Cybersecurity Act, Risk-Management Measures
2024. évi LXIX. törvény (Magyarország kiberbiztonságáról), 6. §
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2025.
A sector security regimes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This duty reaches your service where you are an essential or important organization under Section 1: an organization under the sector annexes that qualifies as a medium-sized enterprise or larger under Hungary's SME Act, or exceeds the thresholds the Act sets for one, or a provider of an online marketplace, online search engine or social-media service platform whose main place of business activity is in Hungary, whether or not you are established there.
- Establish and operate a risk-management framework for the electronic information systems in your organization's possession, following a directly applicable EU legal act or, absent one, the decree of the minister responsible for informatics.
- Survey and register every electronic information system, central service and supporting system you use, appoint or designate the person responsible for the security of those systems, classify them into a security category, and apply protective measures proportionate to their risk.
- Issue an information-security policy for your users and the requirements it sets, and review it at least every two years.
- Report a cyber threat, near-incident or cybersecurity incident affecting your electronic information system to the competent cybersecurity incident-handling centre without delay, on the notification clock this jurisdiction's companion incident-notification row sets out.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Section 42 of Government Decree 418/2024 (XII. 23.) makes the sanction for an infringement of Section 6 an administrative cybersecurity fine; no provision reviewed here makes the infringement itself a criminal offence, though Section 44(4) of the Decree states that paying the fine does not exempt the organization from any separate criminal or civil liability that applies.
Penalty structure
Government Decree 418/2024 (XII. 23.) Section 42(2), not the Act itself, sets the ceiling: the forint equivalent of EUR 10,000,000 or, if higher, 2 percent of the organization's total global annual turnover in the preceding financial year for an essential organization, mirroring NIS2 Article 34(4); a lower tier for an important organization is EUR 7,000,000 or 1.4 percent, mirroring Article 34(5). Section 42(4) separately lets the national cybersecurity authority fine the head of an organization personally up to HUF 15,000,000 for failing to meet a statutory duty.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Szabályozott Tevékenységek Felügyeleti Hatósága (SZTFH, the Supervisory Authority of Regulated Activities) for an organization under Section 1(1)(d) or (e) of the Act, the sector-annex and digital-provider organizations this row is flagged for; a separate national cybersecurity authority the Government designates by decree enforces instead against a public-administration, state-influenced or critical-infrastructure organization under Section 1(1)(a), (b), (c) or (f).
Settledness
- As of
- 14 September 2026
- Open questions
- Does the medium-enterprise threshold in Section 1(4)(f) test an organization on a standalone basis, or does it import the partner-enterprise and linked-enterprise aggregation the referenced SME Act builds on Commission Recommendation 2003/361/EC, the same open question the EU-level NIS2 row records for Article 21?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 6(2) requires the head of an organization within the Act's scope to establish and operate a risk-management framework for the electronic information systems in the organization's possession, following a directly applicable EU legal act or, in its absence, the decree of the minister responsible for informatics.
Section 6(3) to (5) list the concrete tasks the framework must cover: surveying and registering every electronic information system and central service used, appointing the person responsible for system security, classifying systems into a security category, applying protection proportionate to risk, issuing and periodically reviewing an information-security policy, and, for a public-administration, state-influenced or critical-infrastructure organization, spending at least 5 percent of annual IT development costs on cybersecurity.
Section 1 scopes the duty to an essential or important organization. The sector annexes (2. and 3. melléklet) reach an organization that qualifies as a medium-sized enterprise or larger under Hungary's SME Act, or that exceeds the thresholds the Act sets for one. Section 2(1)(c) separately reaches a provider of an online marketplace, online search engine or social-media service platform whose main place of business activity is in Hungary, even where the provider is established elsewhere.
When LexLint raises it
operates_social_platform