NIS2 · MAVIR · MEKH · CBAM · IEC 61850

Software development for energy

SCADA / EMS / MDM integration for power, gas and district-heating providers, smart-meter pipelines on DLMS/COSEM, MAVIR and MEKH data reporting, CBAM 2026 definitive declarations and NIS2 essential-entity compliance — all in one codebase. Last updated 2026-05-04.

TL;DR

  • Energy is an essential entity under NIS2 Annex I — fines >= EUR 10M or 2%, Hungary's Act LXIX of 2024 in force 2026-01-06.
  • CBAM (Reg. 2023/956) definitive period since 2026-01-01, first annual declaration in H1 2027.
  • MAVIR data reporting (system load, REMIT inside information) is automatable via the ENTSO-E API + REMIT URM.
  • DLMS/COSEM (IEC 62056) is the smart-meter standard EU-wide; IEC 61850 handles substation automation.
  • Project ranges: HUF 12-90M depending on scope, EU-region and on-prem deploy.

Pain map — what energy companies are dealing with right now

Concrete, named problems from Hungarian electricity, gas and district-heating providers.

NIS2 essential entity — no Article 21(2) program yet

Power, gas and district-heating providers are all essential entities (NIS2 Annex I). Many organisations haven't lit up the Act LXIX of 2024 ten-measure implementation and the 24h/72h reporting pipeline, while the fine threshold is at least EUR 10M or 2% of global turnover.

MAVIR data reporting in Excel macros

Many smaller market participants still hand-build TSO load and settlement reports. An hour-late filing can breach REMIT (Reg. 1227/2011) inside-information reporting — an automated pipeline is needed.

Smart meter MDM siloed — VEE done by hand

15-minute data coming from DLMS/COSEM reads ends up in Excel / SAS for VEE at many providers. Moving to a real MDM (Itron / Oracle Utilities / Honeywell) automates conflict resolution and the billing handoff.

CBAM definitive period from 2026 — no data warehouse yet

Importers of steel, aluminium, cement, hydrogen and electricity have to file the first CBAM declaration by 31 May 2027 (or 30 September after the amendment) for 2026. The embedded-emissions calculation pipeline (default values, actual measurement, third-party supplier) is incomplete at many companies.

OT / IT segmentation — IEC 61850 GOOSE on the office LAN

At several Hungarian mid-market players, substation IEC 61850 GOOSE traffic and the office IT LAN share the same 1G uplink. Under NIS2 supply-chain and cryptography requirements that's not sustainable — Purdue-level segmentation is needed.

Regulatory landscape for energy software

Only items grounded in official sources (EUR-Lex, MEKH, MAVIR, NJT).

RegulationApplicableScopePenalty
NIS2 — Dir. (EU) 2022/2555HU 2026-01-06 (Act LXIX of 2024)Essential entity (Annex I — energy)>= EUR 10M or 2%
CBAM — Reg. (EU) 2023/956Definitive period from 2026-01-01Importers of steel, aluminium, cement, fertiliser, electricity, hydrogenMember State sanctions
REMIT — Reg. (EU) 1227/2011In forceEnergy market transparency, inside information reportingACER + national regulator (MEKH)
MEKH 1/2023. (IV. 5.)In forceElectricity, gas, district heating data reportingMEKH sanctions
EU AI Act — Reg. (EU) 2024/16892026-08-02 high-risk AICritical-infrastructure safety AI (Annex III pt. 2)<= EUR 15M or 3% (Art. 99(4))
GDPR — Reg. (EU) 2016/6792018-05-25Consumer energy data (smart meter)<= EUR 20M or 4%

Integration matrix — what we connect to

Every named system has a documented API and live integrations in production at our energy customers.

SystemProtocolNote
Siemens Spectrum Power (ADMS / EMS)ICCP / TASE.2 + RESTTSO/DSO grid management, often paired with OSIsoft PI.
ABB Network ManagerICCP / TASE.2 + OPCCommon SCADA/EMS at ENTSO-E TSOs and large DSOs.
OSIsoft PI / AVEVA PIPI Web API + AF SDKEnergy and industrial historian, native pairing with Spectrum Power.
MAVIR ENTSO-E feedENTSO-E Transparency API + REMIT URMTSO-level data reporting, REMIT inside-information feed.
Itron Enterprise Edition (MDM)REST + DLMS/COSEMSmart-meter data management across Europe.
Oracle Utilities Customer Cloud / MDMREST + IEC 62056C&I + residential MDM + CC&B.
IEC 61850 substation (GOOSE / MMS / SV)Ethernet multicast + MMSDigital substation comms, sub-4ms GOOSE.
DLMS/COSEM (IEC 62056)HDLC / TCP/IP, AES-128 GMACSmart-meter read, AMI base protocol.
OPC UABinary / HTTPS + cert authModern OT/IT bridge, IEC 61850 -> OPC UA mapping exists.
EU CBAM RegistryREST + EORI authCBAM declarations and certificate handling from 2026.

Why pick us for an energy project

OT / IT segmentation ready

Purdue-level network zoning, IEC 61850 GOOSE on its own VLAN, OT incident stream into the SOC — NIS2 24h/72h reporting flow.

Multi-protocol depth

IEC 61850, DLMS/COSEM, ICCP/TASE.2, OPC UA, IEC 60870-5-104 — one stack with bridges to cloud telemetry.

CBAM reporting pipeline

Embedded-emissions calc with default + actual + third-party supplier data, CBAM Registry sync.

MAVIR / MEKH automation

ENTSO-E feed, REMIT URM event log, MEKH 1/2023 report export, with audit-trail capture.

Pricing for energy projects

Our published project ranges (see /pricing.md), adjusted for energy overhead (about +25-35% for NIS2 essential-entity requirements).

  • · SCADA / EMS bridge with IEC 61850: 6-10 months, HUF 35-90M
  • · MDM smart-meter pipeline (DLMS/COSEM): 5-9 months, HUF 28-75M
  • · CBAM reporting module (importers): 3-5 months, HUF 12-30M
  • · MAVIR / MEKH data-reporting pipeline: 4-7 months, HUF 18-45M
  • · NIS2 essential-entity compliance program: 6-9 months, HUF 30-80M
  • · OT/IT segmentation + Purdue zoning: 3-4 months, HUF 14-32M
  • · Compliance + integration retainer: HUF 1-3M / month

Talk in person, near our office

In a 30-minute scoping call we map the SCADA / EMS / MDM environment and give you a tight estimate. Call +36 30 098 0767 or drop in.

Budapest office: Bank Center, Szabadság tér 7., 1054 Budapest, 1st floor, office 112. Mon-Fri 9:00-18:00 by appointment · balint@appforge.hu
Internal links if you want to go deeper: NIS2 checklist · SCADA development · System integration.
GYIK

Energy — frequently asked

Yes. NIS2 Annex I lists energy (electricity, district heating and cooling, oil, natural gas, hydrogen) as essential. Hungary's Act LXIX of 2024 (in force 2026-01-06) takes this on in full. The fine threshold is at least EUR 10 million or 2% of global turnover. The Article 21(2) ten measures (risk analysis, incident handling, business continuity, supply-chain security, cryptography, MFA etc.) and Article 23 24h/72h/1-month incident reporting are mandatory. The Commission's reasoned opinion of 7 May 2025 indicates Hungary's full transposition is still ongoing — being proactive on compliance pays off.

Let's start the energy scoping call

In 30 minutes we map the SCADA / EMS / MDM environment and give you a tight time-and-cost estimate.

Start a project