Independent assessment. Transparent compliance. More secure operations.

During OnA’s cybersecurity audit, we assess whether your organization’s IT systems, security measures, and operational processes comply with the Hungarian legal requirements related to the NIS2 Directive.
Our objective is to ensure that the audit results are clear and useful for both management and IT professionals. The audit provides a transparent overview of the organization’s compliance status, identified gaps, and the areas requiring further attention.
More than an IT review
Cybersecurity is not solely a technological issue. Internal policies, clearly defined responsibilities, and employee preparedness remain essential even when IT services are provided by an external service provider. Therefore, the audit covers not only technical safeguards but also the organization’s operational and governance processes.
We assess not only what is documented, but also how security measures operate in practice.
Which organizations is it relevant for?
Hungarian legislation related to NIS2 applies, among others, to certain organizations operating in the energy, transport, healthcare, water supply and wastewater management, food, chemical, waste management, manufacturing, IT, and digital services sectors.
Whether an organization is subject to the audit requirement must be determined based on its specific activities, size, and other criteria defined by applicable legislation. Sector classification alone is not sufficient in every case.
What do we assess during the audit?
The audit is tailored to the applicable requirements and to the security classification of the electronic information systems. The main areas include:
- Governance and risk management: we assess internal policies, responsibilities, risk management processes, system classifications, and cybersecurity awareness.
- Technical and physical protection: we review access management, system security controls, logging, vulnerability management, and physical access protection.
- Business continuity and external relationships: we assess incident management, backup and recovery procedures, as well as security measures related to suppliers and external service providers.