iGAMINGHOUSE
Breaking
Regulation

Hungary Completes First Cybersecurity Audits under NIS2

The SZTFH reports that over 2,100 organizations passed the cybersecurity audit required by June 2026; nearly 90% met the requirements and 10% received the highest rating.

By Miguel SandovalPublished Aug 26, 20263 min readEurope
Editorial representation of an auditor reviewing cybersecurity documents alongside the SZTFH logo and the Hungarian flag

Key Takeaways

  • The SZTFH reported that 2,194 organizations completed the cybersecurity audit before June 2026.
  • 90% of the audited entities met regulatory requirements, and 10% received the highest rating.
  • Audits respond to national transposition of the NIS2 Directive and will be mandatory every two years.
  • Only registered auditors can conduct the audits and must submit their reports to the SZTFH within 7 days.
  • Reviews revealed deficiencies in documentation despite widespread compliance with technical measures.

The Hungarian Authority for Regulated Activities (SZTFH) confirmed that 2,194 organizations completed their first cybersecurity audit before June 30, 2026. Almost 90% satisfactorily met the regulatory requirements, while approximately 10% received the highest rating, "Compliance with Negligible Risk." These results reflect the enforcement of legal harmonization derived from the NIS2 Directive of the European Parliament and Council.

Obligations under the NIS2 Cybersecurity Audit in Hungary

The NIS2 Directive imposes on member states the requirement to adopt strict cybersecurity policies. In Hungary, this regulation was implemented through the Cybersecurity Act for organizations considered at high or significant risk, especially those that meet or exceed the size of a medium-sized enterprise. Entities under majority state ownership are included. The periodicity is clear: mandatory audit every two years.

Microenterprises are exempt, but the scope includes:

  • Providers of electronic communications services
  • Trust and DNS service providers
  • Top-level domain registries
  • Domain name registration companies

Procedure for Cybersecurity Audits and Authorized Agents

Only auditors registered with the SZTFH are authorized to conduct these audits. After completing the process, auditors must submit the corresponding report to the Authority within a 7-day timeframe. This mechanism ensures traceability and timely response to risks identified during the audits.

The process particularly examined the administration of solutions that allow remote access to business systems. Many organizations demonstrated operating these solutions securely. However, the report revealed frequent deficiencies in the adequate documentation of these systems, a key aspect for both regulatory compliance and future risk management.

"The audit obligation represents a key stage in the implementation of community cybersecurity regulation enacted in national legislation," highlighted the SZTFH in its official statement.

Impact and Areas for Improvement Following the Mandatory Audit

The results of these first audits not only aim to ensure compliance. They also provide insights into improvement opportunities and future development in cybersecurity organizational maturity. The process has served as a feedback platform and is not seen as an end in itself, but as a phase of continuous advancement.

The SZTFH announced that it will maintain ongoing monitoring of compliance with the requirements and continue to support high standards in managing cyber risk for the country’s business sector.

Follow-Up on Compliance and Next Steps

Following the conclusion of the first round, the SZTFH emphasized its commitment to vigilance and continuous improvement in the cybersecurity processes of regulated companies. Going forward, the biennial frequency of audits will be maintained for both new obligated entities and those needing to renew their compliance.

The sector must prepare for recurring inspections, considering both the technical challenges and the documentation requirements that showed gaps in the initial review. The experience gained from this first wave creates the foundation for future cycles of compliance, integration of best practices, and progressive adaptation to new regulatory provisions in both the European and national spheres related to regulation and corporate governance.

Frequently Asked Questions

Who is required to conduct the NIS2 cybersecurity audit in Hungary?

Organizations at high or significant risk, such as those of medium size or larger, including entities with majority state ownership, as well as providers of electronic services, trust and DNS services, operators, and registrars of domains, except microenterprises, must undergo the mandatory audit every two years according to Hungarian regulations.

Who can perform the audit and what is the deadline for reporting results?

Only auditors registered by the SZTFH are authorized to conduct the audit and must deliver the report to the regulator within a maximum of 7 days after the audit is completed, ensuring immediate control and regulatory compliance.

What were the main findings of the cybersecurity audits?

Nearly all audited companies met the technical requirements, but recurrent deficiencies were detected in the documentation of systems, particularly those related to secure remote access.

What percentage of organizations received the highest rating?

About 10% of the audited organizations achieved the category of "Compliance with Negligible Risk," the highest score in the evaluative process.

How will compliance monitoring continue in cybersecurity?

The SZTFH will periodically supervise compliance and requires biennial audits, using the results to provide feedback and optimize future regulatory and technical processes in the sector.

Tags

nis2sztfhhungarycybersecurityauditregulation

About the author

Miguel Sandoval

Miguel Sandoval

Regulatory Affairs Correspondent

Miguel Sandoval tracks gambling legislation, licensing, and regulator enforcement — from Spain's DGOJ and the Latin American authorities to the UKGC, the MGA, and the state-by-state map in North America. The reports answer three questions precisely — what changed, where, and who it affects — with jurisdictions, dates, and penalties cited exactly as published. Operators and compliance officers read Miguel Sandoval to know which rulebook moved before their next meeting.

More from Miguel Sandoval

Related Articles

Gamble Responsibly

NCPGMalta Gaming AuthorityGambleAwareGLIGamCareeCOGRA18+

iGamingHouse is intended for users who are 18 years or older (or the legal age in your jurisdiction). Ensure online gambling is legal in your region before participating. Seek help from professional resources if you feel you have a gambling problem. Terms and conditions apply. All rights reserved © 2026.