{
      "name": "nis2-entity-scope-and-obligations",
      "domain": "DORA / NIS2 / ICT Resilience",
      "title": "NIS2 Entity Scope & Obligations",
      "description": "Determine NIS2 entity classification (Essential/Important/Out-of-scope), assess Article 21 cybersecurity risk-management measure maturity across all ten controls, and calculate maximum penalty exposure under Article 34 including mitigating-factor adjustment. Full chain exports a board-ready PDF with execution_hash.",
      "composer_url": "https://ainumbers.co/chaingraph/chains/nis2-entity-scope-and-obligations.html",
      "steps": [
        {
          "tool_id": "art-141-nis2-entity-scope-classifier",
          "handoff": "Entity classification (Essential/Important/Out-of-scope) and penalty caps feed Art. 21 gap checker"
        },
        {
          "tool_id": "art-142-nis2-art21-gap-checker",
          "handoff": "Art. 21 compliance score and critical gaps feed penalty exposure calculator"
        },
        {
          "tool_id": "art-143-nis2-penalty-exposure-calculator",
          "handoff": "Maximum penalty exposure and mitigated estimate — board-ready export with execution_hash"
        }
      ]
    }
