NIS2 · Hungarian transposition: Act LXIX of 2024
NIS2 compliance that passes the audit.
Registration and policies are the easy half. The auditor checks whether the protection measures actually run: logging, access management, backup, segmentation. That is the part I do, from assessment to audit evidence, working alongside your existing consultancy if you have one.
On the first engagement: if your auditor rejects the remediation plan I write, I don't invoice it.
Last updated: 22 August 2026
Where are you now?
The three situations people call from.
01 · Just found out
You are in scope and nobody knows what comes next
Registration with the supervisory authority, appointing an information security officer and classifying your systems into security classes is the first round. Classification is built on a risk analysis, and it decides how many controls you will have to evidence.
What I do here: I assess your actual state, build the technical basis of the classification with you, and put the work in order: what must be built first and what can wait.
02 · Audit approaching
The requirement list exists, the evidence does not
The cybersecurity audit is mandatory every two years, and it doesn't read your policy, it checks operation: is logging running, who can access what, does the backup restore. What has no evidence does not exist in the auditor's eyes.
What I do here: Gap assessment along the control catalogue, at a fixed price, in 2-3 days. Then I build the critical gaps and automate evidence collection so nothing needs scraping together by hand.
03 · Findings landed
The audit is done and there is a list
Findings require a remediation plan, typically within 90 days, with owners, deadlines and risk ratings. In practice this is where things stall: the plan exists, but nobody is there to carry it through technically.
What I do here: I write the plan so your auditor accepts it, then I close it out: from access management to segmentation. The first engagement carries a guarantee, see below.
The law and the machine room
What NIS2 asks for, and what that actually means.
The obligation
Registration with the supervisory authority
What it really means
An administrative step, but from here the authority sees you and the obligations go live. Delaying is the worst strategy: the authority can identify you from public registers on its own.
The obligation
Security classification: basic, significant or high
What it really means
A documented risk analysis, reviewed every two years. Not a formality: it determines the size of the control set you must operate and evidence.
The obligation
Operating the protection measures
What it really means
This is the engineering part: access management with MFA, logging and detection, backup and recovery, network protection, incident response. The list is long, but it can be prioritised, and not everything is needed at once.
The obligation
Cybersecurity audit every two years
What it really means
The auditor asks for evidence: logs, restore test records, access review reports. If the evidence generates itself, the audit is a formality. If you collect it by hand, it is two weeks of work.
The obligation
Incident reporting on deadline
What it really means
The early warning is due within 24 hours, the detailed notification within 72. That only holds if you notice the incident at all: without detection, the reporting obligation fails too.
What I build
Six control areas. Each one closes with evidence.
Access management
SSO and MFA rollout, scheduled access reviews, automatic flagging of dormant and over-privileged accounts. The report generates itself, and the report is the audit evidence.
Logging and detection
Central log collection with retention and tuned alerting. The goal is not to feed everything into a SIEM, it is that whatever alerts actually gets looked at.
Backup and recovery
A 3-2-1-1-0 architecture with an immutable copy, and scheduled, documented restore tests. A backup counts as a backup once it has been restored.
Network segmentation
Zones and controlled transitions, a firewall ruleset people can read, with OT separation in manufacturing. Ransomware in accounting must not be able to reach the production line.
Incident response
A runnable runbook, not a plan written for the shelf: who decides, what gets isolated, how you communicate, and ready-made templates for the 24- and 72-hour reporting deadlines.
Audit evidence, automatically
Scheduled, versioned evidence exports for every control. The two frantic weeks before each audit stop existing.
All of it is built on proven open-source components, so you pay for engineering, not licences. What gets built is yours: configuration, scripts, documentation, handed over in an operable state.
Why me
I don't know this work from a textbook.
I ran the NIS2 programme of a multinational automotive manufacturing site at plant level: cybersecurity strategy, network segmentation on converged OT/IT systems, and security governance across five departments including supplier risk. My day job is security operations at a national telecom provider, which means I operate the controls NIS2 expects, daily and in production.
The detailed case studies are on the home page, with names and roles. The company is new, the work is not, and all of it is verifiable on LinkedIn.
Pricing
You have the number before you commit.
1 · Gap assessment
From €1,200
Fixed price · 2-3 days
A prioritised written report: what is missing, how risky, what the fix is. Enough to decide, with or without me.
2 · Focused build
From €2,500
Fixed price · 2 weeks
One control area taken to a working state: backup with tested recovery, or automated access reviews.
3 · Implementation
From €6,000
Milestone-based
The missing controls built with a defined scope. Every milestone is a documented, working, accepted state.
4 · Controls monitoring
From €700/month
Continuous compliance
The systems stay compliant after I leave: drift detection, scheduled reviews, audit-ready evidence.
My risk, not yours
On the first engagement: if your auditor or the authority doesn't accept the remediation plan I produce, I don't invoice it. I can offer that because the work is technical, and technical work either holds up under inspection or it doesn't.
Frequently asked questions
How much does it cost, and how long does it take?
The gap assessment is from €1,200 at a fixed price and takes 2-3 days, after which you see exactly what is missing and in what order to close it. A focused build of a single control area is from €2,500, also fixed. Full implementation is a milestone-based proposal from roughly €6,000 depending on scope. You get a realistic range on the first call, not after the fact.
How large are the fines?
For essential entities the ceiling is EUR 10 million or 2% of worldwide annual turnover, for important entities EUR 7 million or 1.4%, whichever is higher in each case. In practice supervisory measures and binding orders come before fines, and the directive also establishes management liability. The risk is not theoretical.
We already have a consultancy and a compliance platform. Why another party?
I don't come instead of them, I come after the point where they stop. The platform keeps registers, the consultancy documents, but someone still has to build the logging, the segmentation and the backup architecture. I also work as a subcontractor to consultancies, without touching your client relationship.
Is writing the policies enough?
Until the audit, yes. At the audit, no. The audit examines operation: it asks for an access review report, a restore test record, and it reads the logs. A policy with no working system behind it becomes a finding, not compliance.
We are smaller, but we supply an in-scope enterprise. Does this apply to us?
Directly perhaps not, indirectly yes: NIS2 requires supply chain security, so your in-scope customers will sooner or later ask you for controls and evidence too. Our scope checker tells you where you stand in two minutes.
Do you perform the audit as well?
No, and that is deliberate. The audit is performed by a designated independent auditor. I prepare you to pass it, and because I don't audit, there is no conflict of interest: I never grade my own work.
Let's start
Bring the audit report, the requirement list, or just the suspicion.
30 minutes, free, no obligation. By the end of the call you will know where you stand, what the three most important steps are, and what it would cost with me.
In a manufacturing environment? OT/IT security has its own page. And automating evidence collection is covered here.
