Hungary NIS2 SZTFH competent authority cybersecurity compliance shield

NIS2 in Hungary: Your SZTFH Registration Deadline, Scope Rules, and Compliance Checklist

Hungary moved faster on NIS2 than almost any other EU member state. When the Hungarian Parliament passed Act XXIII of 2023 in May of that year — 17 months before the directive’s October 2024 transposition deadline — it made Hungary an early adopter with real enforcement infrastructure already in place. The consolidated statute, Act LXIX of 2024, entered force on January 1, 2025, and over 3,800 entities have since registered with the supervisory authority.

As of mid-2026, the first mandatory audit deadline is approaching and the January 2026 scope amendment may have changed whether your organisation qualifies in the first place. This guide covers what SZTFH actually is, who must comply under the revised thresholds, how registration works, what the security classification system requires, and what the penalty exposure looks like — including the personal liability provision that other country guides consistently underreport.

Hungary’s Legislative Path to NIS2

Hungary enacted Act XXIII of 2023 on Cybersecurity Certification and Cybersecurity Supervision in May 2023 — well ahead of the EU’s October 17, 2024 transposition deadline. That early law introduced the initial framework but left structural gaps, particularly around the essential/important entity distinction and consolidated enforcement powers.

In December 2024, the Hungarian Parliament adopted Act LXIX of 2024 on the Cybersecurity of Hungary, which entered force on January 1, 2025. Act LXIX is the definitive transposition vehicle: it repealed both Act XXIII of 2023 and Act L of 2013 (the older information security law), consolidating Hungary’s cybersecurity obligations into a single statute covering both public and private sectors. [4]

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

On April 17, 2025, SZTFH issued Decree 3/2025, which sets detailed provisions for how supervisory inspections are conducted and defines the formal role of the Information Systems Security Officer (ISSO) within organisations. Separately, an amendment enacted on May 31, 2025 revised compliance deadlines, and a further amendment on January 6, 2026 changed the scope threshold calculation in a way that may exclude companies previously caught by the rules. [10] [9]

The European Commission issued a reasoned opinion against Hungary on May 7, 2025, for failure to notify full transposition. This does not suspend the Act — enforcement continues — but it signals ongoing dialogue between Budapest and Brussels over whether all directive elements are correctly reflected in national law. [2]

Law Enacted In Force Status
Act XXIII of 2023 (CyberCert Act) May 2023 May 2023 Repealed by Act LXIX
Act LXIX of 2024 (Cybersecurity Act) December 2024 January 1, 2025 In force — primary law
SZTFH Decree 3/2025 April 2025 April 2025 In force — implementing rules
Size threshold amendment January 6, 2026 January 6, 2026 In force — narrows scope

SZTFH — Hungary’s NIS2 Competent Authority

The Supervisory Authority for Regulated Activities — Szabályozott Tevékenységek Felügyeleti Hatósága in Hungarian, abbreviated SZTFH — is Hungary’s primary cybersecurity supervisory authority under Act LXIX of 2024. [3]

NIS2 Hungary multi-regulator cybersecurity landscape showing SZTFH National Bank of Hungary NAIH and Ministry of Defence jurisdictions
Banking and financial entities face dual oversight — both SZTFH and the National Bank of Hungary apply concurrently under the DORA framework.

SZTFH’s core NIS2 functions are: maintaining the official register of in-scope entities; reviewing and approving registrations; maintaining the SZTFH Auditor Registry of certified cybersecurity auditors; conducting supervisory inspections and enforcement; and collecting the annual cybersecurity supervisory fee. Decree 3/2025 added detailed inspection procedures and defined the ISSO’s formal accountability obligations.

Hungary operates a multi-regulator model. SZTFH is not the sole competent authority for all NIS2 sectors:

Sector NIS2 Competent Authority
Digital infrastructure, utilities, transport SZTFH
Banking and financial market infrastructure National Bank of Hungary (NBH)
Data protection overlay NAIH (Data Protection Authority)
Defence and classified systems Ministry of Defence

Banking and financial entities are channelled to the National Bank of Hungary as their NIS2 competent authority. In practice, financial entities that fall under the EU’s Digital Operational Resilience Act (DORA) fulfil equivalent cybersecurity obligations through DORA’s framework — Hungary did not layer NIS2 and DORA requirements on top of each other for the same controls. [5] [12]

CSIRT-Hungary — Incident Reporting to NKI

Hungary’s national CSIRT is the National Cyber Security Centre — Nemzeti Kibervédelmi Intézet, abbreviated NKI, internationally known as NCSC Hungary. NKI serves as Hungary’s single point of contact for EU-level cybersecurity cooperation and the operational hub for significant incident reporting under Act LXIX. [2]

NIS2 Hungary NKI incident reporting cascade timeline showing T-plus-24-hour early warning 72-hour report and 30-day closure requirements
All significant incident reports must use the official template and be sent to incident@nki.gov.hu within the stated deadlines.

