NIS2 Country Guide

NIS2 Hungary: Mandatory Audits, SZTFH Fines & the Supervisory Fee

Hungary implemented the NIS2 Directive through the Cybersecurity Act (2024. évi LXIX. törvény), in force since 1 January 2025, with the operative detail in Government Decree 418/2024. Hungary is one of the few member states to require a mandatory independent cybersecurity audit and to charge an annual supervisory fee — and the first audit deadline for established entities was 30 June 2026.

In force: 1 January 2025 First audit was due: 30 June 2026 Law: Act LXIX of 2024 + Decree 418/2024 Authority: SZTFH · CSIRT: NKI Last updated: 4 August 2026

Introduction: NIS2 Directive & the Hungarian context

Hungary moved from a fragmented cybersecurity framework to a single Cybersecurity Act that implements the NIS2 Directive and extends obligations to a wide range of public and private entities. If you operate critical or important services in Hungary, you are subject to registration, audit and incident-reporting rules that go beyond what the Directive itself requires.

Two features make Hungary unusual. It requires a mandatory independent cybersecurity audit by an auditor on the SZTFH register, and it charges an annual cybersecurity supervisory fee. Neither appears in the Directive. A third point matters more than either: the Act itself sets almost no numbers — the fine amounts and the incident-reporting clock are in Government Decree 418/2024, so a reading of the Act alone tells you very little about what you actually owe.

Quick link: For a general overview, read “What is NIS2?” and “NIS vs NIS2” before diving into Hungary-specific requirements.

What you must do in Hungary

Five duties. Two of the deadlines have already passed, which makes this the most time-sensitive country page on this site — if you are established in Hungary and have not done the first two, you are already exposed to a fine with a statutory minimum.

  1. Register with SZTFH within 30 days of starting operations or of coming within the scope of the Act. Registration is by data submission; failure to submit carries a fine from HUF 200,000, and supplying it late from HUF 50,000.
  2. Conclude a written agreement with a registered cybersecurity auditor. For entities registered after the Act took effect, within 120 days of registration. For entities already trading before 1 January 2025, the deadline was 31 August 2025 and has passed. Failure carries HUF 1,000,000 – 15,000,000.
  3. Complete the first cybersecurity audit. Within two years of registration — but for entities already trading before 1 January 2025 the deadline was 30 June 2026, which has now passed. Failure carries HUF 1,000,000 – 50,000,000.
  4. Pay the annual cybersecurity supervisory fee. SZTFH tells you the amount in your registration decision. Non-payment carries a minimum of HUF 500,000 and a maximum of ten times the annual fee.
  5. Report significant incidents on the 24-hour / 72-hour / one-month clock to the national incident response centre. The detail is in Decree 418/2024 and is set out below.
The auditor must be on the SZTFH register. Not any auditor, and not your existing financial auditor. Only auditors entered on the register kept under 7/2024. (VI. 24.) SZTFH decree may perform the statutory cybersecurity audit; SZTFH publishes the list.

NIS2 Directive implementation in Hungary

Hungary first implemented NIS2 through Act XXIII of 2023 on cybersecurity certification and cybersecurity supervision. That was replaced and consolidated by Act LXIX of 2024 on the cybersecurity of Hungary (2024. évi LXIX. törvény, the “Cybersecurity Act”), in force since 1 January 2025, with detailed rules in Government Decree 418/2024.

Deadlines from the two regimes are routinely mixed up. The 2023 Act had its own registration deadline of 30 June 2024. The 2024 Act reset the framework from 1 January 2025 with different dates. Several widely-read English-language guides blend the two and present the result as current — which is why published summaries of the Hungarian deadlines disagree with each other.

The dates on this page are taken from SZTFH's own published obligations, keyed to the provisions they come from.

Status

Transposed and fully operational. The Cybersecurity Act has applied since 1 January 2025 and the consolidated text is current to 29 July 2026, with a further version dated 1 January 2027 — the Act is still being amended.

