NIS2 · National implementation
NIS2 in Hungary
Hungary transposed NIS2 through Act LXIX of 2024 on Hungary's Cybersecurity, consolidating earlier acts, in force since 1 January 2025 (building on Act XXIII of 2023 which had front-run parts of NIS2).
- National law
- 2024. évi LXIX. törvény
- Act LXIX of 2024 on Hungary's Cybersecurity
- Status
- In force
- In force
- 1 January 2025
- Authority
- SZTFH
Supervision
The SZTFH (Szabályozott Tevékenységek Felügyeleti Hatósága, Supervisory Authority for Regulated Activities) supervises most in-scope entities — an unusual choice, as it is a general regulated-industries authority. National CSIRT functions sit with NKI.
What is specific to Hungary
Hungary's regime is notably audit-driven: in-scope entities must contract a registered cybersecurity auditor and pass audits on a fixed cycle, pay supervision fees, and classify systems into security classes with measures per class set in implementing decrees. This makes Hungarian compliance more prescriptive and more externally verified than the directive baseline.
NIS2 in Hungary: frequently asked questions
Last reviewed:
Related reading
Definitions
