We help you get ready for NIS2 in Hungary

Hungary transposed NIS2 as Act LXIX of 2024, and the SZTFH audit obligation is live.

Audit41 Readiness assesses you against the Hungarian requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.

Check your Hungary NIS2 scope
  1. 1

    Registration

    18 October 2024

  2. 2

    Measures

    18 October 2024

  3. 3

    Audit

    30 June 2026

Every 2 years

Which tier are you?

Essential entity

Organisations whose service is critical to the state, society, or the economy, and larger organisations by the size thresholds in the law.

Penalties

Up to the higher statutory maximum, with proactive supervision. Authorities can audit at any time.

Important entity

Organisations in a covered sector that do not meet the essential threshold but still fall in scope.

Penalties

Up to the lower statutory maximum, with reactive supervision. Investigated when non-compliance is indicated.

Your obligations under Act LXIX of 2024

1

Register with the SZTFH cybersecurity register as an essential or important entity.

2

Contract an SZTFH-accredited auditor within the statutory window after registration.

3

Implement the technical security controls Hungary mandates.

4

Classify your systems into the basic, significant, or high security class and apply the controls each class requires.

5

Complete the first mandatory cybersecurity audit by an SZTFH-accredited auditor.

6

Submit an action plan for any gaps the audit finds, within the deadline set after the audit.

7

Report significant incidents to the national cybersecurity authority under the statutory timelines.

8

Repeat the audit on the recurring cycle the law sets.

Hungary uses NIST SP 800-53 rev.5 as its technical control framework, not ISO 27001. An ISO 27001 certification demonstrates mature security management, but it does not replace the mandatory SZTFH-accredited audit or the mandated controls.

Sectors in scope

EnergyTransportBankingFinancial market infrastructureHealthDrinking waterWaste waterDigital infrastructureICT service managementPublic administrationSpacePostal and courier servicesWaste managementChemicalsFoodManufacturingDigital providersResearch

Finance is supervised by the MNB, not the SZTFH

Financial entities fall under the Magyar Nemzeti Bank as sector regulator, not the SZTFH cybersecurity authority. If you are a bank or financial institution, your supervision path differs.

Three security classes, not one standard

Hungary classifies systems into basic, significant, and high security classes. Your obligations scale with the class, so classification is the first thing that determines your workload.

Auditors must be on the SZTFH register

Only auditors listed in the SZTFH register of accredited cybersecurity auditors can perform your mandatory audit. Contracting an unlisted auditor does not satisfy the obligation.

We had less than 100 days to the SZTFH audit and no idea where we stood. Within a week Audit41 Readiness gave us a control-by-control gap report. Our auditor was impressed we arrived with evidence already in hand.

Z.F., CISO

Logistics company, Hungary

From gap report to audit-ready

Between registering and passing the audit, most organisations reach for a consultant. Audit41 Readiness assesses you against the controls Hungary requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Page one of an Audit41 Readiness Assessment Report, showing a readiness score, the four band scale, a control breakdown, and the top critical gaps and priority actions.

Know where you stand on NIS2 in Hungary

The free self-check applies the Hungarian rules, tells you your entity type, and recommends the right assessment.

Check your Hungary NIS2 scope

This self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.