NIS2 must be implemented through the applicable Hungarian cybersecurity rules. Organisations in scope need to demonstrate compliance with documented evidence. This article explains applicability, the main requirements and deadlines, and a practical sequence for keeping preparation under control.
Who is covered by NIS2?
NIS2 covers medium-sized and large organisations in sectors of high criticality and other critical sectors. Classification depends on both activity and size, including headcount and financial measures. Sectors include:
- energy, transport, banking and financial market infrastructure;
- healthcare, drinking water and wastewater;
- digital infrastructure and ICT service management;
- public administration and space;
- manufacturing, food, chemicals, waste management and postal services.
Some entities are covered regardless of size. Financial organisations must assess DORA separately. Customers may impose security requirements on suppliers contractually, but a supplier relationship alone does not automatically establish statutory scope. See our appointment and scope guide.
What happened to the first audit deadline?
According to SZTFH’s guidance, the first audit deadline for affected organisations operating before 1 January 2025 was 30 June 2026. Newly covered organisations follow deadlines linked to registration. Where a deadline has passed, remediation and next steps must be planned around the organisation’s actual regulatory status.
What are the main NIS2 requirements?
NIS2 calls for a comprehensive, proportionate set of measures. The practical foundations are:
A risk management framework
Identify, assess and treat risks using a documented method and regular reviews. This is the backbone of compliance.
Incident management and reporting
Establish a working response process and report significant incidents within statutory deadlines.
Supply chain security
Manage supplier and service provider risks through due diligence and contractual security requirements.
Business continuity
Maintain BCP/DRP arrangements, backups and recovery capabilities, supported by regular testing. Written plans need to work in practice.
Access control and cyber hygiene
Manage access rights, multifactor authentication, encryption, logging, basic cyber hygiene and recurring staff awareness.
Management accountability
Senior management is personally accountable and must approve and oversee risk management measures.
What are the incident reporting deadlines?
Reporting significant incidents follows a staged process:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours | Initial indication and basic information |
| Incident notification | 72 hours | More detailed assessment and impact |
| Final report | One month | Full analysis and response measures |
The 24-hour and 72-hour periods run from awareness of a significant incident. The month for the final report runs from the incident notification. Our reporting guide covers exceptions and incidents still in progress.
Without established owners and procedures, 24 hours leaves very little time to organise a response.
What is at stake if we do not comply?
Failures may lead to regulatory action and fines. The specific consequences depend on the organisation’s classification, the infringement and applicable Hungarian rules. Management oversight and traceable actions are essential to compliance.
In what order should we proceed?
A well-structured project reduces risk while keeping costs predictable:
- Establish applicability and scope: define exactly what is covered.
- Perform a gap analysis: compare current controls with requirements.
- Prioritise actions: tackle the highest-risk gaps first.
- Implement and document controls: policies, processes and technology.
- Complete internal review and management approval: demonstrate readiness.
- Maintain compliance: regular reviews, training and incident preparedness.
Build the delivery schedule around actual gaps and available resources. A project plan does not extend a statutory deadline.
Common mistakes to avoid
- Scope that is too broad or narrow: it can add unnecessary cost or leave risks uncovered.
- Compliance on paper: policies that do not reflect actual practice.
- Untested recovery plans: BCP/DRP arrangements need exercises to prove they work.
- Absent management involvement: NIS2 explicitly requires leadership accountability.
How zemITis helps
Our CISA- and CISM-qualified experts guide you from gap analysis through regulatory assessment, with independent peer review of deliverables. Get an estimate on our NIS2 service page, then discuss the next steps in a free consultation.