Hungary’s NIS2 Registration Portal Explained: Who Registers with SZTFH, Incident Reporting Deadlines, and Penalties
Hungary’s NIS2 implementation splits authority between two bodies with entirely different roles. The Szabályozott Tevékenységek Felügyeleti Hatósága (SZTFH) — the Supervisory Authority for Regulated Activities — is the regulatory authority: it accepts registrations, conducts inspections, and levies fines. The Nemzeti Kiberbiztonsági Intézet (NKI), Hungary’s National Cyber Security Institute, is the operational CSIRT: incident reports go here, not to SZTFH.
Confusing these two bodies is the most common compliance mistake in-scope entities make. Register with SZTFH — but when a significant incident occurs, report it to NKI at incidens.nki.gov.hu.
Act LXIX of 2024 on the Cybersecurity of Hungary came into force on 1 January 2025, replacing the earlier Act XXIII of 2023. The European Commission issued a reasoned opinion against Hungary on 7 May 2025 for failure to notify complete transposition measures, signalling that the framework continues to evolve. This guide covers what each authority does, who must register, how to use the portal, incident reporting timelines, and the penalty structure.
Two Authorities, Two Jobs: SZTFH and NKI
The NIS2 Directive (Article 8) requires each member state to designate one or more competent authorities responsible for supervising compliance. Hungary designated SZTFH as the primary competent authority for most sectors. NKI serves as the national CSIRT and single point of contact for cross-border cybersecurity coordination with the European Commission and ENISA.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Body | Full Hungarian Name | Role |
|---|---|---|
| SZTFH | Szabályozott Tevékenységek Felügyeleti Hatósága | Regulatory supervisor: registration, audits, inspections, fines |
| NKI | Nemzeti Kiberbiztonsági Intézet | Operational CSIRT: incident response, early warnings, international coordination |
SZTFH operates under the Ministry of Regulatory Affairs, Public Administration and Justice. NKI sits within the Special Service for National Security, reporting to the Cabinet Office of the Prime Minister.
In April 2025, SZTFH issued Decree 3/2025 setting out detailed provisions on cybersecurity supervision, the conduct of regulatory inspections, and the role of the information security supervisor — making SZTFH’s enforcement posture significantly more concrete than under the 2023 Act.
Sector-Specific Authority Routing
SZTFH is the default authority for most entities, but three sectors have designated co-regulators. Hybrid entities — those operating across multiple sectors — must obtain written confirmation from SZTFH about which authority leads their oversight.
| Sector | Lead Authority |
|---|---|
| Banking and financial markets | NBH — Magyar Nemzeti Bank (Central Bank of Hungary) |
| Data-protection-centric activities | NAIH — National Authority for Data Protection and Freedom of Information |
| Public administration and defence | Ministry of Defence |
| All other regulated sectors | SZTFH (default) |
Who Must Register: Scope Under Act LXIX of 2024
Hungarian law covers the same sectors as NIS2 Annex I (essential entities) and Annex II (important entities) — energy, transport, banking, health, digital infrastructure, water, waste, manufacturing, food, space, and digital service providers — plus two Hungary-specific additions: public transport and cement, lime, and plaster manufacturing.
The standard size threshold applies to most sectors: at least 50 employees or annual turnover or balance sheet total exceeding HUF 3.9 billion (approximately €10 million). Three categories fall in scope regardless of size:
- Electronic communications providers
- DNS service operators, top-level domain registries, and trust service providers
- Sole providers — if your organisation is the only entity in Hungary providing a service in a regulated sector, you are in scope regardless of employee count or turnover
The sole provider rule has no direct equivalent in the NIS2 Directive. It prevents critical services from escaping supervision because the supplier is a small company. Between 5,000 and 6,000 Hungarian organisations are estimated to fall within scope overall.
If you are uncertain whether your entity qualifies as essential or important, the essential vs important entity guide explains the classification framework under NIS2.
