NIS2 Hungary: Mandatory Audits, SZTFH Fines & the Supervisory Fee
Hungary implemented the NIS2 Directive through the Cybersecurity Act (2024. évi LXIX. törvény), in force since 1 January 2025, with the operative detail in Government Decree 418/2024. Hungary is one of the few member states to require a mandatory independent cybersecurity audit and to charge an annual supervisory fee — and the first audit deadline for established entities was 30 June 2026.
Introduction: NIS2 Directive & the Hungarian context
Hungary moved from a fragmented cybersecurity framework to a single Cybersecurity Act that implements the NIS2 Directive and extends obligations to a wide range of public and private entities. If you operate critical or important services in Hungary, you are subject to registration, audit and incident-reporting rules that go beyond what the Directive itself requires.
Two features make Hungary unusual. It requires a mandatory independent cybersecurity audit by an auditor on the SZTFH register, and it charges an annual cybersecurity supervisory fee. Neither appears in the Directive. A third point matters more than either: the Act itself sets almost no numbers — the fine amounts and the incident-reporting clock are in Government Decree 418/2024, so a reading of the Act alone tells you very little about what you actually owe.
What you must do in Hungary
Five duties. Two of the deadlines have already passed, which makes this the most time-sensitive country page on this site — if you are established in Hungary and have not done the first two, you are already exposed to a fine with a statutory minimum.
- Register with SZTFH within 30 days of starting operations or of coming within the scope of the Act. Registration is by data submission; failure to submit carries a fine from HUF 200,000, and supplying it late from HUF 50,000.
- Conclude a written agreement with a registered cybersecurity auditor. For entities registered after the Act took effect, within 120 days of registration. For entities already trading before 1 January 2025, the deadline was 31 August 2025 and has passed. Failure carries HUF 1,000,000 – 15,000,000.
- Complete the first cybersecurity audit. Within two years of registration — but for entities already trading before 1 January 2025 the deadline was 30 June 2026, which has now passed. Failure carries HUF 1,000,000 – 50,000,000.
- Pay the annual cybersecurity supervisory fee. SZTFH tells you the amount in your registration decision. Non-payment carries a minimum of HUF 500,000 and a maximum of ten times the annual fee.
- Report significant incidents on the 24-hour / 72-hour / one-month clock to the national incident response centre. The detail is in Decree 418/2024 and is set out below.
NIS2 Directive implementation in Hungary
Hungary first implemented NIS2 through Act XXIII of 2023 on cybersecurity certification and cybersecurity supervision. That was replaced and consolidated by Act LXIX of 2024 on the cybersecurity of Hungary (2024. évi LXIX. törvény, the “Cybersecurity Act”), in force since 1 January 2025, with detailed rules in Government Decree 418/2024.
The dates on this page are taken from SZTFH's own published obligations, keyed to the provisions they come from.
Status
Transposed and fully operational. The Cybersecurity Act has applied since 1 January 2025 and the consolidated text is current to 29 July 2026, with a further version dated 1 January 2027 — the Act is still being amended.
Where the numbers actually live
The Act delegates rather than specifies: it repeatedly refers to a fine “of the amount determined by government decree”. Government Decree 418/2024 carries the fine table and the incident-reporting clock. The only figure in the Act itself is Section 35(1) — HUF 1–5 million for an electronic communications provider.
The three SZTFH decrees
7/2024. (VI. 24.) — the auditor register and the requirements auditors must meet. 1/2025. (I. 31.) — how the cybersecurity audit is conducted and the maximum audit fee. 2/2025. (I. 31.) — the cybersecurity supervisory fee.
The Act covers high-risk and at-risk sectors closely aligned to Annexes I and II of the Directive, and extends obligations to organisations supporting critical state and municipal functions. Defence-purpose electronic information systems are excluded from SZTFH supervision.
Am I in scope in Hungary?
Hungary applies the Directive's sector and size tests, using its own vocabulary of “high-risk” and “at-risk” sectors, and then extends the regime into the public sector.
| Test | Threshold |
|---|---|
| Sector | Listed as a high-risk sector (Annex 1 to the Act, aligned to Directive Annex I) or an at-risk sector (Annex 2, aligned to Annex II). |
| Size | 50 or more employees, or annual net revenue or budget revenue appropriation above the forint equivalent of EUR 10 million — and, for entities required to prepare statutory accounts, a balance-sheet total above the same figure. |
| Regardless of size | Certain provider types are in scope whatever their size, including electronic communications providers, trust service providers, DNS service providers and domain name registries. |
| Public sector | Public bodies operating electronic information systems supporting critical state and municipal functions, with their own duties for information security officers and system classification. |
| Excluded | Defence-purpose electronic information systems fall outside SZTFH's cybersecurity supervision. |
Hungary also requires in-scope entities to classify each electronic information system into a security class, and the required controls follow from that classification rather than being uniform across the organisation. Getting the classification wrong changes the whole control set, so it is the first substantive piece of work, not an administrative afterthought.
