Cybersecurity Act, Incident Notification and Cybersecurity Fine
2024. évi LXIX. törvény, 66. §; 418/2024. (XII. 23.) Korm. rendelet, 42. § és 77. §
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This duty reaches your service on the same basis as this jurisdiction's companion risk-management row: an essential or important organization under Section 1, including a provider of an online marketplace, online search engine or social-media service platform whose main place of business activity is in Hungary, whether or not you are established there.
- Notify the national cybersecurity incident-handling centre (Nemzeti Kiberbiztonsági Intézet, the NKI) of a cyber threat, near-incident or cybersecurity incident affecting your electronic information system: an initial notification without undue delay and in any case within 24 hours of becoming aware, an event notification within 72 hours that updates that report and assesses the incident's severity and impact, and a final report no later than one month after the event notification.
- Submit an interim status report if the centre asks for one, and, if the incident is still ongoing when the final report is due, a report on the results achieved so far followed by a final report within one month of the incident's resolution.
- Expect a failure to notify, or a failure to comply with a cybersecurity-authority order arising from it, to draw an administrative cybersecurity fine: up to the forint equivalent of EUR 10,000,000 or 2 percent of worldwide turnover for an essential organization, and EUR 7,000,000 or 1.4 percent for an important one.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Section 42 of Government Decree 418/2024 (XII. 23.) makes the sanction for a Section 66 notification failure an administrative cybersecurity fine; no provision reviewed here makes the failure itself a criminal offence, though Section 44(4) of the Decree states that paying the fine does not exempt the organization from any separate criminal or civil liability that applies.
Penalty structure
Government Decree 418/2024 (XII. 23.) Section 42(2) sets the same ceiling for a Section 66 notification failure as for a Section 6 risk-management failure: the forint equivalent of EUR 10,000,000 or, if higher, 2 percent of worldwide turnover for an essential organization, mirroring NIS2 Article 34(4); EUR 7,000,000 or 1.4 percent for an important organization, mirroring Article 34(5). Section 42(4) separately lets the national cybersecurity authority fine the head of an organization personally up to HUF 15,000,000 for failing to meet a statutory duty.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Szabályozott Tevékenységek Felügyeleti Hatósága (SZTFH, the Supervisory Authority of Regulated Activities) for an organization under Section 1(1)(d) or (e) of the Act; a separate national cybersecurity authority the Government designates by decree enforces instead against a public-administration, state-influenced or critical-infrastructure organization under Section 1(1)(a), (b), (c) or (f). Notifications themselves are received by the national cybersecurity incident-handling centre regardless of which authority later enforces.
Settledness
- As of
- 14 September 2026
- Open questions
- Did a 2025 amendment to Government Decree 418/2024 move the 24-hour, 72-hour or one-month notification clock, or the fine tiers, away from what its consolidated text as fetched on 2026-09-14 states?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 66(2) of the Act requires an organization under Section 1(1)(d) or (e) to notify the national cybersecurity incident-handling centre of a threat, near-incident or cybersecurity incident causing serious disruption or damage, as specified in a government decree. Section 66(1) imposes the equivalent duty, without that materiality filter, on a public-administration, state-influenced or critical-infrastructure organization under Section 1(1)(a) to (c) or (f).
Section 77(1) of Government Decree 418/2024 sets the clock those notifications run on. It requires an initial notification without undue delay and in any case within 24 hours of becoming aware of the incident. It requires an event notification within 72 hours that updates the initial report and assesses the incident's severity and impact.
It requires a final report no later than one month after that 72-hour event notification, or, if the incident is still ongoing at that point, a report on progress so far followed by a final report within one month of its resolution. Section 42 of the same Decree makes an infringement of either Section 66 or the Decree's own notification rules punishable by an administrative cybersecurity fine on the same NIS2-mirroring tiers as the risk-management duty.
When LexLint raises it
operates_social_platform
Read the law
Consolidated text
Nemzeti Jogszabálytár, Act LXIX of 2024, Section 66, as implemented by Government Decree 418/2024 (XII. 23.), Sections 42 and 77