Skip to main content
NIS2 · HUNGARY

NIS2 in Hungary — an audit-first regime, statutory deadlines in days, and SZTFH.

Hungary's Act LXIX of 2024 entered into force on 1 January 2025 — one of the earliest in-force transpositions — enforced by the Supervisory Authority for Regulatory Affairs (SZTFH), a broader regulatory body rather than a dedicated cyber agency. Its deadlines run in days, not months: newly in-scope entities register within 30 days, and essential entities must contract a certified cybersecurity auditor within 120 days.

That auditor contract is the regime's signature: Hungary front-loads independent assurance, pairing it with a statutory audit cadence — the first audit round for entities registered at the start fell at the end of 2025. The message is structural: evidence of working controls, examined by an outside auditor, is not an annual afterthought but the mechanism the law is built around.

Who it applies to

Essential and important entities across the NIS2 sectors, registering with SZTFH within 30 days of entering scope, with essential entities contracting a certified auditor within 120 days and auditing on the statutory cadence thereafter. Incident reporting runs the directive's three stages: 24 hours, 72 hours, one month.

The clock

Competent authority: SZTFH (Supervisory Authority for Regulatory Affairs). Transposition: Act LXIX of 2024 (Cybersecurity Act).

NIS2 in Hungary · timeline
WhenWhat happens
1 Jan 2025Act LXIX of 2024 enters into force
Within 30 days of scopeRegistration with SZTFH
Within 120 daysEssential entities contract a certified cybersecurity auditor
31 Dec 2025First audit round closes for entities registered at the start

The auditor is not optional, and the clock is short

Hungary's regime is audit-first: the law does not merely ask for controls, it asks for an independent, certified auditor under contract within 120 days of an essential entity entering scope, with audits on a statutory cadence thereafter. Combined with 30-day registration, a newly in-scope Hungarian entity faces the tightest early deadlines in the Union — auditor selection included. TruSecure treats the auditor relationship as a tracked fact on the entity (contracted, deadline, next audit) and assembles the evidence the auditor will sample continuously, so the audit is a review of living records rather than a document hunt.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Hungary transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Hungary requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with SZTFH within 30 days of scopeEntity profile · scope-entry date and 30-day clock as records
Contract a certified auditor within 120 daysGovernance workspace · auditor contracted, deadline and cadence tracked
Operate controls with continuous evidenceControl library · evidence collected continuously for audit sampling
Report incidents: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Keep risk documentation current between auditsLiving documentation · change detection triggers updates

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Hungary NIS2 readiness file · excerptSample data
SZTFH registration
filed · day 19 of 30
Auditor contract
certified auditor · signed day 84 of 120
Next audit
scheduled · evidence current, not assembled
Controls evidenced
72/96 · 24 open, each with an owner and a date
Export
sealed · sha256:6e9c...3f1a

Where teams usually start

With a demo walked through by TruSecure — your scope-entry clocks computed, the auditor-contract obligation tracked, and the evidence an auditor samples shown as living records. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Hungary by SZTFH (Supervisory Authority for Regulatory Affairs). TruSecure determines applicability against Hungary's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Why does a regulatory affairs authority enforce cybersecurity in Hungary?
Hungary's 2024 Cybersecurity Act placed NIS2 enforcement inside SZTFH, a broader supervisory authority for regulatory affairs, rather than creating a standalone cyber agency — one of the few member states to take this approach.