{
  "tool_id": "art-144-nis2-incident-significance-scorer",
  "kernel_id": "art-144-nis2-incident-significance-scorer",
  "display_name": "NIS2 Incident Significance Scorer (Art. 23 Reporting Threshold)",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_mandate",
  "purpose": "Score whether an operational event meets the NIS2 Art. 23 significant-incident threshold (any of: service disruption ≥1h, ≥1,000 affected users, estimated financial loss ≥€100k, third-party cascade, malicious act, cross-border impact). Emits significance verdict (not_significant / significant / critical), fires 24h/72h/30d reporting clocks, and identifies recipient authorities. Root stage of nis2-incident-and-supply-chain-readiness chain.",
  "control_description": "Score whether an operational event meets the NIS2 Art. 23 significant-incident threshold (any of: service disruption ≥1h, ≥1,000 affected users, estimated financial loss ≥€100k, third-party cascade, malicious act, cross-border impact). Emits significance verdict (not_significant / significant / critical), fires 24h/72h/30d reporting clocks, and identifies recipient authorities. Root stage of nis2-incident-and-supply-chain-readiness chain.",
  "declared_inputs": [],
  "declared_outputs": [
    "art-145-nis2-ict-supply-chain-diligence-scorer"
  ],
  "kernel_digest": "sha256:4b3d54970b0fb586ea451d0b55674b3322e00fd974a1f1ed54ade8444ca4d385",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-10",
  "last_validated": "2026-07-10",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 26,
  "source_url": "https://ainumbers.co/chaingraph/art-144-nis2-incident-significance-scorer.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