Hungary’s Security Classification System
Hungary layers a three-tier security classification on top of the NIS2 essential/important binary:
| Security Class | Risk Profile | Controls Standard |
|---|---|---|
| High | System failure could trigger national crisis or massive service disruption | NIST SP 800-53 rev.5 (full control set) |
| Significant | Major operational impact but not catastrophic consequences | NIST SP 800-53 rev.5 (tailored) |
| Basic | Standard systems with lower risk profiles | NIST SP 800-53 rev.5 (baseline) |
The security class assigned to your electronic information systems determines the scope of your mandatory audit and the protective measures required — independent of whether you are classified as an essential or important entity under the Directive.
Registering with SZTFH: Portal, Process, and Deadlines
Registration is submitted electronically via SZTFH’s registration form, accessed through Hungary’s official business client portal (Cégkapu):
Registration portal: https://sztfh.hu/ugyintezes/nyomtatvanyok-es-urlapok/sztfh420/
You must have an active Cégkapu account before submitting. The registration form requires:
- Company identification data
- Cybersecurity contact person details
- The sector(s) under which your organisation is regulated
- EU member states where you provide services covered by the Act
Registration deadlines:
| Entity Type | Deadline |
|---|---|
| Entities already in scope before 1 January 2025 | 31 January 2025 |
| Entities entering scope after 1 January 2025 | Within 30 days of commencing regulated activities |
| Previously registered under Act XXIII of 2023 | Auto-enrolled; EU member state list due by 15 February 2025 |
One procedural point worth noting: submitting a registration does not automatically classify your organisation as NIS2-affected. SZTFH reviews each submission and makes the formal applicability determination. Do not assume registration equals confirmed scope status — await SZTFH’s formal response.
For EU-wide registration obligations under NIS2, including how the principal establishment rule works across member states, see the entity registration guide.
NKI and the Incident Reporting Portal
NKI is Hungary’s national CSIRT and the single point of contact for the EU’s NIS2 cooperation network. Significant incidents must be reported to NKI — not to SZTFH. SZTFH’s role in incident reporting is secondary: it evaluates whether you reported on time and may levy a fine if you missed the deadline. The report itself goes to NKI.
Incident reporting portal: https://incidens.nki.gov.hu
- Registered customer reporting: incidens.nki.gov.hu/customer
- Anonymous reporting: incidens.nki.gov.hu/anonym
- Email: csirt@nki.gov.hu
- Phone: +36 (1) 336-4833
Incident Reporting Timelines Under Article 23
The NIS2 Directive (Article 23) establishes a three-stage notification structure. An incident qualifies as significant when it causes severe operational disruption or financial loss to your organisation, or causes material or non-material damage to others.
| Stage | Deadline | Content Required |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Initial alert — flag suspected criminal origin or cross-border effects |
| Incident notification | Within 72 hours of becoming aware | Severity assessment, indicators of compromise, initial impact estimate |
| Final report | Within 1 month of incident notification | Full threat analysis, root cause, mitigation measures, cross-border consequences |
NKI must respond to your early warning within 24 hours with initial guidance on mitigation. Late notification to NKI triggers an inspection flag at SZTFH. That sequence — NKI receives the report, SZTFH evaluates timeliness, SZTFH may fine — is the practical interaction between the two bodies that every compliance officer should understand.
For a detailed breakdown of notification mechanics, templates, and what qualifies as a significant incident under EU case guidance, see the Article 23 incident notification guide and the incident reporting overview.
Penalties and Enforcement
SZTFH is the body authorised to levy fines under Act LXIX of 2024. Government Decree 418/2024 sets the fine calculation rules. SZTFH Decree 3/2025 (April 2025) operationalises the inspection and supervisory process.
Maximum administrative fines mirror the NIS2 Directive (Article 34):
| Entity Type | Maximum Fine (EU Directive Floor) | Hungarian Scale |
|---|---|---|
| Essential entities | €10,000,000 or 2% of total worldwide annual turnover — whichever is higher | HUF 50M–350M |
| Important entities | €7,000,000 or 1.4% of total worldwide annual turnover — whichever is higher | HUF 50M–350M |
Personal liability is a separate exposure: company executives and directors can face individual fines of up to HUF 15 million for wilful non-compliance. SZTFH may also impose activity prohibitions against individuals found responsible — a measure with no direct parallel in most other member state implementations.
Non-compliance with registration and non-compliance with audit requirements are independently enforceable. Missing the registration deadline is not cured by later registering; SZTFH can fine for the missed deadline itself.
