Directive NIS2 European Union
HU · Member state

NIS2 in Hungary


What binds you in Hungary is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
SZTFH
National CSIRT
VAT on your purchase
27%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


National law

2023. évi XXIII. törvény a kiberbiztonsági tanúsításról és a kiberbiztonsági felügyeletről

Adopted
In force

Hungary legislated early, before most of the Union. The Act is built around cybersecurity certification and supervision rather than restating the directive's measures, so read it alongside the implementing decree.

Supervision

SZTFH inspections

The biennial audit is the practical supervision mechanism, and SZTFH rendelet 7/2024 (VI. 24.) governs who may perform it. An auditor not on the register cannot discharge the obligation, whatever else they are accredited for.

National assessment framework

Védelmi intézkedések a biztonsági osztályok szerint — 7/2024. (VI. 24.) MK rendelet, 2. melléklet

in force since 25 June 2024, published by Miniszterelnöki Kabinetiroda, with SZTFH as auditor registrar. Built on Kiberbiztonsági törvény (Act XXIII of 2023).

Hungary has both a measure catalogue and, uniquely among the 27, a mandatory third-party audit. The protective measures are in Appendix 2 of MK rendelet 7/2024 (VI. 24.) — nineteen categories, required according to the security class you are assigned (alap or jelentős). A cybersecurity audit every two years by an auditor on the SZTFH register is compulsory. Budget for it, and settle your classification early, because the class decides the measures.

  • — Sign the contract with the auditor who will carry out the first cybersecurity audit.
  • — Complete the first cybersecurity audit, for organisations that began operating before 1 January 2025.

A label is not compliance

Hungary is the strictest regime in this hub on evidence: a cybersecurity audit every two years, performed by an auditor on the SZTFH register, is mandatory — not a certification you may choose. Budget for it and check your classification early, because the class decides the measures.

HU protective measures in full — levels, controls and what it does not cover →

Who supervises you

SZTFH is the competent authority designated by Hungary. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to NBSZ NKI, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Hungary legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0