Entities must follow a three-stage incident reporting cascade:

Timeline Obligation
Within 24 hours of discovery Initial early warning alert
Within 72 hours of discovery Detailed report with technical analysis and initial impact assessment
Within 30 days of discovery Final incident closure report with lessons learned

All reports go to incident@nki.gov.hu using the official NKI template. Entities operating in multiple EU member states notify NKI as primary contact; NKI then coordinates with counterpart CSIRTs through the CyCLONe and ENISA networks. [2] [5]

For a detailed breakdown of what constitutes a significant incident under the directive, see the NIS2 incident reporting guide.

Who Must Comply — Scope, Thresholds, and the January 2026 Revision

Essential vs Important Entities

Act LXIX uses the NIS2 two-tier classification. Essential entities face stricter obligations and higher maximum penalties; important entities are fully subject to the cybersecurity risk management requirements but operate under a lighter audit cycle.

NIS2 Hungary scoping gate Venn diagram showing mandatory trifecta criteria and size-exempt bypass categories under January 2026 revision
Under the January 2026 revision, linked and partner enterprise figures no longer count — scope is assessed per standalone legal entity only.

Sector classification determines which tier applies. Hungary’s implementation broadly follows the directive’s two-annex structure: [8]

Tier Sectors
Highly critical (essential entities) Energy, transport, health, drinking water and wastewater, digital infrastructure, ICT service management (B2B), space
Other critical (important entities) Postal and courier services, waste management, chemicals, food production, manufacturing (medical devices, computers, electronics, machinery), digital service providers, research organisations
Hungarian additions Public transport operators, cement and lime/plaster manufacturers

Public administration is excluded from Act LXIX’s scope. Banking and financial market infrastructure fall under the NBH model described above. [12]

The Size Threshold — And What Changed in January 2026

The standard NIS2 size threshold (50+ employees or EUR 10 million annual turnover) applied initially. The January 6, 2026 amendment changed the calculation method significantly: your organisation now must meet all three conditions simultaneously to fall within scope: [9]

  • At least 50 employees, AND
  • EUR 10 million annual turnover, AND
  • EUR 10 million balance sheet total

Critically, linked and partner enterprise figures no longer count. Under the earlier rule, a standalone company with 30 employees could be caught because its parent pushed the combined headcount above 50. That route to scope is closed. Entities that registered under the former rules and now fall below the revised thresholds may pursue de-registration with SZTFH; previously paid supervisory fees are non-refundable, though pro-rated adjustments apply for the current year. [9]

Certain categories fall into scope regardless of size: sole providers of a critical service in Hungary; trust service providers; DNS service providers; domain name registrars; electronic communications network operators.

Nuclear Energy — The Operational System Carve-Out

Nuclear energy is nominally within NIS2 scope as part of the energy sector. Hungary includes a specific carve-out in Act LXIX: electronic information systems that handle classified data, and operational/programmable systems covered by the government decree on physical protection in the application of nuclear energy, are excluded from the Act’s scope. [12]

In practical terms, the core operational technology (OT) and classified IT systems at Hungary’s Paks nuclear facility fall under the pre-existing nuclear physical protection framework rather than Act LXIX. Business and administrative IT systems at nuclear facilities that are neither classified nor covered by the physical protection decree remain subject to standard NIS2 obligations. This is a system-by-system carve-out, not a full sector exclusion — facility operators should conduct a classification exercise to determine which systems are exempt.

Does This Apply to You? A Decision Path

  1. Is your organisation in one of the sectors above (including Hungarian additions)? If No → not in scope.
  2. Do you meet all three post-January 2026 thresholds (50+ employees AND EUR 10M turnover AND EUR 10M balance sheet)? If No, and not a sole critical-service provider → not in scope.
  3. Are you a sole provider of a critical service in Hungary? If Yes → in scope regardless of size.
  4. If Yes to 1 and 2 → in scope as an essential or important entity.

For the EU-level scope criteria and how Hungary’s implementation compares, see the NIS2 scope and size threshold guide.

Registration with SZTFH

Entities in scope must register with SZTFH by submitting the SZTFH 420 form through Hungary’s Cégkapu (“Company Gateway”) business portal. The form requires: company administrative details (name, registration number, address); Information Systems Security Officer (ISSO) name and contact information; sector classification (which Annex of Act LXIX applies); and a list of EU member states where the entity operates. [7] [3]

Entity Registration Deadline
Entities in operation before January 1, 2024 June 30, 2024 (original, under Act XXIII/2023)
Entities notifying multi-state operations February 15, 2025
New entities commencing regulated activities Within 30 days of becoming subject to the Act

Entities that registered under Act XXIII of 2023 are automatically carried into the Act LXIX register — no re-registration is needed. [3] The ISSO role carries substantive personal accountability under the Act: this individual coordinates the organisation’s risk management, maintains documentation for audits, and is the named contact for SZTFH during supervisory inspections.