NIS2 Hungary: what you need to know about compliance & audits
Hungary combines NIS2’s “essential / important” model with national classifications of “high-risk” and “at-risk” sectors, backed by mandatory audits and supervisory fees.
The supervisory fee, in figures
- At most 0.015% of the previous business year's net revenue or budget revenue appropriation.
- Capped at HUF 10,000,000 for a single entity.
- Group cap of HUF 50,000,000 a year across a recognised corporate group, an actual corporate group under the Civil Code, or a consolidation group.
- Calculated, paid and accounted for rounded to HUF 1,000.
- If the year's fee comes to less than HUF 5,000, nothing is payable.
Core obligations
- Classify each electronic information system into a security class and apply the controls that follow from it.
- Register with SZTFH within 30 days, and notify any change of data — failure to notify a change is itself a fineable breach (HUF 50,000 – 1,000,000).
- Register your information security officer and your information security policy with the authority; each omission carries HUF 200,000 – 2,000,000.
- Conclude an agreement with an auditor on the SZTFH register, and complete the audit within the statutory period.
- Report significant incidents on the 24-hour / 72-hour / one-month clock in Decree 418/2024.
- Pay the annual cybersecurity supervisory fee.
- Submit a vulnerability management plan, evidence of cybersecurity training, and an evaluation report after cybersecurity exercises — each has its own fine range.
Standards & certification
The Act does not mandate a single standard (such as ISO/IEC 27001), but allows regulators to require use of ICT products and services certified under Hungarian or European cybersecurity certification schemes. Aligning with recognised frameworks (ISO 27001, NIST CSF, IEC 62443, etc.) is strongly advised.
Registration and the audit obligation
Hungary's distinctive requirement is the mandatory independent cybersecurity audit. Very few member states require one. It has its own contract deadline, its own completion deadline, its own register of eligible auditors and its own fine range — and both of the deadlines for established entities have now passed.
| Duty | Deadline | Provision |
|---|---|---|
| Register with SZTFH | 30 days from starting operations or coming within scope | Cybersecurity Act |
| Agreement with a registered auditor | 120 days from registration | Section 16(2)(a) |
| Agreement with an auditor — entities trading before 1 Jan 2025 | 31 August 2025 — passed | Section 89(1a) |
| Complete the first cybersecurity audit | Two years from registration | Section 16(1) |
| First audit — entities trading before 1 Jan 2025 | 30 June 2026 — passed | Section 89(2) |
| Hungarian | What it means |
|---|---|
| Kiberbiztonsági tv. | The Cybersecurity Act, Act LXIX of 2024 |
| nyilvántartásba vétel | Registration with the authority |
| bírság | Administrative fine |
| felügyeleti díj | The annual supervisory fee |
| elektronikus információs rendszer | Electronic information system — the unit that gets security-classified |
| eseménybejelentés | The 72-hour incident report |
| zárójelentés | The final report, due within one month |
| dias equivalents | Hungarian deadlines here are calendar days unless the source says otherwise |
The Act, the decree and the SZTFH decrees are published in Hungarian. There is no official English translation, so the Hungarian text governs.
Incident reporting in Hungary
The clock is in Government Decree 418/2024, not in the Act. It follows the Directive's shape, and adds one obligation that runs in the other direction.
| Stage | Deadline |
|---|---|
| First report (első bejelentés) | Without undue delay, and in every case within 24 hours of becoming aware of the incident |
| Incident report (eseménybejelentés) | Without undue delay, and in every case within 72 hours, updating the first report and giving an initial assessment of severity and impact |
| Final report (zárójelentés) | Within one month of submitting the 72-hour report |
| Trust service providers | Within 24 hours of becoming aware, for incidents affecting the trust services they provide |
Failing to produce the final report, or producing an inadequate one, carries HUF 500,000 – 5,000,000. Failing to cooperate with the incident response centre, or to carry out an ordered vulnerability assessment or incident investigation, carries HUF 500,000 – 50,000,000.
National NIS2 timeline & key dates (Hungary)
Sector-specific requirements (Hungary)
- High-risk sectors: energy, transport, banking and financial market infrastructures, health, drinking water, wastewater, digital infrastructure and ICT service management, public administration and others broadly aligned with NIS2 Annex I.
