We help you get ready for NIS2 in Hungary
Hungary transposed NIS2 as Act LXIX of 2024, and the SZTFH audit obligation is live.
Audit41 Readiness assesses you against the Hungarian requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.
Check your Hungary NIS2 scope- 1
Registration
18 October 2024
- 2
Measures
18 October 2024
- 3
Audit
30 June 2026
Every 2 years
Which tier are you?
Organisations whose service is critical to the state, society, or the economy, and larger organisations by the size thresholds in the law.
Penalties
Up to the higher statutory maximum, with proactive supervision. Authorities can audit at any time.
Organisations in a covered sector that do not meet the essential threshold but still fall in scope.
Penalties
Up to the lower statutory maximum, with reactive supervision. Investigated when non-compliance is indicated.
Your obligations under Act LXIX of 2024
Register with the SZTFH cybersecurity register as an essential or important entity.
Contract an SZTFH-accredited auditor within the statutory window after registration.
Implement the technical security controls Hungary mandates.
Classify your systems into the basic, significant, or high security class and apply the controls each class requires.
Complete the first mandatory cybersecurity audit by an SZTFH-accredited auditor.
Submit an action plan for any gaps the audit finds, within the deadline set after the audit.
Report significant incidents to the national cybersecurity authority under the statutory timelines.
Repeat the audit on the recurring cycle the law sets.
Hungary uses NIST SP 800-53 rev.5 as its technical control framework, not ISO 27001. An ISO 27001 certification demonstrates mature security management, but it does not replace the mandatory SZTFH-accredited audit or the mandated controls.
Sectors in scope
Finance is supervised by the MNB, not the SZTFH
Financial entities fall under the Magyar Nemzeti Bank as sector regulator, not the SZTFH cybersecurity authority. If you are a bank or financial institution, your supervision path differs.
Three security classes, not one standard
Hungary classifies systems into basic, significant, and high security classes. Your obligations scale with the class, so classification is the first thing that determines your workload.
Auditors must be on the SZTFH register
Only auditors listed in the SZTFH register of accredited cybersecurity auditors can perform your mandatory audit. Contracting an unlisted auditor does not satisfy the obligation.
We had less than 100 days to the SZTFH audit and no idea where we stood. Within a week Audit41 Readiness gave us a control-by-control gap report. Our auditor was impressed we arrived with evidence already in hand.
Z.F., CISO
Logistics company, Hungary
From gap report to audit-ready
Between registering and passing the audit, most organisations reach for a consultant. Audit41 Readiness assesses you against the controls Hungary requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Know where you stand on NIS2 in Hungary
The free self-check applies the Hungarian rules, tells you your entity type, and recommends the right assessment.
Check your Hungary NIS2 scopeThis self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.