NIS2 in Hungary — an audit-first regime, statutory deadlines in days, and SZTFH.
Hungary's Act LXIX of 2024 entered into force on 1 January 2025 — one of the earliest in-force transpositions — enforced by the Supervisory Authority for Regulatory Affairs (SZTFH), a broader regulatory body rather than a dedicated cyber agency. Its deadlines run in days, not months: newly in-scope entities register within 30 days, and essential entities must contract a certified cybersecurity auditor within 120 days.
That auditor contract is the regime's signature: Hungary front-loads independent assurance, pairing it with a statutory audit cadence — the first audit round for entities registered at the start fell at the end of 2025. The message is structural: evidence of working controls, examined by an outside auditor, is not an annual afterthought but the mechanism the law is built around.
Who it applies to
Essential and important entities across the NIS2 sectors, registering with SZTFH within 30 days of entering scope, with essential entities contracting a certified auditor within 120 days and auditing on the statutory cadence thereafter. Incident reporting runs the directive's three stages: 24 hours, 72 hours, one month.
The clock
Competent authority: SZTFH (Supervisory Authority for Regulatory Affairs). Transposition: Act LXIX of 2024 (Cybersecurity Act).
| When | What happens |
|---|---|
| 1 Jan 2025 | Act LXIX of 2024 enters into force |
| Within 30 days of scope | Registration with SZTFH |
| Within 120 days | Essential entities contract a certified cybersecurity auditor |
| 31 Dec 2025 | First audit round closes for entities registered at the start |
The auditor is not optional, and the clock is short
Hungary's regime is audit-first: the law does not merely ask for controls, it asks for an independent, certified auditor under contract within 120 days of an essential entity entering scope, with audits on a statutory cadence thereafter. Combined with 30-day registration, a newly in-scope Hungarian entity faces the tightest early deadlines in the Union — auditor selection included. TruSecure treats the auditor relationship as a tracked fact on the entity (contracted, deadline, next audit) and assembles the evidence the auditor will sample continuously, so the audit is a review of living records rather than a document hunt.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Hungary transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with SZTFH within 30 days of scope | Entity profile · scope-entry date and 30-day clock as records |
| Contract a certified auditor within 120 days | Governance workspace · auditor contracted, deadline and cadence tracked |
| Operate controls with continuous evidence | Control library · evidence collected continuously for audit sampling |
| Report incidents: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Keep risk documentation current between audits | Living documentation · change detection triggers updates |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- SZTFH registration
- filed · day 19 of 30
- Auditor contract
- certified auditor · signed day 84 of 120
- Next audit
- scheduled · evidence current, not assembled
- Controls evidenced
- 72/96 · 24 open, each with an owner and a date
- Export
- sealed · sha256:6e9c...3f1a
Where teams usually start
With a demo walked through by TruSecure — your scope-entry clocks computed, the auditor-contract obligation tracked, and the evidence an auditor samples shown as living records. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Hungary by SZTFH (Supervisory Authority for Regulatory Affairs). TruSecure determines applicability against Hungary's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.