Art 3(1)(b)–(g) do not apply on the facts: no qualified trust or DNS services, no telecoms, not public administration, not identified under Art 2(2)(b)–(e), not a critical entity, and not a former operator of essential services.
  • Art 3(2): "entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities."

Result: an important entity by operation of the text, unless Lithuania identifies it as essential under Art 2(2)(b)–(e) and Art 3(1)(e). Having hospitals and banks as customers does not change this test. It could only matter if the authority relied on it for an Art 2(2)(c)–(e) identification.

5. Duties that follow

lookup_obligations returned zero headings for both roles. Its also_named list pointed to Art 3, 33 and 34 for important entities and Art 32 for essential entities. The duties below come from reading the text.

DutyPinpoint
Registration details for the national list: name, contacts, IP ranges, sector. Changes must be notified within 2 weeks.Art 3(4)
Managed-service-provider registry details (feeds the ENISA registry): sector and type, establishments, Member States served, IP ranges. Changes must be notified within 3 months.Art 27(2), 27(3)
Jurisdiction: the Member State of the main establishment in the Union (Lithuania on these facts)Art 26(1)(b)
The management body approves the risk-management measures, oversees them and can be held liable. Its members must take training.Art 20(1), 20(2)
Appropriate and proportionate risk-management measures, all-hazards, covering at least points (a)–(j): risk analysis, incident handling, business continuity, supply chain, secure development and maintenance, effectiveness review, cyber hygiene and training, cryptography, HR and access control and asset management, multi-factor authenticationArt 21(1), 21(2)
Corrective measures without undue delay where it finds it does not complyArt 21(4)
The Commission's implementing act on technical and methodological requirements specifically covers managed service providersArt 21(5)
Significant-incident reporting: early warning within 24h, notification within 72h, final report within 1 month. Notify affected service recipients where appropriate.Art 23(1), 23(3), 23(4)
Tell affected recipients about significant cyber threats and the measures they can takeArt 23(2)
The Commission's implementing act on which incidents count as significant covers managed service providersArt 23(11)
Supervision is ex post, triggered by evidence or indications of non-complianceArt 33(1)
Fines for breaching Art 21 or 23: maximum of at least EUR 7m or 1.4% of worldwide turnover, whichever is higherArt 34(5)

The implementing act under Art 21(5) and Art 23(11) is not held in Rekvira. The company should read it directly, because it is where the managed-service-provider requirements are set out in detail.

6. Where other EU acts take over (each act kept separate)

NIS2 Art 4. Where a sector-specific Union act imposes risk-management or reporting duties at least equivalent to NIS2 (Art 4(2)), those NIS2 provisions do not apply to the entities covered by that act (Art 4(1)).

DORA. Art 1(2) makes DORA the sector-specific act under NIS2 Art 4 only "in relation to financial entities". That takes over NIS2 duties for the two banks, not for Tinklas. On the board's bank question:

  • Nothing in DORA removes or replaces Tinklas's NIS2 duties.
  • Tinklas is an "ICT third-party service provider" ("an undertaking providing ICT services", Art 3(19)). The banks stay fully responsible for their own ICT third-party risk (Art 28(1)).
  • The bank contracts must contain the terms in Art 30(2). These include service locations, data protection, assistance during incidents, and full cooperation with the banks' competent and resolution authorities.
  • If a service supports critical or important functions, the contracts must also contain the terms in Art 30(3). These include business-continuity testing, taking part in the bank's threat-led penetration testing (TLPT), unrestricted access, inspection and audit rights, and exit transition periods. These duties reach Tinklas through contract.
  • Direct oversight under DORA applies only if the European Supervisory Authorities (ESAs) designate Tinklas a critical ICT third-party provider (Art 31(1)). Nothing suggests that on these facts.

GDPR. Where Tinklas processes personal data for customers (for example hospital patient data on the systems it runs), it acts as a processor under Art 28. It must notify the controller of a personal data breach "without undue delay" (Art 33(2)). This runs alongside NIS2 Art 23. The two do not replace each other.

Hospitals. Health is an Annex I sector, so the hospitals are likely NIS2 entities themselves. Their supply-chain duties under Art 21(2)(d) will be passed down to Tinklas through contract. That does not change Tinklas's class.

7. Citations checked

Every pinpoint above was checked with verify_citation and returned exists=held:

  • NIS2: Art 2(1)\, 2(2), 3(1), 3(2)\, 3(4), 4(1), 4(2), 6(39)\, 20(1), 20(2), 21(1), 21(2)\, 21(4), 21(5), 23(1), 23(2), 23(3), 23(4)\, 23(11), 26(1), 27(2), 27(3), 33(1), 34(5)\, Annex I(9)\*
  • DORA: Art 1(2)\, 3(19), 28(1), 30(2)\, 30(3)\*, 31(1)
  • GDPR: Art 28, 33(2)\*

\* the quoted wording was also checked and found.

Art 26(1)(b) and Art 27(1) were read in full with read_unit. They were verified at paragraph level (Art 26(1)) or read only (Art 27(1)). Recommendation 2003/361/EC is not held, so the size ceilings in section 3 are not verified here.

8. Open points for your decision

  1. Lithuanian transposition. The national cybersecurity law implementing NIS2, including its registration mechanism, deadlines, competent authority and CSIRT, was not read. It is not held in Rekvira.
  2. Designation and the national list. Rekvira cannot see whether the Lithuanian authority has listed or identified Tinklas under Art 3(3) or Art 2(2)(b)–(e), including any identification as essential.
  3. Group structure. Are there partner or linked companies whose staff or financial figures would count towards size under the Recommendation? Also confirm the balance sheet total.
  4. Annex I "type of entity" column. Confirm the managed-service-provider entry against the Official Journal table.
  5. Implementing act for managed service providers (Art 21(5) and 23(11)). Read it directly, because it is not held here.
  6. DORA contract review. Do the services to the two banks support critical or important functions? That decides whether the full Art 30(3) terms apply.
  7. I recorded no applicability verdicts in Rekvira. Once you confirm the class, you can have them recorded against Art 3(2), 21 and 23.

Start it yourself

Connect Rekvira to Claude, ChatGPT or Cursor (one step, no account), then paste this and add your facts:

Use Rekvira to write a NIS2 scoping memo for the company I describe below: in scope or not, essential or important, and the duties that follow.

Where you decide

  • After nis2-essential-entity: Confirm the sector, the headcount and the turnover or balance-sheet figures the size test uses.

What comes back

  1. The entity
  2. Sector test (Annex I or II)
  3. Size test
  4. Essential or important
  5. Duties that follow
  6. Where other EU acts take over
  7. Citations checked
  8. Open points for your decision

How it keeps it defensible

  • Each test cites the article, paragraph or annex it applies
  • Every pinpoint is checked with verify_citation
  • Names the national transposition and designation decisions it cannot see

What it will not do

  • Read your country's transposition law or its list of designated entities
  • Decide the classification for the regulator: it lays out the tests and the text
  • Assess your security measures

Recorded on the live Rekvira service on 23 September 2026 without an account, with the job's playbooks named in the prompt. The prompt, every tool call and the finished text are stored as recorded; tool results above are shortened. The scenario is illustrative.