What does a Non-compliant rating mean?
What does a Non-compliant rating mean?
On 30 June 2026, the deadline for completing the first Hungarian NIS2 cybersecurity audits expired. According to data published by the Supervisory Authority for Regulated Activities (SZTFH), 2,132 of the 2,520 organizations registered as subject to the audit obligation completed their audit on time. By the date of the Authority's communication, 1,511 audit reports had been processed, and the vast majority of organizations had successfully met the requirements. Of these, 170 organizations achieved the highest rating, compliant with negligible risk.
With the first audit cycle completed, a new question has come to the forefront for organizations whose audit resulted in a Non-compliant rating: what exactly does this result mean, how should the findings in the audit report be interpreted, and what does the result actually reveal about the organization's level of cybersecurity compliance?
Further information on the results of the first audit cycle is available in the SZTFH communication:
Completion of the cybersecurity audit deadline – SZTFH communication
What does a Non-compliant rating actually mean?
During a NIS2 audit, the auditor does not simply issue a single Compliant or Non-compliant decision. The compliance of the organization and its audited electronic information systems is assessed at several different levels.
For this reason, the term Non-compliant appearing in an audit report does not necessarily mean that the entire audit has failed.
Individual elementary requirements and requirement groups are assessed separately, and a requirement group may already receive a Non-compliant rating if one of the relevant elementary requirements is not fulfilled appropriately. The organization's overall audit result may nevertheless still be compliant.
At organizational level, a Non-compliant result applies where the organization does not achieve the minimum overall SZEKI score of 71 required for compliance.
When interpreting an audit report, it is therefore important to distinguish between the assessment of elementary requirements and requirement groups, the results of the audited electronic information systems, and the organization's overall rating.
A Non-compliant requirement does not necessarily mean a failed audit
One of the most important characteristics of NIS2 audit reporting is that an organization's audit report may contain several Non-compliant requirement groups while the organization's overall result still remains compliant.
Overall organizational compliance is not determined by the outcome of a single requirement, but by the combined assessment of the audited electronic information systems, the individual requirement groups, and the related deviations.
Two separate questions should therefore be considered:
- Did the auditor identify any requirements that were not compliant? Even in the case of a successful audit, the answer may be yes.
- Did the organization achieve the required overall SZEKI score? At organizational level, this determines whether the audit result is considered compliant.
A successful audit therefore does not necessarily mean flawless operation. Identified deviations may still require further cybersecurity actions even where the organization has successfully passed the audit.
VMI and SZEKI – what should you look for in the audit report?
Two important indicators should be distinguished when interpreting the audit result. VMI reflects compliance at the level of an audited electronic information system, while SZEKI expresses the overall level of compliance at organizational level.
| Indicator | What does it assess? | What does it show? |
| VMI Protective Compliance Index | The compliance level of an audited electronic information system. | Shows the extent to which the protective requirements applicable to the specific EIS are fulfilled. Multiple audited systems within the same organization may achieve different VMI values. |
| SZEKI Organizational Resilience Index | The organization's overall compliance level. | Expresses the overall organizational audit result. A minimum overall SZEKI score of 71 is required for compliance. |
When interpreting a Non-compliant audit result, the final SZEKI score alone is therefore not sufficient. It is also necessary to identify which electronic information systems, requirement groups, and deviations contributed to the overall result.
Not all Non-compliant deviations are equally serious
In addition to whether a requirement is fulfilled, the severity of the identified deviation also provides important information.
Audit reports may distinguish, among others, the following categories:
- negligible deviation;
- minor deviation;
- significant deviation;
- critical deviation.
The distinction is important because one organization may have several relatively minor deficiencies, while another may have fewer findings that represent considerably greater cybersecurity risk.
When interpreting a failed audit, it is therefore not sufficient to consider only how many points are missing from the 71-point SZEKI threshold. It is equally important to understand which requirements caused the loss of points and how serious the underlying deviations are.
What does the auditor actually assess?
A NIS2 audit goes far beyond a simple documentation review.
The auditor may use several assessment methods to determine whether a particular requirement is actually fulfilled. In practice, these may include:
- document review;
- interviews;
- on-site observation;
- testing of individual controls or audit evidence.
To demonstrate compliance, it is therefore not enough for an information security control to be appropriately described in a policy or procedure. The practical operation and execution of the control must also be demonstrable.
For example, a process may appear properly regulated based on document review, while the assessment of actual operation may reveal that there is insufficient evidence to demonstrate that the organization genuinely and regularly performs the defined activity.
One of the key elements of compliance is therefore auditability: the organization's ability to demonstrate implementation of the required measures through appropriate and traceable evidence.
| DID YOUR NIS2 AUDIT RESULT IN NON-COMPLIANCE? WE HELP YOU ADDRESS THE IDENTIFIED GAPS AND ACHIEVE COMPLIANCE. |
Not every audit report looks the same
Although the regulatory framework governing cybersecurity audits is common, the structure, level of detail, and presentation of auditor findings may differ between audit firms.
Some reports present the assessment of elementary requirements, requirement group results, EIS-level VMI values, the organizational SZEKI score, and the supporting evidence in separate sections. Other reports summarize the key results and the distribution of identified deviations in an executive summary, while detailed auditor findings are provided in separate annexes.
The level of detail used to document elementary requirements may also vary. Some reports separately indicate the assessment method used, the auditor's reasoning, the date of the assessment, and the result of the individual control.
The format and level of detail may therefore vary from one auditor to another, but the underlying assessment logic remains the same: the audit examines whether the applicable cybersecurity requirements are appropriately implemented in both the organization's documentation and its actual operations, and whether their implementation can be supported by sufficient evidence.
The SZEKI score is only the starting point
The final score alone is not sufficient to understand a Non-compliant result. In addition to SZEKI, the results of the individual EISs, the requirements that were not fulfilled, the severity of deviations, the auditor's reasoning, and the available supporting evidence should also be assessed together.
A score of 69 may result from a small number of clearly identifiable deficiencies, while a substantially lower SZEKI score may indicate several interconnected documentation, organizational, and technical weaknesses.
The real question after a failed audit is therefore not simply how many points are missing, but why they are missing and exactly what needs to be corrected.
In the second part of our article series, we will show how to process a Non-compliant audit report, turn auditor findings into concrete corrective actions, and prioritize the necessary measures in a professionally structured way.
Source: Supervisory Authority for Regulated Activities (SZTFH): Completion of the cybersecurity audit deadline, 10 July 2026.
| Related NIS2 Services | ||||
Outsourced Chief Information Security Officer (CISO) External information security officer service with audit support, continuous supervision, and ongoing compliance control. Learn more → | Featured service NIS2 Audit Correction Based on the audit report, we identify and address the necessary corrective actions, from planning and implementation through to achieving compliance. Learn more → | NIS2 Preparation Assessment, GAP analysis, action plan, and audit support to achieve NIS2 compliance in a structured and efficient way. Learn more → | ||