Where the numbers actually live

The Act delegates rather than specifies: it repeatedly refers to a fine “of the amount determined by government decree”. Government Decree 418/2024 carries the fine table and the incident-reporting clock. The only figure in the Act itself is Section 35(1) — HUF 1–5 million for an electronic communications provider.

The three SZTFH decrees

7/2024. (VI. 24.) — the auditor register and the requirements auditors must meet. 1/2025. (I. 31.) — how the cybersecurity audit is conducted and the maximum audit fee. 2/2025. (I. 31.) — the cybersecurity supervisory fee.

The Act covers high-risk and at-risk sectors closely aligned to Annexes I and II of the Directive, and extends obligations to organisations supporting critical state and municipal functions. Defence-purpose electronic information systems are excluded from SZTFH supervision.

Am I in scope in Hungary?

Hungary applies the Directive's sector and size tests, using its own vocabulary of “high-risk” and “at-risk” sectors, and then extends the regime into the public sector.

TestThreshold
Sector Listed as a high-risk sector (Annex 1 to the Act, aligned to Directive Annex I) or an at-risk sector (Annex 2, aligned to Annex II).
Size 50 or more employees, or annual net revenue or budget revenue appropriation above the forint equivalent of EUR 10 million — and, for entities required to prepare statutory accounts, a balance-sheet total above the same figure.
Regardless of size Certain provider types are in scope whatever their size, including electronic communications providers, trust service providers, DNS service providers and domain name registries.
Public sector Public bodies operating electronic information systems supporting critical state and municipal functions, with their own duties for information security officers and system classification.
Excluded Defence-purpose electronic information systems fall outside SZTFH's cybersecurity supervision.

Hungary also requires in-scope entities to classify each electronic information system into a security class, and the required controls follow from that classification rather than being uniform across the organisation. Getting the classification wrong changes the whole control set, so it is the first substantive piece of work, not an administrative afterthought.

NIS2 Hungary: what you need to know about compliance & audits

Hungary combines NIS2’s “essential / important” model with national classifications of “high-risk” and “at-risk” sectors, backed by mandatory audits and supervisory fees.

The supervisory fee, in figures

  • At most 0.015% of the previous business year's net revenue or budget revenue appropriation.
  • Capped at HUF 10,000,000 for a single entity.
  • Group cap of HUF 50,000,000 a year across a recognised corporate group, an actual corporate group under the Civil Code, or a consolidation group.
  • Calculated, paid and accounted for rounded to HUF 1,000.
  • If the year's fee comes to less than HUF 5,000, nothing is payable.

Core obligations

  • Classify each electronic information system into a security class and apply the controls that follow from it.
  • Register with SZTFH within 30 days, and notify any change of data — failure to notify a change is itself a fineable breach (HUF 50,000 – 1,000,000).
  • Register your information security officer and your information security policy with the authority; each omission carries HUF 200,000 – 2,000,000.
  • Conclude an agreement with an auditor on the SZTFH register, and complete the audit within the statutory period.
  • Report significant incidents on the 24-hour / 72-hour / one-month clock in Decree 418/2024.
  • Pay the annual cybersecurity supervisory fee.
  • Submit a vulnerability management plan, evidence of cybersecurity training, and an evaluation report after cybersecurity exercises — each has its own fine range.

Standards & certification

The Act does not mandate a single standard (such as ISO/IEC 27001), but allows regulators to require use of ICT products and services certified under Hungarian or European cybersecurity certification schemes. Aligning with recognised frameworks (ISO 27001, NIST CSF, IEC 62443, etc.) is strongly advised.

The audit period runs from registration, not on a fixed national cycle. The first audit is due within two years of the entity's registration, so two organisations registering months apart have different deadlines. The exception is entities already trading before 1 January 2025, for whom the Act fixed a single date — 30 June 2026. Missing the audit deadline carries HUF 1,000,000 – 50,000,000.

Competent authorities & CSIRT

Supervision is centralised in SZTFH; incident handling sits with the national cybersecurity incident response centre. The Act carves defence-purpose systems out of SZTFH's remit.

