{
      "name": "nis2-incident-and-supply-chain-readiness",
      "domain": "DORA / NIS2 / ICT Resilience",
      "title": "NIS2 Incident Reporting & Supply-Chain Readiness",
      "description": "Score whether an operational event meets the NIS2 Article 23 significant-incident threshold (firing the 24h/72h/30-day reporting clocks), assess ICT vendor due-diligence posture against Art. 21(2)(d) and ENISA supply-chain guidance, and check Art. 20 management-body governance readiness including personal-liability risk flag. Terminal stage exports governance attestation with execution_hash.",
      "composer_url": "https://ainumbers.co/chaingraph/chains/nis2-incident-and-supply-chain-readiness.html",
      "steps": [
        {
          "tool_id": "art-144-nis2-incident-significance-scorer",
          "handoff": "Incident significance verdict and reporting clocks feed ICT supply-chain diligence scorer"
        },
        {
          "tool_id": "art-145-nis2-ict-supply-chain-diligence-scorer",
          "handoff": "Vendor risk tier and remediation checklist feed governance readiness checker"
        },
        {
          "tool_id": "art-146-nis2-governance-readiness-checker",
          "handoff": "Governance grade and personal liability risk — governance attestation with execution_hash"
        }
      ]
    }