- At-risk sectors: postal and courier services, waste management, food production and distribution, manufacturing of key products (e.g. medical devices, pharmaceuticals, electronics), and certain digital services, reflecting Annex II of NIS2.
- State & municipal bodies: the Cybersecurity Act also captures many public bodies that operate critical electronic information systems, with specific duties for information security officers and system classification.
How Hungary differs from the NIS2 Directive
Hungary is one of the more demanding transpositions in the EU, and the differences are structural rather than cosmetic. If you are running a multi-country programme built on the Directive, these are the gaps.
- A mandatory independent audit. The Directive requires risk management; Hungary requires an external cybersecurity audit by an auditor on a state register, on a statutory deadline, with its own fine range. Very few member states do this.
- An annual supervisory fee. Up to 0.015% of net revenue, capped at HUF 10 million per entity and HUF 50 million per group. The Directive contains nothing comparable, and this is a recurring budget line rather than a one-off compliance cost.
- Statutory minimum fines, per infringement. The Directive sets ceilings. Decree 418/2024 sets a floor and a ceiling for each of more than twenty separately-named breaches — from HUF 50,000 for a late data change up to HUF 150,000,000.
- Mandatory personal liability on repeat. Where the head of the organisation fails to meet a statutory duty, the authority may impose a fine of up to HUF 15,000,000 — and on a repeat breach it must. The discretion disappears the second time.
- Security classification drives the controls. Rather than one control set for the organisation, each electronic information system is classified and the required measures follow from that class. The classification is the compliance decision.
Penalties, fine ranges and personal liability
The Cybersecurity Act sets almost no amounts — it delegates them to government decree. The operative figures are in Annex 2 to Government Decree 418/2024, which names more than twenty separate breaches and gives each one a minimum and a maximum in forint. Annex 3 carries a separate scale for other categories of organisation. Below are the ranges most entities will care about.
The overall ceilings
- Essential entities: the forint equivalent of EUR 10 million or 2% of total global annual turnover in the previous financial year, whichever is higher.
- Important entities: the forint equivalent of EUR 7 million or 1.4% of global annual turnover, whichever is higher.
- Euro amounts are converted at the Magyar Nemzeti Bank rate on the day the fine decision is made, not at the date of the breach.
The per-breach table — Decree 418/2024, Annex 2
| Infringement | Minimum | Maximum |
|---|---|---|
| Failure to supply the data required for registration | HUF 200,000 | HUF 2,000,000 |
| Failure to apply to register the information security officer | HUF 200,000 | HUF 2,000,000 |
| Failure to apply to register the information security policy | HUF 200,000 | HUF 2,000,000 |
| Failure to notify a change of registered data | HUF 50,000 | HUF 1,000,000 |
| Registration data supplied late (essential / important entity) | HUF 50,000 | 0.1% of net revenue, max HUF 15,000,000 |
| Registration data not supplied at all (essential / important entity) | 0.5% of net revenue, min HUF 1,000,000 | 2% of net revenue, max HUF 150,000,000 |
| Failure to pay the supervisory fee | HUF 500,000 | Ten times the annual supervisory fee |
| Failure to conclude the auditor agreement on time | HUF 1,000,000 | HUF 15,000,000 |
| Failure to complete the cybersecurity audit on time | HUF 1,000,000 | HUF 50,000,000 |
| Non-compliance with a final, enforceable decision of the authority | HUF 1,000,000 | HUF 50,000,000 |
| Failure to cooperate with the information security supervisor | HUF 1,000,000 | HUF 40,000,000 |
| Failure to inform service users when ordered to | HUF 2,000,000 | HUF 20,000,000 |
| Failure to submit the vulnerability management plan | HUF 200,000 | HUF 10,000,000 |
| Failure to submit the cybersecurity exercise evaluation report | HUF 200,000 | HUF 4,000,000 |
| No certificate evidencing cybersecurity training | HUF 200,000 | HUF 4,000,000 |
| Failure to cooperate with the incident response centre | HUF 500,000 | HUF 50,000,000 |
| Failure to carry out an ordered vulnerability assessment or incident investigation | HUF 500,000 | HUF 50,000,000 |
| Final report missing or inadequate | HUF 500,000 | HUF 5,000,000 |
| Breach of an intermediary provider's cooperation duty | HUF 1,000,000 | HUF 40,000,000 |
Electronic communications providers have their own tier in the Act itself: HUF 1,000,000 – 5,000,000 under Section 35(1), repeatable after a further deadline passes without compliance.
How to prepare for NIS2 in Hungary
- Confirm scope: map your services and electronic information systems against the high-risk and at-risk sector lists and determine whether you are an essential or important entity.
