Hungary’s SZTFH Completes First Wave of Cybersecurity Audits with 90% Compliance
By June 30, 2026, nearly 2,200 Hungarian organisations completed their inaugural cybersecurity audit under the NIS2-aligned regime, with high rates of compliance and a focus on remote access security.

Key Takeaways
- Over 2,190 Hungarian organisations completed their first cybersecurity audit by June 30, 2026.
- About 90% of audited entities successfully met compliance standards set by SZTFH.
- 10% of organisations received the top 'negligible risk' rating.
- Biennial cybersecurity audits are now mandatory for Hungarian medium-sized and larger high-risk organisations.
- Remote access security was a focus, though documentation gaps were identified.
Nearly 2,200 entities in Hungary have completed the first round of mandatory cybersecurity audits under legislation aligned with the European Union’s NIS2 Directive. According to the Supervisory Authority of Regulated Activities (Szabályozott Tevékenységek Felügyeleti Hatósága, SZTFH), as of June 30, 2026, 2,194 organisations submitted audit reports, with almost 90% successfully meeting the required standards and about 10% rated as carrying negligible risk.
NIS2 Directive Drives New Cybersecurity Audit Obligations in Hungary
The audit process stems from Hungary’s implementation of the EU’s NIS2 Directive, designed to harmonise cybersecurity across the bloc. The requirements were incorporated into national law, mandating biennial cybersecurity audits for organisations engaged in medium or high-risk activities and meeting at least the medium enterprise threshold. This category includes companies with majority state ownership.
The scope is broad, extending—except for micro-enterprises—to electronic communications providers, trust service providers, DNS service operators, top-level domain registries, and domain name registrars. These rules mark a significant expansion of compliance oversight within Hungary’s cybersecurity landscape.
Audit Procedure and Reporting Requirements
Cybersecurity audits must be conducted by auditors registered with SZTFH. Once an audit is completed, the auditor has seven days to submit the resulting report to the Authority. The SZTFH reviewed all reports submitted up to the June 30 deadline and provided statistics on outcomes.
- Total audited organisations: 2,194
- Success rate: Nearly 90% met the audit requirements
- Top rating: About 10% were certified as presenting only negligible risk
“The audit process not only checks compliance but also gives valuable feedback on further development opportunities,” SZTFH stated in its official announcement.
Focus on Remote Access and Documentation Gaps
Analysis of the first audits highlighted the widespread use and critical importance of secure remote access solutions among audited organisations. However, one consistent gap was identified: many entities lacked thorough documentation for their systems, which is an area regulators expect to see improved in the next audit cycle.
In addition to confirming technical compliance, the audits serve as a feedback mechanism, helping companies identify and prioritise future investments in their cybersecurity frameworks.
Ongoing Oversight and the Path Ahead
Completion of the first round of cybersecurity audits is a milestone, yet the process is continuous. The SZTFH has signalled its intent to continue monitoring compliance closely and to support the evolving security needs of the sector. Biennial audit cycles are now a fixture for qualifying organisations.
For operators, being prepared for the next audit window will require both continued technical improvements—particularly in documentation and secure remote access—and diligent engagement with authorised auditors. The Authority has made clear its commitment to high professional standards and ongoing oversight of cybersecurity requirements.
For the wider European iGaming sector, Hungary’s experience signals the growing regulatory focus on operational resilience and systematic risk reduction. The application of the NIS2 Directive at a national level provides a model others in the region may follow.
Frequently Asked Questions
Who is required to undergo Hungary’s cybersecurity audits under the NIS2 Directive?
Hungarian organisations engaged in medium or high-risk activities and meeting at least the medium-size enterprise threshold—including majority state-owned entities—must undergo biennial cybersecurity audits, in line with national law transposing the NIS2 Directive.
Which authority oversees Hungary’s cybersecurity audit programme?
The Supervisory Authority of Regulated Activities (SZTFH) manages the cybersecurity audit process, including auditor registration, report submission workflows, and ongoing compliance oversight.
What were the main findings of Hungary’s first cybersecurity audits?
Almost 90% of organisations met the required standards, with 10% achieving negligible risk status, and significant focus placed on the secure operation of remote access solutions and the need for improved system documentation.
What is the reporting timeline for auditors in Hungary’s cybersecurity audit regime?
Auditors registered with SZTFH must submit the audit report to the Authority within seven days of completion, as mandated in Hungary's national cybersecurity law.
What ongoing obligations do audited Hungarian organisations have post-audit?
Audited organisations must maintain compliance with cybersecurity requirements and are subject to biennial audits, with the SZTFH monitoring progress and focusing on areas such as documentation and remote access security between cycles.
Tags
About the author

Eleanor Whitfield
Regulatory Affairs Correspondent
Eleanor Whitfield tracks gambling legislation, licensing decisions, and regulator enforcement across key markets — from the UKGC, MGA, and Germany's GGL to Spain's DGOJ and the state-by-state map in the Americas. The reporting answers three questions precisely: what changed, where, and who it affects, with jurisdictions, effective dates, and penalty figures named exactly as published. Compliance officers and operators read Eleanor Whitfield to know which rulebook moved before their next board meeting.
More from Eleanor Whitfield








