Advisory · Compliance · Cybersecurity · Strategy

IT strategy and cyber resilience

Comprehensive audit preparation and outsourced security officer services across NIS2, DORA, ISO 27001, ISO 42001, ISO 22301, IoT and system integrity. From gap analysis to successful certification.

CISA & CISM advisers ISO 27001 & 42001 Lead Auditors Response within 24 hours 120+ successful projects
Qualifications & standards
What we do

Expert guidance through complex requirements
— from planning to a successful audit.

One team for the full range of cybersecurity regulations and standards, from framework implementation to audit readiness.

Our full range of services
Ongoing support

Outsourced Data Protection Officer (DPO)

A registered DPO with regulatory experience, available for a predictable monthly fee and with capacity tailored to your organisation. Expert oversight of GDPR compliance, so you can focus on your business.

Explore and get an estimate
Audit readiness

DORA implementation and audit readiness

We help financial entities and their direct service providers implement digital operational resilience frameworks that meet DORA requirements. Our audit preparation experience and relationships with leading audit firms bring ICT risk management, major incident handling and resilience testing into a coherent, transparent and auditable framework.

Framework

System integrity frameworks and audit preparation

Our experts help you implement and operate controlled IT environments that meet regulatory requirements for system integrity. Data handling, access management and tamper-resistant logging form a transparent, continuously auditable control framework.

AI · New

AI management systems and ISO 42001 audit readiness

We help you implement and operate an Artificial Intelligence Management System (AIMS) aligned with international standards. Our experts bring risk management, ethical principles and technical compliance together to make your use of AI transparent and accountable.

Continuity

BCMS implementation and ISO 22301 audit readiness

Implement a Business Continuity Management System (BCMS) aligned with international standards. Integrate disruption prevention, recovery of critical functions and emergency procedures into one auditable framework.

Framework

IoT security services

Compliance advice for IoT security management aligned with international standards. We help you demonstrate that the physical environment, communications and privacy controls of connected devices and networks meet applicable requirements within a measurable, auditable framework.

Advisory

Strategic cybersecurity advisory

Integrate cybersecurity into your business strategy, with the right security architecture, clear risk priorities and a practical approach to business continuity.

Training

Information security awareness training

Role-specific awareness programmes for employees and executives, helping make security part of your organisational culture.

Compliance

Regulatory compliance

Comprehensive support for key regulatory requirements, from gap analysis and policy development to technical implementation.

About us

Expertise backed by
international qualifications

Our team holds leading international cybersecurity and audit qualifications. We combine a thorough understanding of NIS2, DORA, ISO 27001 and ISO 42001 requirements with practical experience in helping organisations meet them.

CISA

Certified Information Systems Auditor

Certified Information Systems Auditor

CISM

Certified Information Security Manager

Certified Information Security Manager

ISO/IEC 27001 Lead Auditor

Lead Auditor certification

Information Security Management System

ISO/IEC 42001 Lead Auditor

Lead Auditor certification

Artificial Intelligence Management System

Senior expertise

Every project is delivered by a senior expert with over ten years of enterprise experience, a degree in IT or law and multiple professional certifications, across sectors from banking to critical infrastructure.

Continuous professional development

Our experts complete at least 80 hours of internationally accredited training each year through organisations such as ISACA, ISC², SANS and ENISA. A structured CPE programme keeps their qualifications current.

Independent peer review

Every report, action plan and professional deliverable is reviewed and approved by at least two senior experts before release, under our four-eyes and peer review process.

Confidentiality and discretion

Strict confidentiality and discretion are fundamental to every engagement. We uphold our NDA commitments as a professional principle as well as a legal obligation.

Information security and regulatory compliance are essential to keeping your business running. Clients choose us to take the work and complexity of compliance off their hands, giving them more time and confidence to focus on growth.
— Zemitis Advisory · Our approach
Why act now

Compliance is a requirement. The stakes are real.

NIS2 and related standards bring concrete obligations and business risks. Preparation is an investment in resilience.

10million EUR
Maximum fine
Essential entities may face fines of up to €10 million or 2% of annual turnover for non-compliance.
80+
Requirements to address
Risk management, incident handling, supply chain security and access controls: NIS2 requires a comprehensive set of measures.
72hours
Incident reporting deadline
Significant incidents trigger strict statutory reporting deadlines. Without preparation, meeting them can be a challenge.
Client perspectives

What our clients say

★★★★★
The gap analysis was ready in two weeks, and we knew exactly what we needed to do for NIS2. We went into the audit with confidence.
BE
Eszter Bartha
Head of IT · Energy
★★★★★
At last, a partner who takes you all the way to certification. The outsourced security officer service took a real weight off our shoulders.
CM
Márk Csizmadia
Managing Director · Manufacturing
★★★★★
We gained access to senior, CISA-certified expertise without hiring a full-time information security executive. Management finally had a clear picture of our security posture.
FM
Márta Fenyvesi
CFO · Financial services
FAQ

Frequently asked questions

Answers to common questions about our NIS2, ISO 27001 and outsourced security officer services.

NIS2 is the EU’s cybersecurity directive, covering medium-sized and large organisations in critical and other key sectors. Applicability depends on your activities and size; an initial scope assessment will clarify your position.
Fees depend on your organisation’s size and cybersecurity maturity. Indicative NIS2 preparation fees are typically HUF 3–8 million, excluding VAT; ISO 27001 preparation starts at HUF 2.7 million. Use the calculators on our service pages for an instant estimate.
Preparation is a one-off project to establish compliance and support a successful audit. The Information Security Officer (IBF) provides ongoing monthly support to maintain and oversee compliance, from HUF 300,000 per month.
Depending on your starting point, NIS2 preparation typically takes 2–4 months, while ISO 27001 ISMS implementation takes 4–9 months. For urgent deadlines, we develop a prioritised delivery plan.
Our experts hold CISA, CISM, ISO/IEC 27001 Lead Auditor and ISO/IEC 42001 Lead Auditor qualifications. All deliverables undergo internal peer review under the four-eyes principle.
Yes. An ISO/IEC 27001 ISMS provides a strong foundation for NIS2, with substantial overlap in risk management, controls and documentation.
Contact

Let’s talk about compliance.

Call or email us to discuss your next steps in a free consultation. You can also estimate your fee in just a few clicks.

or get an instant estimate