{
      "tool_id": "art-145-nis2-ict-supply-chain-diligence-scorer",
      "tool_version": "1.0.0",
      "display_name": "NIS2 ICT Supply-Chain Diligence Scorer (Art. 21(2)(d) / ENISA)",
      "mcp_name": "score_nis2_supply_chain_diligence",
      "mandate_type": "compliance_mandate",
      "wave": 26,
      "gpu": false,
      "url": "https://ainumbers.co/chaingraph/art-145-nis2-ict-supply-chain-diligence-scorer.html",
      "description": "Score ICT vendor due-diligence posture against NIS2 Art. 21(2)(d) and ENISA ICT supply-chain risk framework. Seven controls: ISO 27001 certification, vendor incident history, audit clause, breach-notification SLA ≤72h, EU-only data residency, sub-contractor mapping, availability SLA ≥99.5%. Emits risk score, tier (Low/Medium/High/Critical), active flags, and remediation checklist.",
      "input_schema_ref": "chaingraph/art-145-nis2-ict-supply-chain-diligence-scorer.html#manifest",
      "consumes": [
        "art-144-nis2-incident-significance-scorer"
      ],
      "feeds": [
        "art-146-nis2-governance-readiness-checker"
      ],
      "status": "live",
      "conformance_fixtures": true,
      "compute_capability": "server",
      "compute_images": [{"system":"sha256-source","image_id":"sha256:5568ba2aecf8ca9923d20122d22c9cfd8950d2e781ea7cc58041c885e3de85b4","valid_from":"2026-07-10"},{"system":"risc0","image_id":"sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6","valid_from":"2026-06-28"}],
      "compute_proof": {
        "type": "ZkVmReceipt",
        "system": "risc0",
        "receiptFormat": "groth16-bn254",
        "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
        "seal": "GRpW49bOACKaOFpavocfd/7GQAaX1ZIU3n4t1uE84I0ZWZmKNRnEEdvs0eAYc/KO+Hx0pAZNFqr0uiIOEKpd2hQrpVqsNMBXGHpcuZZPCpckts5B17BhTeG2N9c8qVL+E72rwL/JDEqUBcNBLw5gwqG+pfRB5MZWX1eZ4/YekYEv9bHBerP9yTeMP0nGggPqEY1H+g5QA62ttR8k9S8Lhg2Oj0vk40u12P8TGfQvNG7EkCK2ouz7MrPcY2Ni9VVdLWLWSc3UCusrn1JaiMZJgagXolYsfJlpFUYt/VZ+OOEW+5VUpGyHl+XkvRxGwEMiDCfgBpYR2xS39XhQN9DOrg==",
        "journal": {
          "chaingraph_version": "0.4.0",
          "kernel_digest": "sha256:f6cb28e18e77723ace52cdb18e2cfa05888fd9a6d077b9f11293ef150cf90285",
          "output": {
            "active_risk_flags": [],
            "enisa_control_coverage_pct": 100,
            "remediation_checklist": [],
            "risk_score": 0,
            "risk_tier": "low",
            "vendor_incident_history_12mo": 0
          }
        }
      },
      "export_capability": [
        "json",
        "vc"
      ]
    }