Security Classification and Core Obligations

Act LXIX requires each entity to classify its electronic information systems into one of three tiers: Basic, Significant, or High. The classification determines which control set the entity must implement. Hungary uses NIST SP 800-53 revision 5 as its reference control framework — a specific national choice that diverges from the ISO 27001 or BSI IT-Grundschutz approaches used in other EU member states. [11]

NIS2 Hungary system classification NIST SP 800-53 three-tier framework showing Basic Significant and High criticality levels with control requirements
Hungary is the only EU member state that explicitly mandates NIST SP 800-53 rev.5 as the reference framework for NIS2 system classification.
Security Class Typical Application Control Depth
Basic Low-criticality systems, limited public-service impact Core Art.21 measures
Significant Medium-criticality; disruption affects many users Extended controls and enhanced monitoring
High Critical national infrastructure, large-scale essential services Comprehensive controls, continuous monitoring, advanced cryptography

Regardless of classification tier, all in-scope entities must implement the ten security measure categories from NIS2 Article 21: [1]

  • Risk analysis and information security policies
  • Incident handling procedures
  • Business continuity, backup management, and disaster recovery
  • Supply chain security — written assessments of direct supplier vulnerabilities
  • Secure systems acquisition, development, and maintenance
  • Policies to assess effectiveness of cybersecurity measures
  • Cyber hygiene practices and cybersecurity training
  • Cryptography and encryption policies
  • Human resources security, access control, and asset management
  • Multi-factor authentication or continuous authentication solutions

Essential entities must obtain ISO/IEC 27001 certification (or its national equivalent) by 2027 — a mandatory requirement that exceeds the NIS2 directive minimum. [11] Act LXIX also explicitly encourages post-quantum cryptographic approaches, signalling that the compliance framework will evolve toward quantum-resistant encryption for future infrastructure decisions.

The annual cybersecurity supervisory fee is calculated at 0.015% of the entity’s net sales revenue, capped at HUF 10 million (approximately EUR 25,000 at mid-2026 rates). [6]

For guidance on preparing for a supervisory audit, the NIS2 audit preparation guide covers documentation requirements and control evidence standards.

Audit Requirements

All in-scope entities must undergo periodic cybersecurity audits conducted by a firm listed on the SZTFH Auditor Registry. Self-assessments do not satisfy this obligation. The audit verifies whether implemented controls meet the requirements of the entity’s assigned security classification. Audits must be repeated every two years for essential entities. [10]

Milestone Deadline
Sign written contract with registered auditor August 31, 2025 (already passed)
Complete first cybersecurity audit June 30, 2026
Subsequent audits Every 2 years (essential entities); SZTFH-determined cycle (important entities)

The August 31, 2025 auditor contract deadline has passed. Organisations that have not yet contracted a registered auditor should contact SZTFH immediately to understand their enforcement exposure before the June 30, 2026 first-audit deadline arrives.

Penalties and Management Liability

Hungary’s penalty framework mirrors the NIS2 Directive’s Article 32/33 structure, applied in HUF equivalent at the conversion rate on the date of the enforcement decision: [6] [5]

NIS2 Hungary enforcement penalties diagram showing corporate fines up to 10 million euros and 3-year personal management ban risk
Hungary adds a mandatory personal fine of up to HUF 15M for the head of the organisation for wilful NIS2 non-compliance.
Entity Type Maximum Fine
Essential entities EUR 10 million or 2% of total worldwide annual turnover — whichever is higher
Important entities EUR 7 million or 1.4% of total worldwide annual turnover — whichever is higher

The more significant enforcement lever for executives is personal management liability. If the head of the organisation wilfully ignores compliance obligations, SZTFH can impose a personal fine of up to HUF 15 million (approximately EUR 37,500). For repeated infringement, imposition of a personal fine is mandatory — not discretionary — and a three-year prohibition on holding management positions is available as an additional sanction. [6] [7]

This personal liability provision distinguishes Hungary’s implementation from several other EU member states where fines fall exclusively on the corporate entity. Board-level engagement with NIS2 compliance is not merely good governance in Hungary — it is a live personal financial and professional risk.

For the complete HUF fine tiers, the seven-step SZTFH supervisory escalation ladder, and the director ban mechanism in full detail, see the Hungary NIS2 penalties and enforcement guide. For penalty structures across other EU member states and the full Article 32/33 framework, see the NIS2 penalties and enforcement guide. For an overview of the directive itself, the NIS2 directive guide covers the EU-level framework underpinning Hungary’s implementation.