RoleAuthorityNotes
National cybersecurity authority / supervisor Supervisory Authority of Regulated Activities (SZTFH) Primary supervisory authority for most essential and important entities; oversees registration, audits, supervisory fees and enforcement of the Cybersecurity Act.
National CSIRT National Cyber Security Center of Hungary (NKI / NCSC Hungary) Operates the national incident reporting platform and handles significant cybersecurity incidents (including NIS2-related incidents) 24/7.
Auditor register SZTFH, under 7/2024. (VI. 24.) SZTFH decree Keeps the register of cybersecurity auditors and sets the requirements they must meet. Only a registered auditor may carry out the statutory cybersecurity audit; the list is published by SZTFH.
Defence-purpose systems Outside SZTFH supervision The Act expressly excludes defence-purpose electronic information systems from the cybersecurity supervision exercised by SZTFH.

Registration and the audit obligation

Hungary's distinctive requirement is the mandatory independent cybersecurity audit. Very few member states require one. It has its own contract deadline, its own completion deadline, its own register of eligible auditors and its own fine range — and both of the deadlines for established entities have now passed.

DutyDeadlineProvision
Register with SZTFH 30 days from starting operations or coming within scope Cybersecurity Act
Agreement with a registered auditor 120 days from registration Section 16(2)(a)
Agreement with an auditor — entities trading before 1 Jan 2025 31 August 2025 — passed Section 89(1a)
Complete the first cybersecurity audit Two years from registration Section 16(1)
First audit — entities trading before 1 Jan 2025 30 June 2026 — passed Section 89(2)
If you have missed either deadline, the exposure is a fine with a statutory floor. Failing to conclude the auditor agreement on time is HUF 1,000,000 – 15,000,000; failing to complete the audit on time is HUF 1,000,000 – 50,000,000. These are not ceilings that a regulator may or may not approach — the decree sets a minimum as well.
HungarianWhat it means
Kiberbiztonsági tv.The Cybersecurity Act, Act LXIX of 2024
nyilvántartásba vételRegistration with the authority
bírságAdministrative fine
felügyeleti díjThe annual supervisory fee
elektronikus információs rendszerElectronic information system — the unit that gets security-classified
eseménybejelentésThe 72-hour incident report
zárójelentésThe final report, due within one month
dias equivalentsHungarian deadlines here are calendar days unless the source says otherwise

The Act, the decree and the SZTFH decrees are published in Hungarian. There is no official English translation, so the Hungarian text governs.

Incident reporting in Hungary

The clock is in Government Decree 418/2024, not in the Act. It follows the Directive's shape, and adds one obligation that runs in the other direction.

StageDeadline
First report (első bejelentés) Without undue delay, and in every case within 24 hours of becoming aware of the incident
Incident report (eseménybejelentés) Without undue delay, and in every case within 72 hours, updating the first report and giving an initial assessment of severity and impact
Final report (zárójelentés) Within one month of submitting the 72-hour report
Trust service providers Within 24 hours of becoming aware, for incidents affecting the trust services they provide
The obligation runs both ways. Under the decree, the incident response centre must respond to your first report without delay and, where possible, within 24 hours — sending acknowledgement and, if you ask for it, guidance on mitigation measures. Very few transpositions impose a response time on the regulator, and it is worth knowing you are entitled to ask.

Failing to produce the final report, or producing an inadequate one, carries HUF 500,000 – 5,000,000. Failing to cooperate with the incident response centre, or to carry out an ordered vulnerability assessment or incident investigation, carries HUF 500,000 – 50,000,000.

National NIS2 timeline & key dates (Hungary)

