NIS2 Compliance in Hungary: An Executive Guide (2026)
NIS2 is the EU's cybersecurity directive. In Hungary it is already in force through Act LXIX of 2024 (effective 1 January 2025), supervised by SZTFH. In-scope "essential" and "important" entities must register, implement risk-management measures, and meet strict incident-reporting deadlines (24…
On this page
- Why this matters to you
- What is NIS2?
- NIS2 in Hungary: the national legal position
- Core NIS2 obligations
- 1. Registration with SZTFH
- 2. Risk-management measures
- 3. Incident reporting — the deadlines
- 4. Management responsibility
- What this means in practice — a NIS2 preparation path
- Risk and opportunity
- How Regcytech helps
- FAQ
- Related content
TL;DR: NIS2 is the EU's cybersecurity directive. In Hungary it is already in force through Act LXIX of 2024 (effective 1 January 2025), supervised by SZTFH. In-scope "essential" and "important" entities must register, implement risk-management measures, and meet strict incident-reporting deadlines (24 hours – 72 hours – 1 month). Non-compliance can lead to fines and supervisory action, and management responsibility is explicitly named.
Why this matters to you
If your company operates in energy, transport, healthcare, digital infrastructure, manufacturing, waste management, food, or public-sector supply, it is likely in scope of NIS2 — often falling under cybersecurity regulation for the first time. The question is no longer "does it apply?" but "where are we on compliance?" This guide summarises, from an executive perspective, what NIS2 means in practice and how to prepare in a structured way.
What is NIS2?
🔴 Legal requirement. NIS2 (Network and Information Security 2, Directive (EU) 2022/2555) is the EU's harmonised cybersecurity framework. It broadens the sectors in scope, standardises the minimum requirements for cyber risk management, and introduces strict incident-reporting deadlines. Its goal is to make organisations providing critical and important services more resilient to cyberattacks.
NIS2 distinguishes two categories:
- Essential entities — stricter, proactive supervision.
- Important entities — reactive (ex-post) supervision.
Classification depends on the sector, company size, and the criticality of the service.
NIS2 in Hungary: the national legal position
🔴 Legal requirement. Hungary has transposed NIS2: Act LXIX of 2024 on Cybersecurity entered into force on 1 January 2025, replacing the earlier partial transposition (Act XXIII of 2023). The supervisory authority is the Regulated Activities Supervisory Authority (SZTFH).
Two January 2025 SZTFH decrees clarify the practical framework:
- SZTFH Decree 1/2025 — procedures for cybersecurity audits and maximum audit fees.
- SZTFH Decree 2/2025 — the annual cybersecurity supervision fee.
🟡 Recommendation / context. In mid-2025, further legislation (Act XXXII of 2025) addressed technical cybersecurity controls following the logic of NIST SP 800-53. Detailed technical expectations should be read together with the latest SZTFH guidance.
Flagged review item: specific entity-classification thresholds and technical control details should be finalised against current SZTFH guidance before publication.
Core NIS2 obligations
1. Registration with SZTFH
🔴 In-scope entities must register electronically in the SZTFH system, providing a contact, the relevant sector, and the EU Member States where they provide services.
2. Risk-management measures
🔴 NIS2 requires risk-based, proportionate measures, including: risk analysis and information-security policy, incident handling, business continuity and backup, supply-chain security, access control and multi-factor authentication (MFA), encryption, and measuring the effectiveness of controls. The detailed control framework is covered in our ISO 27001 & Governance Frameworks(HU) article.
3. Incident reporting — the deadlines
🔴 Significant incidents must be reported in stages:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | within 24 hours | suspicion, whether malicious, cross-border impact |
| Incident notification | within 72 hours | initial assessment, severity, indicators |
| Final report | within 1 month | detailed description, cause, mitigation |
Practical steps are covered in Incident Response & Business Continuity(HU).
🟡 Recommendation — when is an incident "significant"? For a narrower set of digital providers, CIR (EU) 2024/2690 provides concrete thresholds (e.g. damage above EUR 500,000 or 5% of annual turnover, exfiltration of trade secrets). In most sectors, however, "significant" is qualitative — which is why an internal incident-classification policy matters.
Flagged review item: CIR (EU) 2024/2690 entity-specific thresholds to be clarified in the final article; they are not generalisable across all sectors.
4. Management responsibility
🔴 NIS2 names management responsibility: leadership must approve and oversee cybersecurity measures and undertake training. This ties governance directly to cybersecurity.
What this means in practice — a NIS2 preparation path
- Clarify scope — is the company in scope, and as an essential or important entity?
- Register with SZTFH by the deadline.
- Gap analysis — where do we stand versus the risk-management measures?
- Implement risk-management measures — MFA, backup, access control, supply-chain risk.
- Build and rehearse an incident-response and continuity plan.
- Documentation and evidence — policies, records, measurement.
- Audit readiness and continuous review.
Risk and opportunity
Risk: fines and supervisory action, operational disruption during a real incident, and exclusion from the supply chain if a large customer requires NIS2 compliance. Opportunity: structured cybersecurity reduces real incident damage, gives an edge in public procurement and enterprise supplier relationships, and builds demonstrable trust.
How Regcytech helps
Regcytech supports NIS2 scope assessment, gap analysis, the design of risk-management measures and required documentation, and preparation for SZTFH registration and audit. (Regcytech is not a law firm and not a certification body — we provide preparation and documentation, not legal guarantees or certification.)
FAQ
Who does NIS2 apply to in Hungary? Organisations in in-scope sectors (energy, healthcare, digital infrastructure, manufacturing, public-sector supply, etc.) meeting defined size thresholds, as "essential" or "important" entities. Exact classification is determined by the SZTFH framework.
How much time is there to report an incident? Early warning within 24 hours, incident notification within 72 hours, final report within 1 month.
Do we need to register with SZTFH? Yes, in-scope entities must register electronically.
What is the difference between NIS and NIS2? NIS2 expands the sectors in scope, tightens risk-management and reporting requirements, and introduces management responsibility.
Related content
Trust signals
- Expert reviewed — Regcytech
- Last reviewed:
- Next review:
- Regulatory / standard status: Current within the stated review window.
- Related service: NIS2 readiness
- Related analysis: An AI Governance Framework for Leaders: Governing Responsible AI
- Related knowledge article: Cybersecurity Essentials for Hungarian SMEs
- Author
- Regcytech
- Editorial status
- Published
- Update cycle
- monthly
- Last reviewed
- Next review
Sources
- Directive (EU) 2022/2555 (NIS2) – EUR-Lex
- Commission Implementing Regulation (EU) 2024/2690 – EUR-Lex
- Act LXIX of 2024 on Cybersecurity; SZTFH Decrees 1/2025 and 2/2025 – SZTFH
- ENISA – cybersecurity guidance
This content is general information and does not constitute legal advice. Regcytech Kft. is not a law firm, accredited auditor, or certification body. Seek professional advice for specific matters.
Related services
Related knowledge
Related analysis
NEXT STEP
NIS2 quick assessment
A few questions show where your NIS2 readiness likely stands — and the most useful next step.
Start NIS2 assessment