NIS2 Compliance in Europe: How Liferay Hungary Strengthens Cybersecurity and Operational Resilience
Learn how Liferay Hungary achieved NIS2 compliance and what it means for cybersecurity, operational resilience, and supply chain security across Europe.
The NIS2 Directive (EU 2022/2555) is a mandatory European Union cybersecurity framework that requires organisations in essential and important sectors to implement risk management, incident response, supply chain security, and business continuity measures.
Enforcement began in 2024, with member states implementing national regulations and supervisory authorities – including Hungary's SZTFH – overseeing compliance.
Liferay Hungary Kft has proactively completed its NIS2 audit, validating that its security controls align with the directive's stringent requirements and supporting its customers' compliance obligations.
What Is the NIS2 Directive?
The NIS2 Directive (EU 2022/2555) represents the European Union’s most comprehensive framework for cybersecurity compliance. It establishes strict requirements for organisations operating in essential and important sectors, ensuring they can withstand, respond to, and recover from cyber threats.
In Hungary, compliance is overseen by the Supervisory Authority for Regulated Activities (SZTFH), which enforces adherence to national implementations of the directive.
Unlike previous frameworks, NIS2 compliance is a mandatory operational standard, not a voluntary certification. Organisations must demonstrate strong governance, risk management, and incident response capabilities.
When Is the NIS2 Compliance Deadline?
The NIS2 Directive (EU 2022/2555) entered into force in January 2023, with EU member states required to transpose it into national law by October 17, 2024.
From this point onward:
-
National authorities can begin enforcement
-
Organisations classified as “essential” or “important” must comply
Because each country implements NIS2 individually, enforcement timelines may vary slightly, but organisations should already be actively working toward compliance.
Which Industries Are Covered by NIS2?
NIS2 significantly expands the scope of the original directive and applies to organisations in essential and important sectors.
Essential sectors include:
-
Banking and financial services
-
Digital infrastructure
Important sectors include:
-
Digital providers
-
Postal and courier services
-
Waste management
Applicability depends on company size, role in the economy, and national classification rules.
What Are the Key Requirements of NIS2?
Organisations must implement:
-
Risk management frameworks
-
Incident detection and reporting processes
-
Supply chain security controls
-
Business continuity and disaster recovery
-
Governance and executive accountability
These measures must be proportionate but demonstrable, meaning organisations must prove compliance during audits.
What Are the Penalties for Non-Compliance?
NIS2 introduces strict enforcement measures across the EU.
Penalties may include:
-
Significant financial fines (based on company size and severity)
-
Binding instructions from regulators
-
Temporary suspension of operations in extreme cases
-
Personal liability for management bodies
Exact penalties vary by country but are designed to ensure cybersecurity is treated as a board-level responsibility.
What Is the NIS2 Implementation Timeline?
The NIS2 timeline can be broken down into key phases:
-
2023: Directive enters into force
-
2024: National transposition deadline (October)
-
2024–2025: Organisations assessed and classified
-
Ongoing: Continuous compliance, audits, and enforcement
This reinforces that NIS2 is not a one-time effort but an ongoing operational requirement.
How Much Does NIS2 Compliance Cost?
The cost of NIS2 compliance depends on:
-
Organisation size and complexity
-
Existing cybersecurity maturity
-
Industry-specific requirements
Typical investment areas include:
-
Security tools and infrastructure
-
Governance and compliance processes
-
Staff training and awareness
-
External audits and consulting
For many organisations, NIS2 is less about new costs and more about formalising and strengthening existing security practices.
Sources:
-
EUR-Lex – Full legal text of NIS2 (EU 2022/2555) https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:32022L2555
-
European Commission: https://digital-strategy.ec.europa.eu/en/policies/nis2-directive

Liferay Hungary Achieves NIS2 Compliance
Liferay Hungary Kft has proactively completed the NIS2 audit, validating that its internal processes align with the stringent requirements of the directive and Hungarian legal framework.
This achievement highlights Liferay’s ongoing investment in cybersecurity compliance in Europe and its role in supporting secure digital transformation for its customers.
Key Pillars of NIS2 Audit Success
The audit confirmed that Liferay Hungary Kft maintains effective controls across several critical domains:
Governance & Risk Management
A structured approach to overseeing systems, data handling policies, and organisational risk ensures alignment with NIS2 requirements.
Incident Management
Clearly defined procedures enable rapid detection, reporting, and mitigation of cybersecurity incidents – minimising disruption and downtime.