27 Dec 2022 — NIS2 Directive (EU) 2022/2555 is published in the EU Official Journal.
23 May 2023 — Act XXIII of 2023 on cybersecurity certification and cybersecurity supervision is adopted, starting Hungary’s NIS2 transposition.
30 Jun 2024 — Initial registration deadline for affected entities under the 2023 cybersecurity regime.
20 Dec 2024 — Act LXIX of 2024 on the cybersecurity of Hungary (“Cybersecurity Act”) is adopted.
1 Jan 2025 — Cybersecurity Act and Government Decree 418/2024 enter into force, repealing the previous cybersecurity laws and consolidating NIS2 implementation.
31 Jan 2025 — 1/2025 and 2/2025 SZTFH decrees published, setting the conduct and maximum fee of the cybersecurity audit and the supervisory fee.
31 Aug 2025 — Deadline for entities trading before 1 January 2025 to conclude an agreement with a registered cybersecurity auditor (Section 89(1a)).
30 Jun 2026 — Deadline for entities trading before 1 January 2025 to complete the first mandatory cybersecurity audit (Section 89(2)). This date has passed.
29 Jul 2026 — The consolidated Cybersecurity Act is current to this date, following amendment. A further consolidated version is dated 1 January 2027.

Sector-specific requirements (Hungary)

  • High-risk sectors: energy, transport, banking and financial market infrastructures, health, drinking water, wastewater, digital infrastructure and ICT service management, public administration and others broadly aligned with NIS2 Annex I.
  • At-risk sectors: postal and courier services, waste management, food production and distribution, manufacturing of key products (e.g. medical devices, pharmaceuticals, electronics), and certain digital services, reflecting Annex II of NIS2.
  • State & municipal bodies: the Cybersecurity Act also captures many public bodies that operate critical electronic information systems, with specific duties for information security officers and system classification.

How Hungary differs from the NIS2 Directive

Hungary is one of the more demanding transpositions in the EU, and the differences are structural rather than cosmetic. If you are running a multi-country programme built on the Directive, these are the gaps.

  1. A mandatory independent audit. The Directive requires risk management; Hungary requires an external cybersecurity audit by an auditor on a state register, on a statutory deadline, with its own fine range. Very few member states do this.
  2. An annual supervisory fee. Up to 0.015% of net revenue, capped at HUF 10 million per entity and HUF 50 million per group. The Directive contains nothing comparable, and this is a recurring budget line rather than a one-off compliance cost.
  3. Statutory minimum fines, per infringement. The Directive sets ceilings. Decree 418/2024 sets a floor and a ceiling for each of more than twenty separately-named breaches — from HUF 50,000 for a late data change up to HUF 150,000,000.
  4. Mandatory personal liability on repeat. Where the head of the organisation fails to meet a statutory duty, the authority may impose a fine of up to HUF 15,000,000 — and on a repeat breach it must. The discretion disappears the second time.
  5. Security classification drives the controls. Rather than one control set for the organisation, each electronic information system is classified and the required measures follow from that class. The classification is the compliance decision.
Where Hungary does not deviate: the sector lists track Annexes I and II closely, the size thresholds are the Directive's, and the incident-reporting clock keeps the familiar 24-hour, 72-hour and one-month shape.

Penalties, fine ranges and personal liability

The Cybersecurity Act sets almost no amounts — it delegates them to government decree. The operative figures are in Annex 2 to Government Decree 418/2024, which names more than twenty separate breaches and gives each one a minimum and a maximum in forint. Annex 3 carries a separate scale for other categories of organisation. Below are the ranges most entities will care about.

The overall ceilings

  • Essential entities: the forint equivalent of EUR 10 million or 2% of total global annual turnover in the previous financial year, whichever is higher.
  • Important entities: the forint equivalent of EUR 7 million or 1.4% of global annual turnover, whichever is higher.
  • Euro amounts are converted at the Magyar Nemzeti Bank rate on the day the fine decision is made, not at the date of the breach.

