Skip to content
profix::sec
HU

Free self-check

Does NIS2 apply to you?

Four questions and you see instantly whether you fall under NIS2, as an essential or important entity, what the statutory fine ceiling is, and what the next three steps are. The sector lists and size thresholds come from the EU directive itself; the registration and deadline specifics follow the Hungarian transposition. You don't enter anything about yourself.

Which sector does your activity fall into?

Actual activity is what counts, not necessarily your registered main activity code.

How many people do you employ?

What is your annual turnover?

Are you established in Hungary, or providing services there?

This decides whether the Hungarian authority and deadlines apply. Elsewhere in the EU, your member state's transposition applies.

Have you registered with the SZTFH yet?

Have you had a cybersecurity audit?

Result

Answer the first four questions and the assessment appears here instantly. You don't enter anything about yourself, and nothing is sent anywhere.

An indicative self-check based on the NIS2 annexes and Hungary's transposition (Act LXIX of 2024). Not legal advice, and no substitute for the authority's classification. The final determination always turns on the organisation's actual activities.

How scope is decided

Two things matter: sector and size.

NIS2 does not apply by company size in general, it applies by sector. The directive's annexes list the covered activities in two groups: sectors of high criticality (energy, transport, health, drinking water, digital infrastructure, public administration and others) and other critical sectors (manufacturing, food, chemicals, waste, postal services, research, digital providers).

If your activity is on one of the lists, size decides the category. As a main rule it applies from medium-sized enterprises upwards: over 50 employees, or annual turnover above EUR 10 million. High-criticality sector at large size means an essential entity; every other in-scope case is an important entity.

Some entity types are in scope regardless of size, for example trust service providers, DNS and TLD registries, certain telecom providers and public administration. So size alone never rules scope out.

The actual protection requirements are then set by security classification (basic, significant or high in the Hungarian system), which the organisation must perform itself based on risk analysis and review every two years.

Frequently asked questions

When do we have to comply?

Hungary's cybersecurity act has been in force since 1 January 2025. In-scope organisations must register with the supervisory authority (SZTFH), appoint an information security officer, and classify their information systems into security classes. The cybersecurity audit is then mandatory every two years. Elsewhere in the EU, your member state's transposition sets the dates.

What is the difference between an essential and an important entity?

The requirements are substantially the same. The difference is supervision and the fine ceiling: essential entities can be supervised proactively and carry the higher ceiling, while important entities are typically supervised after the fact.

What happens if the audit report contains findings?

A remediation plan must be submitted, typically within 90 days, with risk ratings, owners, deadlines and evidence expectations. In practice this is where the process stalls: the finding exists, but nobody is there to fix it technically.

We are a smaller company, but we supply an in-scope organisation.

Then the requirements reach you through the supply chain: NIS2 obliges in-scope organisations to manage supplier risk, so your customers will pass controls and evidence requirements down by contract. ISO 27001 is usually a good answer to those.

If the findings are already on the table and the question is who fixes them: that is what I do, with an OT/IT focus in manufacturing.