All services 03 · Compliance embedded in daily work

NIS2 Audit Readiness

Find out what the auditor will find — before you pay the auditor.

  • 10–12 weeks
  • ~24–28 consulting days
  • From 750,000 HUF + VAT
  • Independent of the audit

The problem

The findings are in a drawer and the managing director’s name is on the registration.

The audit produced a list, and nobody in the company knows how to turn a list into work. Or the policies were bought last year, written for the auditor, and the organisation does not recognise itself in them. Or you are newly in scope — through your sector, your size, or a larger customer’s supply chain — and the first audit is somewhere in the next two years.

Meanwhile the MSP says security is your responsibility and you thought it was theirs, and nobody has written down which of you owns what. Under the Hungarian act the managing director is personally accountable, SZTFH can fine, order measures and publish, and unremediated findings compound into the next audit.

Paper compliance costs the same as real compliance and protects nobody.


Who it's for
This is a fit if
  • You are registered with SZTFH and facing your next periodic audit or an inspection
  • You hold findings from your first audit that nobody has turned into work
  • You are newly in scope and the first audit is due within two years of registration
  • You are not sure whether you are in scope at all, and customers or tenders have started asking
  • Or you passed on paper and know the controls are not really running
  • One legal entity, up to 150 employees, one classification level
Who buys it
  • The managing director — the act makes them personally accountable — often with the CFO
  • The designated cybersecurity officer or IT lead is the working counterpart
  • Entities with a single system at the basic classification level are steered to Entry: for them the statutory audit is inexpensive and a full programme is rarely proportionate
  • Groups, OT and industrial environments, and the highest classification level are quoted individually

What happens

Six steps, ten to twelve weeks.

  1. Intake One week. Sponsor kick-off onsite, registration and classification documents collected, any existing audit report read, contact established with the MSP.
  2. Readiness assessment One to two weeks. Your position against the safeguards required for your classification level — assessed against the same requirements and procedure the registered auditor will use, so nothing in the audit is a surprise. Ends with an explicit enter-audit verdict.
  3. Scope Statement One week. The entity, the classification, the findings in scope, the processes controls will be embedded into, and the MSP boundary. From here scope changes only by written change order.
  4. Risk framework and policies Three weeks. The risk register the act requires, built as a working register rather than a document, and the policy set written in your vocabulary — with the MSP responsibility matrix agreed rather than assumed.
  5. Control embedding Three to four weeks. Controls written into your existing process descriptions as steps, with an owner and an evidence point each, and the first evidence actually collected.
  6. Management review and hand-over One week. The review held and minuted, the evidence pack indexed to the act’s requirements, and the remediation status reported finding by finding.

Premium adds implementation support alongside your IT or MSP, a staff awareness session, a dry-run against the SZTFH audit procedure, help selecting and contracting a registered auditor, and our presence beside you through the audit or inspection itself.


What you get

Six documents, and evidence behind each one.

Readiness Assessment Report

Whether and how you are in scope, your registration and classification status, every required safeguard rated, the finding profile to expect — and an explicit verdict on whether you are ready to enter the audit.

Scope Statement

Entity, classification, findings in scope, processes, MSP boundary, deliverables and dates against your audit calendar. The scope baseline.

Risk Register & Framework

The method the act requires — scales, roles, review cycle — and the working register: assets, threats, current controls, residual risk, treatment, owner. Approved at a minuted management review, not filed.

Policy Set

Information security, incident management, access and identity, change, backup and continuity, supplier security, onboarding and offboarding, awareness — written in your words and mapped to the processes that actually execute them.

Embedded Process Descriptions & Responsibility Matrix

Each control as a step in a process, with an owner and a defined evidence point — and every control allocated between you and your MSP, countersigned by them.

Evidence Pack Index & Remediation Status

Each requirement mapped to a control, an owner, an evidence type and where it lives, with first evidence collected — and every finding shown as closed-with-evidence or open-with-owner-and-date.


Packages
  • Entry — readiness assessment Applicability and classification checked, findings triaged or a gap check run, and a verdict on whether you would pass. If you turn out to be out of scope, it says so and you stop there. 750,000 HUF + VAT.
  • Standard — remediation to readiness Everything on this page: risk framework, policies, controls embedded in your processes, MSP boundary signed, evidence pack, management review. 3,900,000 HUF + VAT, fixed price.
  • Premium — through the audit Standard plus implementation support with your IT or MSP, an awareness session, a pre-audit dry-run, auditor selection, and our presence beside you at the audit or inspection. Quoted individually.
  • Custom Groups, OT and industrial environments, the highest classification level. Quoted individually.

The statutory audit fee is paid by you to the registered auditor and is capped by decree — the formula starts from a net 1,750,000 HUF base and scales with revenue, systems and classification, so published examples range from roughly 1.6 million to tens of millions. The readiness assessment is always cheaper than the audit; remediation is cheaper than the audit for anyone with more than a system or two.


What we need from you
  • The managing director or a delegate as sponsor, and the designated cybersecurity officer as counterpart
  • Registration, classification and any audit documentation — in writing
  • Your MSP contractually required to cooperate and to provide evidence
  • Risk-treatment and policy decisions within five business days
  • Requested information within five business days; delays move milestones, they do not shrink the work
What this is not
  • Not the statutory audit — that must be performed by an auditor organisation registered with SZTFH. Interpunct is not one, and will not become one: that is precisely what makes the readiness verdict independent
  • Not legal representation before the authority
  • Not security tooling procurement
  • Not hands-on technical implementation — Premium coordinates it; your IT or MSP executes
  • Not ISO 27001 certification — that is the separate certification readiness service

Next step

Ask the cheaper question first.

Before you pay a registered auditor to tell you what is missing, find out from someone on your side of the table. Two weeks, one report, and an honest answer about whether you would pass.