Directive NIS2 European Union
7/2024. (VI. 24.) MK rendelet, 2. melléklet · in force since 25 June 2024

Védelmi intézkedések a biztonsági osztályok szerint

NIS2 says what you must achieve, never how you demonstrate it. Hungary answers with HU protective measures. If you operate there, this is what your regulator reads.

Published
Implementation routes
2
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Hungary is the strictest regime in this hub on evidence: a cybersecurity audit every two years, performed by an auditor on the SZTFH register, is mandatory — not a certification you may choose. Budget for it and check your classification early, because the class decides the measures.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 helps build the management system but does not replace the statutory audit, which is against the decree and no other document.

Implementation routes

2 routes, chosen by scope and depth


Alap biztonsági osztály

The lighter set of protective measures. The class is assigned, not chosen.

Entities classified in the basic security class

Jelentős biztonsági osztály

The fuller set. Classification follows from the systems you operate.

Entities classified in the significant security class

What it is built on

HU protective measures does not invent its own taxonomy. It sits on Kiberbiztonsági törvény (Act XXIII of 2023).

Appendix 2 of the decree sets out nineteen categories of protective measure — programme management, access control, awareness and training, logging, supply chain risk management among them — required according to security class.

Mapping

Why there is no unit-level mapping


Basis

Nineteen categories are confirmed as the structure of Appendix 2, together with several of their names. The full list has not been transcribed from the decree.

Limit of this mapping

Not recorded yet at category level. The category names reported so far — programme management, access control, awareness and training, logging, supply chain risk management — read like the NIST SP 800-53 family set, and nineteen is a suggestive count. We are not publishing that as a mapping: an equivalence inferred from five names out of nineteen would be a guess wearing a citation.

No stable public identifiers to map against

This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.

The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. HU protective measures is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to HU protective measures and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training 5.37 6.3 8.7 AT SI CM
(h) Cryptography 8.24 SC
(i) HR, access, assets 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Sources

We are not affiliated with Miniszterelnöki Kabinetiroda, with SZTFH as auditor registrar. HU protective measures and related marks belong to their owners.

Cart 0