DÁP eSignature cybersecurity requirements tightened: Significant security class and 95% compliance

2026/11/08

As of 22 July 2026, new cybersecurity requirements apply to electronic information systems (EIS) participating in the DÁP Integrated eSignature service. Under IdomSoft’s Connection Policy, the affected EISs must comply with the requirements of the SIGNIFICANT security class, achieving a compliance level of at least 95%. This is a substantially higher threshold than the overall SZEKI score above 70% required to successfully pass a NIS2 audit.

DÁP Integrated eSignature enables organizations to integrate the DÁP digital signature service directly into their own digital administration or contracting processes. This allows users to approve and digitally sign documents prepared for them within the given process using the DÁP mobile application.

The newly effective Connection Policy, however, introduces significantly stricter cybersecurity requirements for systems participating in the service. According to Chapter 9 of the Policy, all EISs participating in the service must demonstrate compliance with the SIGNIFICANT security class under Decree 7/2024, achieving a passing result of at least 95%. In addition, the relevant security and service quality controls of ETSI TS 119 101 must also be taken into account.

The current DÁP Integrated eSignature Connection Policy and related documentation are available on the SZEÜSZ portal:

DÁP Integrated eSignature – official connection documentation

70% is no longer enough – 95% is required

One of the most important consequences of the change is that for systems involved in DÁP Integrated eSignature, an overall SZEKI score above 70%, which is sufficient to successfully pass a NIS2 cybersecurity audit, is no longer enough: the Connection Policy requires 95% compliance with the requirements of the SIGNIFICANT security class.

This is particularly important for organizations whose electronic information systems have already successfully undergone a NIS2 audit. A system that has successfully passed a NIS2 audit does not necessarily meet the requirements applicable to DÁP eSignature. The SIGNIFICANT security class may require the implementation of additional security measures, while the expected 95% result also sets a considerably higher bar in terms of the overall level of compliance.

The change therefore involves much more than an administrative reclassification. Meeting the requirements of the SIGNIFICANT security class may require the introduction of new organizational, procedural and technical measures, further development of existing policies and procedures, and an expansion of the evidence to be presented during the audit.

NEED SUPPORT WITH NIS2 PREPARATION? OUR EXPERTS CAN GUIDE YOU FROM ASSESSMENT TO AUDIT.

New users must demonstrate compliance before going live

For organizations planning to use the service, the requirement directly affects their preparation for going live. The Connection Policy states that compliance with the specified technical requirements must be demonstrated in order to use the service. To this end, an audit report, audit certificate or audit confirmation relating to the affected system must be submitted to IdomSoft. The documentation must clearly demonstrate the assessment and fulfilment of the prescribed requirements, as well as the results of the assessment.

Cybersecurity preparation therefore cannot be treated as a separate task to be addressed only at the end of the DÁP integration. If an organization plans to integrate DÁP Integrated eSignature into its own system, it is worth assessing already during the development and integration planning phase how far the current compliance level of the affected EIS is from the 95% threshold required for the SIGNIFICANT security class.

Further practical information about the implementation of DÁP, including audit-related questions concerning integrated eSignature, is also available in FinTechZone’s overview:

DÁP 2026 in the financial sector – 18 questions and answers

The change may also affect systems that have already successfully passed an audit

The new requirements are relevant not only to organizations currently planning to introduce DÁP Integrated eSignature. They may be particularly important for organizations that already use or have integrated the service, while the affected EIS was previously successfully audited under the BASIC security class.

For these organizations, it may become necessary to prepare the EIS for the higher level of requirements before the next renewal audit. This involves assessing the additional security measures applicable under the SIGNIFICANT security class, identifying gaps compared with the current state, and implementing the necessary organizational, documentation and technical improvements. All of this must be done in a way that enables the organization to demonstrate not only compliance during the audit, but also the 95% result required by DÁP.

For this reason, it is advisable not to wait until the next audit to begin preparation. The earlier an organization identifies that an EIS must be prepared for the SIGNIFICANT rather than the BASIC security class due to DÁP eSignature, the more effectively the necessary improvements can be planned and implemented.

We help you prepare for the new DÁP eSignature requirements

The Regens expert team provides support in both situations:

  • preparing organizations planning to introduce DÁP Integrated eSignature,
  • and supporting organizations that have already successfully passed an audit but whose affected EIS will need to be audited under the SIGNIFICANT security class at their next renewal audit.

As part of the preparation, we:

  • assess the gaps between the current state and the requirements of the SIGNIFICANT security class;
  • identify the actions required to achieve the 95% compliance level;
  • support the development of the necessary policies, procedures, registers and audit evidence;
  • provide professional recommendations for implementing the required technical measures;
  • and support the organization throughout its audit preparation.

DÁP ESIGNATURE AND NIS2 PREPARATION? WE CAN HELP YOU ACHIEVE 95% COMPLIANCE.

Related NIS2 Services

Outsourced Chief Information Security Officer (CISO)

External information security officer service with audit support, continuous supervision, and ongoing compliance control.

Learn more →

 

Featured Service

NIS2 Preparation

Assessment, GAP analysis, action plan, and audit support to achieve NIS2 compliance in a structured and efficient way.

Learn more →

 

NIS2-compliant IT Operations

Secure and auditable IT operations with continuous monitoring, incident management, and well-documented processes.

Learn more →