Védelmi intézkedések a biztonsági osztályok szerint
NIS2 says what you must achieve, never how you demonstrate it. Hungary answers with HU protective measures. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Hungary is the strictest regime in this hub on evidence: a cybersecurity audit every two years, performed by an auditor on the SZTFH register, is mandatory — not a certification you may choose. Budget for it and check your classification early, because the class decides the measures.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 helps build the management system but does not replace the statutory audit, which is against the decree and no other document.
2 routes, chosen by scope and depth
The lighter set of protective measures. The class is assigned, not chosen.
Entities classified in the basic security class
The fuller set. Classification follows from the systems you operate.
Entities classified in the significant security class
What it is built on
HU protective measures does not invent its own taxonomy. It sits on Kiberbiztonsági törvény (Act XXIII of 2023).
Appendix 2 of the decree sets out nineteen categories of protective measure — programme management, access control, awareness and training, logging, supply chain risk management among them — required according to security class.
Why there is no unit-level mapping
Nineteen categories are confirmed as the structure of Appendix 2, together with several of their names. The full list has not been transcribed from the decree.
Not recorded yet at category level. The category names reported so far — programme management, access control, awareness and training, logging, supply chain risk management — read like the NIST SP 800-53 family set, and nineteen is a suggestive count. We are not publishing that as a mapping: an equivalence inferred from five names out of nineteen would be a guess wearing a citation.
No stable public identifiers to map against
This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.
What you already have, for the same measure
Nobody in scope starts from nothing. HU protective measures is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) Risk analysis | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | 8.24 | SC |
| (i) HR, access, assets | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
- https://tmkik.hu/nis2-szabalyozasahoz-kapcsolodo-rendeletek/
- https://kpmg.com/hu/hu/szolgaltatasok/advisory/technology/cybersecurity/nis-2.html
We are not affiliated with Miniszterelnöki Kabinetiroda, with SZTFH as auditor registrar. HU protective measures and related marks belong to their owners.