
NIS2 in Hungary: what should you prepare for before the cybersecurity audit?
By 2026, the Hungarian regulatory framework for NIS2 has clearly reached a stage where the focus is no longer on the general interpretation of the law, but on actual implementation and audit readiness. In Hungary, the framework is primarily defined by Act LXIX of 2024 on the Cybersecurity of Hungary and its implementing regulations. According to information from the SZTFH (Supervisory Authority for Regulated Activities), organizations subject to audit that began operations before January 1, 2025, must complete their first cybersecurity audit no later than June 30, 2026. The deadline for these organizations to contract with an auditor was August 31, 2025.
Why has this become a genuine leadership and legal issue?
In practice, NIS2 compliance cannot be managed solely as an IT project. Domestic regulations require organizational obligations, a system of accountability, documented risk management, appropriate protective measures, and auditability. Based on the implementing decree, the obligations and regulatory oversight extend to specific groups of organizations covered by the law, and the system specifically addresses the role of the person responsible for the security of the electronic information system. The justification for the training decree issued in 2025 emphasizes that the organization's leader must also participate in training to raise awareness of the importance of cybersecurity, and the person responsible for information system security must possess appropriate qualifications and undergo further training.
This is important from a business perspective because, for many organizations, cybersecurity is still viewed primarily as a technological or vendor-related issue. However, the audit logic for June 30, 2026, assumes that the organization must operate in a controlled, documented, and verifiable manner internally. Where this is lacking, the audit will typically not be a simple check, but an event that reveals the organization's operational shortcomings. From this perspective, NIS2 is clearly a leadership, compliance, and legal task.
What might the audit examine in practice?
According to SZTFH Decree 1/2025 (I. 31.), the purpose of the cybersecurity audit is for an independent auditor to examine how resilient the audited organization's electronic information systems are against cybersecurity threats. Based on the decree, the auditor prepares an audit plan, is entitled to access documents related to the security of the organization and its systems, and the person responsible for the security of the electronic information systems must ensure and follow through with the audit as determined by the auditor. For systems classified as having significant or high security levels, the decree may also require the involvement of a testing laboratory.
In practice, this means that affected organizations cannot simply present a few technical controls. Generally, they must at least review which systems fall under the regulation, whether the necessary classification has been performed, whether a documented risk management logic exists, whether internal policies and incident management procedures are up to date, and whether the responsible individuals who can effectively cooperate with the auditor during the audit have been designated and properly involved. This is no longer just a question of technical readiness, but also of documentation and organizational readiness.
Where do organizations usually stumble?
A typical problem is that an organization may have certain technical protection solutions in place, but there is no unified and documented management logic behind them. Another common deficiency is that areas of responsibility are not clearly defined, policies exist only formally but do not align with daily operations, or contracts with external IT and security providers do not properly address incident management, access rules, reporting obligations, or auditability. Since NIS2 compliance affects the entire operation of an organization, such gaps typically do not remain hidden during an audit. This is partly a conclusion drawn from official audit and preparation rules, but it is strongly supported by the logic of Hungarian regulation.
The contractual environment is a particular risk factor. If an organization's critical systems or parts thereof are operated by an external provider, compliance often depends on whether the contractual documentation accurately regulates security expectations, cooperation obligations, and the framework for access or information provision required by the auditor. In many cases, this is where it becomes clear that NIS2 preparation is not just a technological issue, but a serious commercial and compliance matter.
Why is the June 30, 2026, deadline particularly important?
The SZTFH has confirmed in several communications that for affected organizations subject to audit that began operations before January 1, 2025, the deadline for the first audit is June 30, 2026. The SZTFH also indicated that the authority began inspecting businesses involved in the audit in the autumn of 2025. This suggests that the practical enforcement of the regulation is no longer just a future possibility, but an actual area of regulatory focus.
Due to the proximity of the deadline, the question in 2026 is no longer primarily whether an organization has started its NIS2 project, but whether it has reached a state of audit readiness. The biggest risk in such cases is usually not a total lack of preparation, but that compliance elements exist in a scattered manner at different levels of maturity and do not form a uniformly verifiable system. This can be particularly problematic from an audit perspective, as the logic of the decree assumes explicitly structured, documented compliance.
What should be reviewed now?
Before the audit on June 30, 2026, it is advisable to review at least five areas. First, scope and the range of electronic information systems: has the organization accurately identified which systems fall under the regulation? Second, documentation: are internal policies, records, and incident management and risk management materials up to date? Third, the system of responsibility: has the person responsible for the security of the electronic information system been designated, and is the leadership role clarified? Fourth, the contractual environment: do external provider and vendor contracts reflect cybersecurity expectations? And fifth, the level of audit readiness: is the organization able to present compliance to the auditor in a way that is genuinely transferable, consistent, and verifiable? These points are not literal lists from the law, but practical compliance focuses derived from official Hungarian rules and audit requirements.
Summary
The implementation of NIS2 in Hungary in 2026 is clearly an operational compliance issue. Before the audit on June 30, 2026, affected organizations must demonstrate not only technical measures but also that cybersecurity has been integrated into their operations at the organizational, leadership, documentation, and contractual levels. Those who manage this in a timely and systematic manner will not only handle an audit better but can also develop a more defensible operational model in the long term.