For how Hungary’s enforcement posture compares to other EU member states, see the NIS2 penalties overview.
Cybersecurity Audit Requirements
All in-scope entities must undergo mandatory biennial cybersecurity audits conducted by auditors registered in SZTFH’s official auditor registry. The audit scope is tied to your assigned security class (high, significant, or basic) — not merely to your NIS2 essential/important classification.
| Milestone | Deadline |
|---|---|
| Auditor contract signed | 31 August 2025 |
| First audit — entities in scope before 1 January 2025 | 31 December 2025 |
| First audit — entities entering scope from January 2025 | 30 June 2026 |
| Subsequent audits | Every two years |
SMEs in non-critical sectors may request deferral of the first audit to 30 June 2026, but only with written regulatory approval from SZTFH. Self-assessment, incident reporting, and evidence retention obligations remain in force throughout any approved deferral period. Deferral is not available for electronic communications providers, DNS operators, or any entity classified at the High security level.
Key Takeaways
- Register with SZTFH at sztfh.hu via Cégkapu. SZTFH decides final scope applicability.
- Report incidents to NKI at incidens.nki.gov.hu. The three-stage timeline: 24h early warning, 72h detailed notification, 1-month final report.
- Hungary expands NIS2 scope to public transport and certain manufacturing sectors, and adds a sole-provider rule that catches small entities the Directive would otherwise exempt.
- Hungary’s three-tier security classification (high / significant / basic) imposes additional control requirements beyond the NIS2 baseline and determines your audit scope.
- Executive personal liability (up to HUF 15M) and activity prohibitions apply separately from corporate fines.
- Monitor SZTFH and NKI announcements: the EC’s May 2025 reasoned opinion signals further implementing measures are expected.
FAQ
My company registered under Act XXIII of 2023. Do I need to re-register under Act LXIX of 2024?
Previously registered entities were automatically enrolled under the new Act. You needed to submit your list of EU member states where you operate by 15 February 2025. If you missed that deadline, contact SZTFH directly.
What if I am a small business with fewer than 50 employees?
You may fall outside scope unless you are an electronic communications provider, DNS operator, trust service provider, or the sole provider of a regulated service in Hungary. Check your sector against Act LXIX of 2024 Annexes before assuming exemption.
Where exactly do I send incident reports?
To NKI at incidens.nki.gov.hu or csirt@nki.gov.hu — not to SZTFH. Your registration is with SZTFH, but incident reports go exclusively to NKI.
Is the incident reporting portal the same as the registration portal?
No. Registration: sztfh.hu (via Cégkapu). Incident reporting: incidens.nki.gov.hu. Separate bodies, separate platforms, separate purposes.
What is the sole provider rule?
If your organisation is the only entity in Hungary providing a specific regulated service, Act LXIX of 2024 brings you within scope regardless of company size. There is no SME exemption for sole providers in regulated sectors.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive, Article 8 — Competent Authorities and Single Points of Contact. nis-2-directive.com
- NIS2 Directive, Article 23 — Incident Notification Requirements. nis-2-directive.com
- NIS2 Directive, Article 34 — Administrative Fines. nis-2-directive.com
- Hungary — EU NIS2 Directive. Eversheds Sutherland. ezine.eversheds-sutherland.com
- NIS2 Directive Transposition in Hungary. nis-2-directive.com
- NIS2 Hungary: New Compliance Rules, Authority Map, and Audit Risks Explained. isms.online
- NIS2 Hungary Guide: Compliance, Timelines, and Implementation for 2026. copla.com
- NIS2 Directive — Registration Deadline for Hungary. DLA Piper. dlapiper.com
- NIS2 Registration and Sanctions. RSM Hungary. rsm.hu
- NIS2 Directive Implementation in Hungary. European Commission. digital-strategy.ec.europa.eu
- Incidens Bejelentés — Incident Reporting Portal. NKI. nki.gov.hu
- NCSC-HU — National Cyber Security Centre. en.nki.gov.hu
- NIS 2 in Hungary: A New Era of Cybersecurity Compliance. Katona Law. katonalaw.com
- EU NIS2 in Hungary. OpenKRITIS. openkritis.de
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
