Home / Services / IT Governance
IT governance and compliance
Governed, documented, audit-ready IT.
We help make sure your IT doesn’t just work, but also complies with NIS2, ISO 27001 and GDPR, and evolves along a well-thought-out IT strategy.
At a glance
- NIS2 readinessunder Hungary’s Cybersecurity Act
- ISO/IEC 27001information security management system
- GDPRtechnical and organisational measures
- vCIOIT leadership as a service
What we do
From policies to implementation, from one partner.
Most consultants stop at the paperwork. With us, the same team that writes the policies also implements the technical measures, so what’s on paper matches reality.
NIS2 and cybersecurity compliance
We assess whether you’re in scope, classify your systems, carry out a gap analysis, draw up an action plan and prepare your company for the mandatory cybersecurity audit.
- Scope assessment
- Security classification
- Audit preparation
Risk assessment and policies
Risk assessment and the policies you need, tailored to how your company actually works, with no boilerplate.
- IT security policy
- Access, backup and device policies
- Business continuity plan (BCP/DRP)
ISO/IEC 27001
Support in building an information security management system (ISMS) according to the 2022 version of the standard, and preparation for the certification audit.
- Building the ISMS
- Implementing controls
- Certification readiness
GDPR and data protection
The IT side of data protection compliance: access control, logging, encryption and a process for handling personal data breaches.
- Technical and organisational measures
- Access management and logging
- Incident handling process
IT strategy and vCIO
A virtual CIO who represents IT at management level without a full-time hire: budget, roadmap, vendors and reporting.
- IT budget and development roadmap
- Vendor and contract management
- Decision support for management
Continuous compliance
Compliance isn’t a one-off project. We regularly review measures and documentation and prepare you for the next audit.
- Regular internal reviews
- Keeping documentation up to date
- Supplier security requirements
NIS2 in brief
Cybersecurity is now a legal obligation.
The law
In Hungary, the NIS2 Directive is transposed by Act LXIX of 2024 on the Cybersecurity of Hungary. Companies are supervised by the Supervisory Authority for Regulated Activities (SZTFH).
Who is in scope?
Medium-sized and large companies in specific sectors, such as energy, transport, healthcare, digital infrastructure and certain areas of manufacturing, including motor vehicle manufacturing.
Audit
Organisations in scope must undergo a cybersecurity audit. For organisations operating before 2025, the first audit deadline was 30 June 2026, and compliance must be maintained on an ongoing basis.
As a supplier
Companies covered by NIS2 expect security measures from their suppliers too, so smaller companies can be affected indirectly.
Technologies
What we work with.
Legislation
- NIS2 Directive
- Act LXIX of 2024 (Hungary)
- GDPR
Standards
- ISO/IEC 27001:2022
- ISO/IEC 27002
Documents
- IT security policy
- Risk assessment
- BCP/DRP
- Action plan
Process
How we get you to compliance.
Current state
Scope, existing systems, policies and practices.
Gap analysis
Risk assessment and comparison against the requirements.
Action plan
Priorities, owners, deadlines and costs.
Implementation
Policies, plus technical measures delivered by our own team.
Audit and follow-up
Audit preparation, then regular reviews.
FAQ
Questions our clients often ask.
Is our company in scope for NIS2?
It depends on your sector and company size. We start with a scope assessment. Even if you’re not directly in scope, you may receive security requirements from your clients as a supplier.
What’s the difference between NIS2 and ISO 27001?
NIS2 is a legal obligation for organisations in scope, while ISO 27001 is a voluntary international standard. Many requirements overlap, so a well-built ISMS is a strong foundation for NIS2 compliance.
Do you carry out the cybersecurity audit?
No. The mandatory audit is performed by an independent auditor registered with SZTFH. We help with preparation and with closing any gaps.
What is a vCIO?
A virtual CIO: an experienced professional who handles IT leadership tasks within an agreed time budget, without a full-time hire.
Related services
Firewalls, remote access, LAN/WAN
Microsoft 365, Entra ID, Intune, Azure
Windows Server, Hyper-V, VMware, Linux
Contact
Let’s talk about your IT.
Call us, or send us a short note about how many employees and which systems need support. We’ll assess your current setup and prepare a tailored proposal.
- Phone
- +36 1 353 9430
- info@tredit.hu
- Registered office
- 2340 Kiskunlacháza, Dobó István utca 23.Tax number: 24076735-2-13
- Support
- Support portalFor contracted clients