- Register (or update data): ensure your organisation is correctly registered with the competent cybersecurity authority and that all mandatory data (including cross-border service locations) is up to date.
- Classify systems: perform the required classification of electronic information systems, using the national security classes and templates referenced in the Cybersecurity Act and related decrees.
- Contract an auditor: select a registered cybersecurity auditor, sign the mandatory audit contract and plan your audit timeline so you meet statutory deadlines.
- Strengthen risk management: implement or enhance controls in line with recognised frameworks (ISO 27001 / NIST CSF / IEC 62443, etc.), covering IT and OT systems where applicable.
- Build incident readiness: set up monitoring, escalation and incident response processes that meet Hungarian incident reporting timelines to NCSC Hungary.
- Budget for supervisory fees: factor the cybersecurity supervisory fee and audit costs into your compliance budget and establish internal ownership for payments and declarations.
- Train leadership & staff: brief executives on their responsibilities (including potential personal liability) and roll out regular awareness training and exercises.
Operating in more than one EU country?
DNS service providers, TLD name registries, cloud computing, data centre and content delivery network providers, managed service and managed security service providers, and online marketplaces, search engines and social networking platforms answer to the regulator where their main establishment sits, rather than in every member state they serve. For most of those categories that is where cybersecurity risk-management decisions are predominantly taken.
For those same entity types, Implementing Regulation (EU) 2024/2690 applies directly. It is a regulation rather than a directive, so it is not transposed and reads identically in Hungary and everywhere else.
Two Hungarian deltas to plan around if Hungary is one of several markets: the mandatory external audit has no counterpart in most member states and needs an auditor from a Hungarian register, and the annual supervisory fee is a recurring cost that group budgeting usually misses — with a group-level cap of HUF 50 million that is worth checking against your structure. Compare with Austria, Slovakia, Poland and Romania.
Official links & resources
FAQ: NIS2 in Hungary
What law implements NIS2 in Hungary?
Who is the main NIS2 supervisory authority?
Where do I report cybersecurity incidents?
Are cybersecurity audits really mandatory?
How much is the cybersecurity supervisory fee?
Do Hungarian rules go beyond the basic NIS2 requirements?
Sources & verification
Every date and figure on this page comes from the consolidated Hungarian legislation or from SZTFH's own published obligations. Law-firm and vendor summaries were used to decide what to check, never as authority — which mattered here more than usual, because they contradict each other on almost every deadline.
| Source | Used for | Checked |
|---|---|---|
| Act LXIX of 2024 (Kiberbiztonsági tv.), consolidated text | Entry into force, scope and size thresholds, the delegation of fine-setting to government decree, the supervisory fee formula and caps, Section 35(1), and the 29 July 2026 currency of the consolidation | 4 August 2026 |
| Government Decree 418/2024 (Kiberbiztonsági vhr.), consolidated text | The full incident-reporting clock, the response duty on the incident centre, and the Annex 2 fine table with minimum and maximum amounts | 4 August 2026 |
| SZTFH — cybersecurity supervision | The 30-day registration deadline, the 120-day auditor agreement rule, the two-year audit rule, and the 31 August 2025 and 30 June 2026 dates for entities trading before 1 January 2025, each keyed to its provision | 4 August 2026 |
| SZTFH — cybersecurity supervisory fee | Rounding to HUF 1,000, the HUF 5,000 threshold below which no fee is payable, and how SZTFH notifies the amount | 4 August 2026 |
What this page deliberately does not state
- A number for how many organisations are in scope. Figures around 5,000–6,000 circulate in advisory commentary. We have found no official count and would rather print nothing than a number that gets quoted back.
- A sectoral authority map. This page previously listed “sector-specific regulators and ministries” and some third-party guides name the central bank and the data protection authority as NIS2 sector regulators for Hungary. The Act assigns cybersecurity supervision to SZTFH for the relevant categories and expressly excludes defence-purpose systems. The unverified claims have been removed rather than repeated.
- What the 29 July 2026 amendment changed. The consolidated text's own validity header shows the Act was amended with effect from that date, and that a further version is dated 1 January 2027. Identifying the substance of those changes needs a clause-by-clause comparison that this review has not done, so the page records only that the amendment exists.
- Any enforcement activity. No published SZTFH fines under this regime were found.
- A correction worth recording: until this update, this page stated that the first mandatory audit was due 31 December 2025. That was wrong. The deadline for entities trading before 1 January 2025 was 30 June 2026, under Section 89(2) of the Act, as published by SZTFH. Two of the three most visible English-language guides still print the older, incorrect date.
