NIS 2 Directive | Transposition in Hungary



12 March 2026 Update - The transposition of NIS 2 in Hungary

Hungary represents an interesting case in the European Union’s implementation of Directive (EU) 2022/2555, as the country adopted a two stage legislative approach and ultimately consolidated the transposition into a comprehensive national cybersecurity statute. Hungary enacted a new unified cybersecurity framework designed to integrate NIS 2 obligations across both the public and private sectors.

Before the adoption of the NIS 2 Directive, cybersecurity regulation in Hungary was primarily governed by the Information Security Act of 2013, which applied mainly to public administration and state-related systems. In addition, various sector specific rules governed cybersecurity requirements for critical infrastructure operators and digital service providers. This regulatory structure implemented the earlier NIS Directive but remained fragmented across different statutes and regulatory authorities.

Hungary began implementing the NIS 2 framework relatively early compared with many EU Member States. The first major legislative step occurred in May 2023, when the Hungarian Parliament adopted Act XXIII of 2023 on Cybersecurity Certification and Cybersecurity Supervision. This statute introduced the first elements of the national framework required by the directive and established supervisory mechanisms for cybersecurity certification and regulatory oversight.

Under this law, organizations falling within the scope of the new cybersecurity regime were required to register with the competent authority by 30 June 2024, initiating the operational implementation of the NIS 2 compliance framework in Hungary.

However, the 2023 legislation was widely viewed as only a partial implementation of the directive and left several structural issues unresolved.

A more significant reform occurred in December 2024, when Hungary adopted a new consolidated cybersecurity statute: Act LXIX of 2024 on the Cybersecurity of Hungary. This law is the primary legislative instrument implementing the NIS 2 Directive in Hungary. The statute replaced the earlier 2023 cybersecurity certification act and the 2013 information security law, thereby consolidating the national cybersecurity framework into a single legislative instrument.

The new act entered into force on 1 January 2025, marking the beginning of the fully integrated Hungarian NIS 2 regulatory regime.

The Hungarian transposition model is notable for its centralized and unified legislative structure. It did not maintain separate legal regimes for public sector information systems and private sector cybersecurity obligations. Hungary consolidated these frameworks into a single cybersecurity statute.

The law introduces the NIS 2 classification system distinguishing between essential entities and important entities, which must implement comprehensive cybersecurity risk management measures. The regulatory framework includes obligations relating to vulnerability management, incident detection, supply chain security, and organizational cybersecurity governance.

Another distinctive feature of the Hungarian approach is the integration of a national cybersecurity audit system. Entities falling within the scope of the law must conclude contracts with registered cybersecurity auditors and undergo periodic cybersecurity audits designed to verify compliance with the statutory requirements.

The supervisory structure under the Hungarian NIS 2 regime is centred on the Supervisory Authority for Regulatory Affairs (SZTFH), which exercises regulatory oversight over entities subject to the cybersecurity law.

Operational incident response is coordinated through the National Cyber Security Centre (NKI/NCSC Hungary), which serves as the national CSIRT and acts as the primary contact point for cybersecurity incident reporting and international cooperation within the European cybersecurity framework.

This institutional model combines centralized regulatory supervision with a national incident response authority responsible for operational cybersecurity coordination.

Following the adoption of Act LXIX of 2024, the Hungarian government adopted several implementing regulations in order to operationalize the new cybersecurity regime. In January 2025, two important decrees were issued by the supervisory authority governing cybersecurity audits and the annual cybersecurity supervisory fee applicable to regulated entities. These regulations define the procedural framework for cybersecurity audits and establish the financial contributions required from regulated organizations to support the supervisory system.

The Hungarian cybersecurity framework has continued to evolve after its entry into force. In January 2026, the government adopted amendments clarifying the size thresholds determining whether private-sector organizations fall within the scope of the Cybersecurity Act. These amendments exclude certain companies that qualify as large enterprises only because of their corporate group structure but do not independently meet the criteria for medium-sized enterprises. This adjustment illustrates the ongoing process of refining the regulatory scope as authorities gain practical experience with the new cybersecurity regime.

Despite the adoption of the legislation, Hungary was still included among the Member States receiving a reasoned opinion from the European Commission in May 2025 for failure to notify complete transposition measures, indicating that the Commission was still assessing whether the national implementation fully satisfied the requirements of the directive.

Hungarian National Legislation Database, Act LXIX of 2024 on the cybersecurity of Hungary

EU - Transposition, Member States