Supply Chain Security
Liferay Hungary applies rigorous assessment standards to vendors and partners, ensuring end-to-end security across the service lifecycle.
Business Continuity
Proven strategies are in place to maintain essential operations during and after security incidents, strengthening overall operational resilience.
What NIS2 Compliance Means for Liferay Partners
Liferay Hungary Kft plays a critical role in maintaining the cybersecurity posture of the broader Liferay organisation. Its compliance delivers tangible benefits to partners and clients:
Simplified Due Diligence
Organisations working with Liferay benefit from reduced compliance complexity. The NIS2 audit confirms that a critical vendor within their supply chain already meets stringent cybersecurity requirements.
Alignment with European Standards
This achievement complements Liferay’s commitment to the Esquema Nacional de Seguridad (ENS), creating a unified approach to European cybersecurity compliance frameworks.
Stronger Operational Resilience
The successful audit demonstrates that Liferay has implemented the technical and organisational measures necessary to protect service integrity and ensure continuity.
Why NIS2 Compliance Matters Now
With cyber threats increasing in scale and sophistication, regulatory frameworks like NIS2 are reshaping how organisations approach security.
Businesses that prioritise NIS2 compliance are better positioned to:
-
Mitigate risk
-
Ensure business continuity
-
Strengthen customer trust
-
Meet evolving regulatory demands across Europe
NIS2 Compliance Checklist
To align with NIS2 requirements, organisations should ensure they have the following measures in place:
-
A defined risk management framework
-
Incident detection and reporting processes, including escalation procedures
-
Supply chain security controls and vendor risk assessments
-
Business continuity and disaster recovery plans
-
Clear governance and executive accountability for cybersecurity
Frequently Asked Questions About NIS2 Compliance
What is the NIS2 Directive?
The NIS2 Directive (EU 2022/2555) is a European Union cybersecurity framework that sets out legal measures to strengthen the security and resilience of network and information systems across the EU.
It applies to organisations operating in essential and important sectors, requiring them to implement risk management measures and report significant cybersecurity incidents.
Who needs to comply with NIS2?
NIS2 applies to medium and large organisations operating in sectors defined by the directive as essential.
Applicability depends on:
-
National implementation of the directive
-
Company size thresholds
-
Whether the organisation provides critical or digital services within the EU
In some cases, smaller organisations may also be included if they are considered critical to national infrastructure.
Is NIS2 compliance mandatory?
Yes. NIS2 establishes mandatory cybersecurity requirements across the European Union.
Organisations must comply once:
-
The directive is implemented into national law
-
They are identified as an essential or important entity
While enforcement timing may vary slightly between countries, compliance is not optional for in-scope organisations.
What does NIS2 compliance mean for customers?
Working with a NIS2-aligned provider helps organisations strengthen their own cybersecurity posture and simplify compliance efforts.
Compliant partners can:
-
Support vendor risk management and due diligence
-
Provide assurance around security practices
-
Reduce supply chain risk exposure
However, each organisation remains responsible for its own compliance under the directive.
How does NIS2 impact supply chain security?
NIS2 places strong emphasis on third-party and supply chain risk management. Organisations must assess and monitor the cybersecurity practices of their vendors and partners.
This means:
-
Increased scrutiny of service providers
-
More rigorous vendor assessments
-
Greater accountability across the entire service ecosystem
Working with compliant partners, such as Liferay, helps reduce this complexity.
How can organisations get started with NIS2 compliance?
Organisations should begin by assessing their current cybersecurity maturity and identifying gaps against NIS2 requirements.
Key first steps include:
-
Establishing a risk management framework
-
Defining incident detection and reporting processes
-
Reviewing supply chain security practices
-
Implementing business continuity and recovery plans
Early action is critical, as NIS2 compliance requires ongoing governance – not a one-time implementation.
Strengthen Your NIS2 Readiness with Liferay
Navigating the requirements of the NIS2 Directive (EU 2022/2555) goes beyond meeting regulatory obligations – it requires a secure, scalable foundation for your digital services.
Liferay helps organisations across Europe:
-
Build secure digital experience platforms aligned with modern cybersecurity standards
-
Support governance, risk management, and compliance initiatives
-
Strengthen operational resilience and service continuity
With a proven commitment to European frameworks and security best practices, Liferay provides the tools and expertise needed to support your compliance journey.
Interested in how Liferay can help you address NIS2 requirements?
Book a personalised demo to explore Liferay’s secure platform in action.
Connect with our experts to discuss your organisation’s compliance needs