The per-breach table — Decree 418/2024, Annex 2

InfringementMinimumMaximum
Failure to supply the data required for registrationHUF 200,000HUF 2,000,000
Failure to apply to register the information security officerHUF 200,000HUF 2,000,000
Failure to apply to register the information security policyHUF 200,000HUF 2,000,000
Failure to notify a change of registered dataHUF 50,000HUF 1,000,000
Registration data supplied late (essential / important entity)HUF 50,0000.1% of net revenue, max HUF 15,000,000
Registration data not supplied at all (essential / important entity)0.5% of net revenue, min HUF 1,000,0002% of net revenue, max HUF 150,000,000
Failure to pay the supervisory feeHUF 500,000Ten times the annual supervisory fee
Failure to conclude the auditor agreement on timeHUF 1,000,000HUF 15,000,000
Failure to complete the cybersecurity audit on timeHUF 1,000,000HUF 50,000,000
Non-compliance with a final, enforceable decision of the authorityHUF 1,000,000HUF 50,000,000
Failure to cooperate with the information security supervisorHUF 1,000,000HUF 40,000,000
Failure to inform service users when ordered toHUF 2,000,000HUF 20,000,000
Failure to submit the vulnerability management planHUF 200,000HUF 10,000,000
Failure to submit the cybersecurity exercise evaluation reportHUF 200,000HUF 4,000,000
No certificate evidencing cybersecurity trainingHUF 200,000HUF 4,000,000
Failure to cooperate with the incident response centreHUF 500,000HUF 50,000,000
Failure to carry out an ordered vulnerability assessment or incident investigationHUF 500,000HUF 50,000,000
Final report missing or inadequateHUF 500,000HUF 5,000,000
Breach of an intermediary provider's cooperation dutyHUF 1,000,000HUF 40,000,000
Personal liability becomes mandatory on a repeat breach. Where the head of the organisation fails to meet a duty imposed by law, the national cybersecurity authority may impose a fine of up to HUF 15,000,000 — and where the breach is repeated, it must. A further HUF 15,000,000 is available where the decree's incident-handling and investigation duties are not met.

Electronic communications providers have their own tier in the Act itself: HUF 1,000,000 – 5,000,000 under Section 35(1), repeatable after a further deadline passes without compliance.

How to prepare for NIS2 in Hungary

  1. Confirm scope: map your services and electronic information systems against the high-risk and at-risk sector lists and determine whether you are an essential or important entity.
  2. Register (or update data): ensure your organisation is correctly registered with the competent cybersecurity authority and that all mandatory data (including cross-border service locations) is up to date.
  3. Classify systems: perform the required classification of electronic information systems, using the national security classes and templates referenced in the Cybersecurity Act and related decrees.
  4. Contract an auditor: select a registered cybersecurity auditor, sign the mandatory audit contract and plan your audit timeline so you meet statutory deadlines.
  5. Strengthen risk management: implement or enhance controls in line with recognised frameworks (ISO 27001 / NIST CSF / IEC 62443, etc.), covering IT and OT systems where applicable.
  6. Build incident readiness: set up monitoring, escalation and incident response processes that meet Hungarian incident reporting timelines to NCSC Hungary.
  7. Budget for supervisory fees: factor the cybersecurity supervisory fee and audit costs into your compliance budget and establish internal ownership for payments and declarations.
  8. Train leadership & staff: brief executives on their responsibilities (including potential personal liability) and roll out regular awareness training and exercises.

Operating in more than one EU country?

DNS service providers, TLD name registries, cloud computing, data centre and content delivery network providers, managed service and managed security service providers, and online marketplaces, search engines and social networking platforms answer to the regulator where their main establishment sits, rather than in every member state they serve. For most of those categories that is where cybersecurity risk-management decisions are predominantly taken.

For those same entity types, Implementing Regulation (EU) 2024/2690 applies directly. It is a regulation rather than a directive, so it is not transposed and reads identically in Hungary and everywhere else.

Two Hungarian deltas to plan around if Hungary is one of several markets: the mandatory external audit has no counterpart in most member states and needs an auditor from a Hungarian register, and the annual supervisory fee is a recurring cost that group budgeting usually misses — with a group-level cap of HUF 50 million that is worth checking against your structure. Compare with Austria, Slovakia, Poland and Romania.

