Skip to main content
Glama
novtriq-tech

NOVTRIQ Engineering

check_nis2_readiness

Determine your organization's NIS2 readiness with a compliance score, maturity level, fine exposure estimate, and prioritized remediation actions.

Instructions

Assess NIS2 Directive (EU 2022/2555) compliance readiness. Returns compliance score (0-18), maturity level, estimated fine exposure, and prioritised remediation actions.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sectorYese.g. energy, transport, healthcare, banking
has_cisoYes
has_ir_planYes
has_ot_policyYes
has_24h_reportingYes
has_ot_monitoringYes
organisation_sizeYes
has_asset_inventoryYes
has_board_reportingYes
has_supplier_assessmentYes
has_network_segmentationYes
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the burden of disclosing behavioral traits. The verb 'Assess' suggests a read-only analysis, and the description lists the computed outputs. However, it does not explicitly state that the tool has no side effects, does not modify data, or does not require any permissions. It also doesn't disclose whether it performs external lookups or calculations only. The provided outputs add some transparency, but the lack of explicit safety guarantees keeps this at a moderate score.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, dense sentence that front-loads the purpose and lists key outputs. Every word earns its place, with no fluff or redundant phrasing. It is an excellent model of concise yet informative writing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

This is a complex tool with 11 input parameters, no output schema, and no annotations. The description only lists the outputs at a high level, but does not explain the meaning of the inputs, the range of the compliance score, what 'maturity level' refers to, or how the remediation actions are prioritized. For an agent to use this correctly, it would need more guidance on parameter interpretation and expected output format. The description is insufficient for the tool's complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 11 parameters but only 1 (sector) has a description, giving 9% coverage. The tool description does not explain any of the parameters, nor does it clarify expected values beyond what the names imply. While some names are self-explanatory (e.g., has_ciso), others like has_board_reporting or has_ot_policy could benefit from further detail. Given the low schema coverage and zero compensation in the description, this dimension scores poorly.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly specifies a concrete action ('Assess') and a precise resource ('NIS2 Directive (EU 2022/2555) compliance readiness'). It also lists distinct outputs (compliance score, maturity level, fine exposure, remediation actions), making it highly specific. It is clearly differentiated from sibling tools like check_uae_cybersecurity, which targets a different regulation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies a clear use case: assess an organization's readiness against the NIS2 Directive. While it doesn't explicitly mention alternatives or when not to use, the context is unambiguous. The tool is specifically for NIS2, so an agent would know when to choose it. No exclusions are stated, but none are necessary given the narrow scope.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/novtriq-tech/novtriq-engineering-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server