Risk Register Lint — NIS2 Art. 21(2)

Lints Markdown risk registers: all ten NIS2 Article 21(2) measures (a)-(j) covered, and every risk row has an owner, a 1-5 score, a treatment and a review inside 12 months. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

16 rules: ten Art. 21(2) measures (a)-(j) plus owner, 1-5 score, treatment and 12-month review for Markdown risk registers

Buy the full version — $29

Questions people ask

What does Risk Register Lint do?

It reads a Markdown risk register and runs 16 rules: ten check that every NIS2 Article 21(2) measure (a) to (j) is cited by at least one risk row, and six check each row for a named owner, a 1-5 likelihood and impact, a valid treatment, a real review date and a review inside 365 days. Each finding carries a line number.

Who is it for?

It is for CISOs, security leads and compliance engineers at EU essential and important entities under NIS2, such as energy, water, transport, health and digital infrastructure operators, who keep their cybersecurity risk register as a Markdown table in a Git repository and want it audit-ready before a supervisor or certification auditor reads it.

Why not just ask a chatbot or use a free Markdown linter?

A Markdown linter checks table syntax, not content. A chatbot can rewrite the table but does not reliably count which of the ten Art. 21(2) letters are cited and does not compare your review column with today's date. Risk Register Lint does both deterministically: the sample register gives the same 6 findings on every run.

What is free and what needs a licence key?

Free: one register, all 16 rules, with line numbers, in VS Code or the browser page. On the sample register it finds 6 findings: 2 missing measures (d) and (h), 1 owner TBD, 1 likelihood written as high, 1 score 20 risk accepted, 1 review 455 days old. The licence key adds a workspace-wide scan and a dated audit evidence export.

What does getting it wrong cost?

NIS2 Article 34 lets authorities fine essential entities up to at least EUR 10,000,000 or 2 percent of worldwide annual turnover, and important entities up to at least EUR 7,000,000 or 1.4 percent. Article 20 makes the management body approve the Article 21 measures, so a gap in the risk register reaches the board, not only the security team.

Why not just ask ChatGPT or another AI chat?

A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Risk Register Lint — NIS2 Art. 21(2) checks the file you open against 16 rules, each naming its legal or official basis, from a rule set dated 2026-09-28, and points at the exact line. For a filing, an audit or a client you need that dated result on your own files.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool