NIS2 · National implementation

NIS2 in Hungary

Hungary transposed NIS2 through Act LXIX of 2024 on Hungary's Cybersecurity, consolidating earlier acts, in force since 1 January 2025 (building on Act XXIII of 2023 which had front-run parts of NIS2).

National law
2024. évi LXIX. törvény
Act LXIX of 2024 on Hungary's Cybersecurity
Status
In force
In force
1 January 2025
Authority
SZTFH

Supervision

The SZTFH (Szabályozott Tevékenységek Felügyeleti Hatósága, Supervisory Authority for Regulated Activities) supervises most in-scope entities — an unusual choice, as it is a general regulated-industries authority. National CSIRT functions sit with NKI.

What is specific to Hungary

Hungary's regime is notably audit-driven: in-scope entities must contract a registered cybersecurity auditor and pass audits on a fixed cycle, pay supervision fees, and classify systems into security classes with measures per class set in implementing decrees. This makes Hungarian compliance more prescriptive and more externally verified than the directive baseline.

Official sources

Primary references: the national statute book at njt.hu and the national cybersecurity authority at sztfh.hu.

NIS2 in Hungary: frequently asked questions

Last reviewed:

Related reading

Definitions

All 27 EU member states