Hungary NIS2 Compliance Checklist

Step Action Deadline / Status
1 Confirm scope: sector classification AND revised 3-condition size threshold (50+ employees AND EUR 10M turnover AND EUR 10M balance sheet, post-Jan 2026) Immediately
2 Register via SZTFH 420 form on Cégkapu portal; provide ISSO contact details and sector classification New entities: 30 days from becoming subject to the Act
3 Appoint Information Systems Security Officer (ISSO) — named individual with documented accountability At registration
4 Classify electronic information systems into Basic / Significant / High tiers using NIST SP 800-53 rev.5 Before audit
5 Implement all Article 21 NIS2 security measures across the 10 categories Ongoing
6 Sign written contract with SZTFH-registered cybersecurity auditor August 31, 2025 — PASSED
7 Complete first cybersecurity audit with registered auditor June 30, 2026
8 Configure incident reporting: 24h / 72h / 30-day cascade to incident@nki.gov.hu Ongoing
9 Budget and pay annual cybersecurity supervisory fee (0.015% of net sales, max HUF 10M) Annual
10 Plan ISO/IEC 27001 certification pathway (essential entities only) Deadline 2027; begin gap assessment now

Frequently Asked Questions

Is my company in scope for NIS2 in Hungary?

Since January 6, 2026, your organisation must meet all three conditions simultaneously: 50 or more employees, annual turnover of EUR 10 million or more, and a balance sheet total of EUR 10 million or more. Linked and partner enterprise figures no longer affect the calculation. If you fall below any one of these thresholds, you are not in scope unless you are a sole provider of a critical service, a trust service provider, a DNS provider, or a domain name registrar.

What is SZTFH?

SZTFH — Szabályozott Tevékenységek Felügyeleti Hatósága — is the Supervisory Authority for Regulated Activities, Hungary’s primary NIS2 competent authority. It registers in-scope entities, certifies auditors, conducts supervisory inspections, and enforces Act LXIX of 2024. Registration is completed via the SZTFH 420 form on the Cégkapu portal.

When is the NIS2 audit deadline in Hungary?

The deadline to complete your first mandatory cybersecurity audit is June 30, 2026. You must have signed a written contract with a SZTFH-registered auditor by August 31, 2025 — that deadline has passed. If you have not yet contracted an auditor, contact SZTFH promptly.

Can management be personally fined for NIS2 non-compliance in Hungary?

Yes. If the head of the organisation wilfully ignores compliance obligations, SZTFH can impose a personal fine of up to HUF 15 million. For repeated infringement the fine is mandatory, and a three-year management ban is available as an additional measure. This is a meaningful personal liability exposure, not a theoretical one.

Sources

  1. NIS2 Directive Article 21 — Security Requirements. nis-2-directive.com. https://nis-2-directive.com/NIS_2_Directive_Article_21.html
  2. NIS2 Directive Implementation in Hungary. European Commission. https://digital-strategy.ec.europa.eu/en/policies/nis2-directive-hungary
  3. Hungary — NIS2 Directive. Eversheds Sutherland. https://ezine.eversheds-sutherland.com/eu-nis2-directive/hungary
  4. NIS2 Directive Transposition — Hungary. nis-2-directive.com. https://www.nis-2-directive.com/Transposition/Hungary.html
  5. NIS2 Hungary: New Compliance Rules, Authority Map, and Audit Risks Explained. ISMS.online. https://www.isms.online/nis-2/country/hungary/
  6. New Cybersecurity Act in Hungary: What Is Changing from 2025? ILF Law. https://www.ilflaw.com/publications/new-cybersecurity-act-in-hungary-what-is-changing-from-2025/
  7. NIS2 Directive — Registration Deadline and Severe Sanctions. RSM Hungary. https://www.rsm.hu/en/blog/nis2-directive-nis2-registration
  8. Registration Required by the CyberCert Act. Forvis Mazars Hungary. https://www.forvismazars.com/hu/en/insights/newsletters/legal-newsletters/legal-newsletters-2024/registration-required-by-the-cybercert-act
  9. Hungary Cybersecurity Act: NIS2 Size Threshold Changes 2026. CMS Law. https://cms.law/en/hun/legal-updates/hungary-revises-size-thresholds-for-nis2-implementation
  10. NIS2: Modified Cybersecurity Deadlines. RSM Hungary. https://www.rsm.hu/blogs/audit/nis2-modified-cybersecurity-deadlines
  11. NIS2 Hungary Guide: Compliance, Timelines, and Implementation for 2026. Copla. https://copla.com/blog/compliance-regulations/nis2-directive-regulations-and-implementation-in-hungary/
  12. EU NIS2 in Hungary. OpenKRITIS. https://www.openkritis.de/eu/eu-nis-2-hungary.html
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: