{
  "tool_id": "art-142-nis2-art21-gap-checker",
  "kernel_id": "art-142-nis2-art21-gap-checker",
  "display_name": "NIS2 Article 21 Gap Checker (Ten Cybersecurity Risk-Management Measures)",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_mandate",
  "purpose": "Check presence and maturity of all ten NIS2 Article 21(2)(a)–(j) cybersecurity risk-management measures. Derives per-measure maturity (0=absent, 1=documented-only, 2=implemented, 3=implemented+tested), aggregates to compliance score 0–100 and grade A–F, emits critical-gap list and prioritised remediation list. Consumes art-141 scope verdict; feeds penalty exposure calculator art-143.",
  "control_description": "Check presence and maturity of all ten NIS2 Article 21(2)(a)–(j) cybersecurity risk-management measures. Derives per-measure maturity (0=absent, 1=documented-only, 2=implemented, 3=implemented+tested), aggregates to compliance score 0–100 and grade A–F, emits critical-gap list and prioritised remediation list. Consumes art-141 scope verdict; feeds penalty exposure calculator art-143.",
  "declared_inputs": [
    "art-141-nis2-entity-scope-classifier"
  ],
  "declared_outputs": [
    "art-143-nis2-penalty-exposure-calculator"
  ],
  "kernel_digest": "sha256:bc2eae2bec7dca52ad1bd76a78b883c23813eeb5a8a7a58a4e67937e5b8a72bc",
  "trust_label": "deferred -- deterministic source published, zkVM proof not yet generated",
  "data_vintage": "2026-07-10",
  "last_validated": "2026-07-10",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 26,
  "source_url": "https://ainumbers.co/chaingraph/art-142-nis2-art21-gap-checker.html",
  "generated_at": "2026-07-25T20:02:55.601Z"
}