Official links & resources

FAQ: NIS2 in Hungary

What law implements NIS2 in Hungary?
NIS2 is implemented mainly through Act LXIX of 2024 on the cybersecurity of Hungary, supported by Government Decree 418/2024 and several SZTFH decrees on audits and supervisory fees.
Who is the main NIS2 supervisory authority?
The primary supervisory authority is the Supervisory Authority of Regulated Activities (SZTFH), which oversees registration, audits, supervisory fees and most enforcement actions under the Cybersecurity Act.
Where do I report cybersecurity incidents?
To the national cybersecurity incident response centre (NKI), on the clock in Government Decree 418/2024: a first report within 24 hours of becoming aware, an incident report within 72 hours, and a final report within one month of the 72-hour report. Trust service providers report within 24 hours for incidents affecting their trust services.
Are cybersecurity audits really mandatory?
Yes, and the deadlines are specific. The auditor must be on the register kept under 7/2024. (VI. 24.) SZTFH decree. The agreement is due within 120 days of registration, and the first audit within two years of registration — except for entities already trading before 1 January 2025, whose agreement was due 31 August 2025 and whose first audit was due 30 June 2026. Missing the audit deadline carries a fine of HUF 1,000,000 – 50,000,000.
How much is the cybersecurity supervisory fee?
At most 0.015% of your previous business year's net revenue, capped at HUF 10,000,000 for a single entity and HUF 50,000,000 a year across a corporate group. It is rounded to HUF 1,000, and if the year's fee works out at less than HUF 5,000 it is not payable at all. SZTFH tells you the amount in your registration decision.
Do Hungarian rules go beyond the basic NIS2 requirements?
In several areas, yes — see “How Hungary differs” above. The mandatory external audit, the annual supervisory fee, per-infringement fines with a statutory minimum, and personal liability that becomes mandatory on a repeat breach are all national additions. The Directive sets ceilings only; Hungary sets floors from HUF 50,000 to HUF 1,000,000 depending on the breach.

Sources & verification

Every date and figure on this page comes from the consolidated Hungarian legislation or from SZTFH's own published obligations. Law-firm and vendor summaries were used to decide what to check, never as authority — which mattered here more than usual, because they contradict each other on almost every deadline.

SourceUsed forChecked
Act LXIX of 2024 (Kiberbiztonsági tv.), consolidated text Entry into force, scope and size thresholds, the delegation of fine-setting to government decree, the supervisory fee formula and caps, Section 35(1), and the 29 July 2026 currency of the consolidation 4 August 2026
Government Decree 418/2024 (Kiberbiztonsági vhr.), consolidated text The full incident-reporting clock, the response duty on the incident centre, and the Annex 2 fine table with minimum and maximum amounts 4 August 2026
SZTFH — cybersecurity supervision The 30-day registration deadline, the 120-day auditor agreement rule, the two-year audit rule, and the 31 August 2025 and 30 June 2026 dates for entities trading before 1 January 2025, each keyed to its provision 4 August 2026
SZTFH — cybersecurity supervisory fee Rounding to HUF 1,000, the HUF 5,000 threshold below which no fee is payable, and how SZTFH notifies the amount 4 August 2026

What this page deliberately does not state

  • A number for how many organisations are in scope. Figures around 5,000–6,000 circulate in advisory commentary. We have found no official count and would rather print nothing than a number that gets quoted back.
  • A sectoral authority map. This page previously listed “sector-specific regulators and ministries” and some third-party guides name the central bank and the data protection authority as NIS2 sector regulators for Hungary. The Act assigns cybersecurity supervision to SZTFH for the relevant categories and expressly excludes defence-purpose systems. The unverified claims have been removed rather than repeated.
  • What the 29 July 2026 amendment changed. The consolidated text's own validity header shows the Act was amended with effect from that date, and that a further version is dated 1 January 2027. Identifying the substance of those changes needs a clause-by-clause comparison that this review has not done, so the page records only that the amendment exists.
  • Any enforcement activity. No published SZTFH fines under this regime were found.
  • A correction worth recording: until this update, this page stated that the first mandatory audit was due 31 December 2025. That was wrong. The deadline for entities trading before 1 January 2025 was 30 June 2026, under Section 89(2) of the Act, as published by SZTFH. Two of the three most visible English-language guides still print the older, incorrect date.
Information provided for general guidance; consult Act LXIX of 2024 and Government Decree 418/2024 as published in the Nemzeti Jogszabálytár, the SZTFH decrees and guidance, and Hungarian legal counsel, for definitive NIS2 compliance requirements in Hungary.