Lints Markdown risk registers: all ten NIS2 Article 21(2) measures (a)-(j) covered, and every risk row has an owner, a 1-5 score, a treatment and a review inside 12 months. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
16 rules: ten Art. 21(2) measures (a)-(j) plus owner, 1-5 score, treatment and 12-month review for Markdown risk registers
Buy the full version — $29It reads a Markdown risk register and runs 16 rules: ten check that every NIS2 Article 21(2) measure (a) to (j) is cited by at least one risk row, and six check each row for a named owner, a 1-5 likelihood and impact, a valid treatment, a real review date and a review inside 365 days. Each finding carries a line number.
It is for CISOs, security leads and compliance engineers at EU essential and important entities under NIS2, such as energy, water, transport, health and digital infrastructure operators, who keep their cybersecurity risk register as a Markdown table in a Git repository and want it audit-ready before a supervisor or certification auditor reads it.
A Markdown linter checks table syntax, not content. A chatbot can rewrite the table but does not reliably count which of the ten Art. 21(2) letters are cited and does not compare your review column with today's date. Risk Register Lint does both deterministically: the sample register gives the same 6 findings on every run.
Free: one register, all 16 rules, with line numbers, in VS Code or the browser page. On the sample register it finds 6 findings: 2 missing measures (d) and (h), 1 owner TBD, 1 likelihood written as high, 1 score 20 risk accepted, 1 review 455 days old. The licence key adds a workspace-wide scan and a dated audit evidence export.
NIS2 Article 34 lets authorities fine essential entities up to at least EUR 10,000,000 or 2 percent of worldwide annual turnover, and important entities up to at least EUR 7,000,000 or 1.4 percent. Article 20 makes the management body approve the Article 21 measures, so a gap in the risk register reaches the board, not only the security team.
A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Risk Register Lint — NIS2 Art. 21(2) checks the file you open against 16 rules, each naming its legal or official basis, from a rule set dated 2026-09-28, and points at the exact line. For a filing, an audit or a client you need that dated result on your own files.
One question, answered by the person who built it. Your email only if you want the answer sent.