National energy statutes
audited GREEN jurisdictions (e.g. SE Ellagen, DE EnWG, GB Electricity Act 1989 + Utilities Act 2000, NO energiloven)
Grid and generation compliance, anchored on the NIS2 duties that land on essential entities.
Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.
Energy compliance grounded in the regulations that bite — NIS2 essential-entity obligations, the Critical Entities Resilience Directive, and the EU cyber stack at article level — alongside national energy statute across the audited GREEN jurisdictions and the national regulators' decisions, grid codes and network regulations for seven of them. US federal energy regulation is served too: FERC (18 CFR) and the NRC nuclear rules (10 CFR). The DOE C2M2 maturity model and the CISA cross-sector performance goals give the programme a scored spine. Run the NIS2 gap analysis or an OT threat model on grid, generation and SCADA estates.
National energy statutes
audited GREEN jurisdictions (e.g. SE Ellagen, DE EnWG, GB Electricity Act 1989 + Utilities Act 2000, NO energiloven)
National energy-regulator decisions, grid codes and network regulations
GB, DE, NO, SE, FI, DK and NL, attributed per row to the regulator that issued them
US federal energy regulation — FERC (18 CFR) and the NRC nuclear rules (10 CFR)
served verbatim from the eCFR
Dutch radiation-protection and nuclear-safety regulation (ANVS)
NIS2 (Dir (EU) 2022/2555)
essential-entity security measures (Art. 21) & supervision
Critical Entities Resilience Directive (EU) 2022/2557
energy as a designated critical-entity sector
Cybersecurity Act (EUCC) · Cyber Solidarity Act
DOE C2M2 v2.1
356 maturity practices across ten domains, each tagged MIL1-MIL3, served verbatim — the de-facto energy-sector maturity model
CISA Cross-Sector Cybersecurity Performance Goals v2.0
the baseline critical-infrastructure control spine, water and wastewater included, crosswalked to NIST CSF 2.0 / 800-53 / 800-82r3 — served verbatim
Energy case law · preparatory works · agency guidance
NIS2 gap analysis
Directive (EU) 2022/2555 Art. 21 for energy essential and important entities — the page spine
OT / ICS threat model
STRIDE zones-and-conduits for grid, generation, substation and SCADA systems
OT / ICS TARA
for operational-technology assets — an available analysis, never a legally-assured verdict
Effective-risk CVE rescoring
reprioritise OT/ICS vulnerabilities with NVD / CISA KEV / EPSS context — never exploit code
C2M2 maturity-scored gap analysis
the DOE C2M2 practices at MIL1-MIL3 over your OT programme, with the CISA performance goals as the cross-sector baseline — assembled from the served practice text and the gap-analysis workflow
Critical Entities Resilience & regulatory gap analysis
CER (EU) 2022/2557 and broader regimes
Adversary tabletop & enterprise risk assessment
critical-infrastructure incident readiness (ISO 31000 / NIST 800-30)
STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.
Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.
Building energy compliance? It works today — we take on a few design partners per sector to tune it to your team.