The Process and Risks of Introducing NIS2 in Hungary

doi: 10.32567/hm.2024.3.10


The number and complexity of incidents and attacks in cyberspace increased significantly after the turn of the millennium and caused significant damage not only to the private sector, but also to governments. These events made it clear that it is necessary to create a comprehensive cyber security regulation in the EU. In 2016, the Union adopted its first EU-level cybersecurity legislation, the Network and Information Security (NIS) Directive, which was a fundamental step towards the common information security of EU-level network and information systems. During the implementation, the stakeholders faced several challenges both at the EU and national level, and due to the rapid development of cyber threats and the rapid spread of new technologies, the directive - due to its nature - was unable to keep up with the continuous changes.
The emerging challenges and the constantly changing digital environment forced a review of the EU framework. As a result, NIS2 was born. The updated directive represents a comprehensive strategy in the field of EU cyber security, its declared aim is to strengthen enforcement mechanisms, the basic legal pillar of the field. At the same time, it significantly expanded the subject and material scope of its predecessor, the NIS, in order to strengthen the resilience of critical infrastructures and services.

The purpose of this study is to investigate whether the conditions are available for the compliance of domestic enterprises and organizations covered by the directive, and what is necessary for the relevant organizations to be able to meet the expectations of NIS2


NIS2 cybersecurity risk skills awareness

How to Cite

Kis, M., Bódi, A., & Számadó, R. (2025). The Process and Risks of Introducing NIS2 in Hungary . Military Engineer, 19(3), 165–182.


évi XXIII. törvény - a kiberbiztonsági tanúsításról és a kiberbiztonsági felügyeletről

/2023. (V. 15.) SZTFH rendelet - az információs és kommunikációs technológiák kiberbiztonsági tanúsításáról

BOR Olivér – BENCSIK Balázs (2024): Ki és hogyan készüljön fel a NIS2-re? SZTFH konferencia. Online:

BYTTEBIER, Pieter (2022): NIS-2: Where are you? Centre for Cybersecurity Belgium, 2022. április 30. Online:

ENISA (2024): Foresight Cybersecurity Threats For 2030. Executive Summary. Online:

Európai Bizottság (2023a): NIS2 Directive. Online:

Európai Bizottság (2023b): NIS2 FAQS. Online:

MEGYERI Lajos – FARKAS Tibor (2017): Kockázatkezelés, tudomány vagy kuruzslás. Hadmérnök, 12(3), 198–209. Online:

MIKE Nimród – KRÉN Enikő – KECSKEMÉTI Tamás (2023): Farkasbiztos téglaház? A KKV-k információbiztonsága Magyarországon. Vezetéstudomány, 54(9), 44–57. Online:

SCHMITZ-BERNDT, Sandra – COLE, Mark (2023): Towards an Efficient and Coherent Regulatory Framework on Cybersecurity in the EU: The Proposals for a NIS 2.0 Directive and a Cyber Resilience Act. Applied Cybersecurity & Internet Governance, 1(1), 1–17. Online:

VANDEZANDE, Niels (2024): Cybersecurity in the EU: How the NIS2-directive Stacks up Against Its Predecessor. Computer Law & Security Review. Online:

World Economic Forum (2024): Global Risks Report 2024. 19th Edition: Online:

ZÁGON Csaba – GECSEI Márton (2021): Kockázatelemzés a gyakorlatban: cigaretta a repülőtéren. In Tradíció, tudomány, minőség. 30 éves a Vám- és Pénzügyőri Tanszék. Tanulmánykötet. Budapest: Magyar Rendészettudományi Társaság Vám- és Pénzügyőri Tagozata, 129–142. Online: DOI: