NIS2 Audit Regulation Published

[Forrás: Gróf József]
Although the implementation the NIS2 EU directive started well in Hungary, progress has significantly slowed over the past six months. A crucial regulation regarding mandatory audits was recently published, but instead of reassuring the professional community, it has raised further concerns. The key question remains: will the deadlines set in stone in the cybersecurity law be achievable?

 

◼︎ A shortage of Professionals and Time

On January 31, there was finally a significant development regarding NIS2: the Supervisory Authority for Regulated Activities (SZTFH) issued its long-awaited regulation detailing the procedure for conducting cybersecurity audits and setting the maximum audit fees. This regulation is crucial because compliance with NIS2 security requirements must be verified by external, independent auditors registered with the SZTFH. The newly published regulation defines the audit process and its associated costs.

Pricing Structure and Fees

The regulation spans over a hundred pages and outlines the methodology and required control points for assessing electronic information systems (EIRs). As for pricing, the base fee (excluding VAT) is HUF 1,750,000, which is adjusted using multipliers ranging from 0.9 to 5 based on the organization’s revenue, the security classification, and the number of EIRs subject to the audit. (See the table below for revenue-based multipliers.)

The cybersecurity audit fee multiplier based on the organization’s revenue (Base fee: HUF 1,750,000)

Net Revenue of the Organization (Previous Fiscal Year) Multiplier
Below HUF 1 billion 0.9
Between HUF 1-5 billion 1
Between HUF 5-10 billion 1.9
Between HUF 10-15 billion 2.5
Between HUF 15-25 billion 2.75
Between HUF 25-40 billion 3
Above HUF 40 billion 4

Source: Magyar Közlöny

According to the regulation, if an organization has at least one system classified as belonging to the „significant” or „high” security category, the entire audit fee must be calculated using the highest applicable multiplier. In the highest category (i.e., revenue above HUF 40 billion, more than 16 EIRs, with at least one classified as high security), the audit cost is HUF 1,750,000 × 4 × 4 × 5, totaling precisely HUF 140 million. Meanwhile, the smallest companies must allocate at least HUF 1.5 million for the NIS2 cybersecurity audit.

Cybersecurity experts we consulted—including some working at registered auditing firms—welcome the regulation, even though it was issued with considerable delay. According to the original schedule in the now-repealed Cybersecurity Certification Act (Kibertantv), affected companies should have already contracted an auditor by December 31, 2024, so that the first audits could be conducted by December 31, 2025. However, on December 27, a brief statement appeared on the SZTFH’s website, indicating that negotiations with the Hungarian Chamber of Commerce and Industry (MKIK) regarding the maximum audit fee were still ongoing, and the final regulation would only be published in 2025.

This delay has prevented affected organizations from contracting auditors for their audits, and auditors themselves were also left in limbo, unable to initiate preliminary discussions with potential clients due to the lack of established fees. Furthermore, the SZTFH did not include auditors in the consultations.

Too High or Too Low?

Given these circumstances, one might expect that auditors would unanimously welcome the regulation with relief. However, this is far from the case—many concerns have been raised regarding both the pricing and the audit methodology.

One of the MKIK’s primary goals during negotiations was to ensure that the audit fees would not place an excessive burden on smaller businesses. This led to the introduction of a tiered fee structure based on revenue. Our sources acknowledge that this approach is fair and reasonable, considering that many small internet and telecommunications service providers with annual revenues in the tens of millions of forints fall under the NIS2 directive. It would have been unfair if these companies were forced to pay HUF 5-10 million for an audit.

However, auditors see another side to the issue. For them, the lower limit of HUF 1.5 million is quite low given the extensive workload required. The auditing methodology is the same regardless of company size, and it is highly complex. This means that auditors will need to invest significant effort and consulting hours, which the current pricing does not adequately cover. Moreover, auditing multiple systems—especially those in the higher security categories—demands even more resources.

On the other hand, auditing organizations operating „significant” or „high” security EIRs may still be financially viable, even though higher-tier audits involve additional verification procedures such as penetration testing. However, only two firms (Certop and Kürt) are authorized to audit systems in the „significant” category, while only one (Hunguard) can audit „high” security systems.

Documentation and Indexes

Concerns about the audit methodology go beyond just pricing. Experts generally support the principle of conducting thorough security policy and control reviews. However, given the limited availability of professionals, time, and financial resources, performing comprehensive audits as required by the regulation may be unrealistic.

The first step in an audit is reviewing an organization’s information security documentation. The regulation provides a comprehensive list of documents that auditors must request, including EIR inventories and procurement-related records. These must then be assessed against the 7/2024 MK regulation to determine compliance.

Following document reviews, auditors conduct in-person interviews to evaluate the company’s preparedness. This includes verifying whether EIRs are properly defined, whether unjustified consolidations have occurred, and whether security classifications are appropriately assigned. The results of these assessments contribute to the VMI Index, which measures an organization’s compliance level. If the VMI Index falls below 70%, the company fails the audit.

15 83006760

A Tight Deadline

These challenges cast doubt on whether the December 31 deadline can realistically be met. Currently, only ten auditing firms are responsible for auditing thousands of organizations within just 11 months. Many of these organizations are among the largest Hungarian corporations, each operating dozens of EIRs that must be audited thoroughly. Given that even a single audit can take several weeks, and the industry is already struggling with a cybersecurity workforce shortage, experts warn that the math simply does not add up—there are not enough trained professionals to complete all necessary audits in time.

Key Milestones
  • January 16, 2023: The EU formally adopts the NIS2 directive.
  • May 23, 2023: Hungary’s Parliament adopts the Cybersecurity Certification Act (Kibertantv).
  • January 1, 2024: SZTFH begins registering affected entities.
  • June 24, 2024: Regulations on auditor requirements and security classifications are published.
  • October 17, 2024: NIS2 takes effect across the EU.
  • December 31, 2024: Original deadline for contracting auditors.
  • January 31, 2025: SZTFH publishes audit methodology and pricing regulation.
  • December 31, 2025: Deadline for completing the first cybersecurity audits.
The Temptation of Shortcuts

These difficulties may lead organizations and auditors to take shortcuts, undermining NIS2’s original intent. Instead of truly strengthening cybersecurity practices, companies may focus on achieving only paper compliance—mirroring past experiences with GDPR.

Likewise, audit firms may allocate only the minimum resources necessary to make their work financially viable, leading to rushed and superficial assessments. However, many professionals remain committed to the goal of enhancing cybersecurity resilience. Auditors also bear legal responsibility for their assessments, meaning that if security gaps emerge later (e.g., in the event of an attack), it could have serious consequences for their reputation and credibility.

A Way Forward?

Experts advise affected companies to prepare thoroughly. Organizations that proactively align their systems with the NIST 800-53 standard will undergo smoother audits. Meanwhile, auditors should explore automation and artificial intelligence tools to accelerate compliance assessments. Regardless of the approach taken, the coming months will be a learning curve for both organizations and auditors alike.

További tartalmak

Legolvasottabb tartalmak

Strategy

Valós idejű adózás

Human

Az egészség hálózatai

Technology

Egy év, amely átírta az emberiség és a mesterséges intelligencia viszonyát

Strategy

Exportcikk lehet a DÁP-ból

ITBUSINESS heti hírlevél feliratkozás

.
Scroll to Top