Legal blog

New Cybersecurity Rules from 2026

2026-01-09 | IT jog, IT Law

New Cybersecurity Rules from 2026

1. New Regulatory Authority Roles in the Field of Cyber Resilience

The Act clearly designates the Supervisory Authority for Regulated Activities (SZTFH) as the body responsible for:

  • the notifying authority functions under the Cyber Resilience Regulation;

  • the market surveillance authority functions under the same Regulation; and

  • the competences related to the cybersecurity certification of non-military digital products.

In practice, this means that a single, central authority will in the future be responsible for verifying whether digital products comply with the prescribed cybersecurity requirements and, where necessary, for adopting enforcement measures.


2. Extension of the Scope of Application of the Cybersecurity Act

The amendment reshapes the range of organisations required to apply the provisions of the Cybersecurity Act. The legislation уточifies and expands the circle of affected entities, in particular:

  • undertakings under majority state ownership, provided that

    • their annual turnover or budgetary revenue exceeds EUR 10 million, and

    • their balance sheet total also reaches this threshold;

  • certain medium-sized enterprises, where

    • they employ at least 50 employees, or

    • their annual turnover reaches EUR 10 million.

An important rule is that the thresholds expressed in euros must be converted into Hungarian forints based on the official exchange rate of the Hungarian National Bank.

As a result, many undertakings that previously did not consider themselves affected may now fall under cybersecurity obligations. This may entail new administrative, organisational, and IT-related requirements.


3. Clarification of Notification and Registration Obligations

The Act establishes clear statutory deadlines:

  • affected organisations must register with the national cybersecurity authority within 30 days;

  • it also defines when an entity becomes subject to, and ceases to be subject to, the scope of the Act (for example, if headcount or turnover subsequently decreases).

This predictability is particularly important for organisations facing growth or restructuring.


4. National Implementation of the Cyber Resilience Regulation

The Act dedicates a separate chapter to the implementation of the EU Cyber Resilience Regulation at national level. Within this framework, it:

  • defines the concepts of conformity assessment, notified body, and market surveillance;

  • stipulates that products containing digital elements must comply with security requirements already at the design and development stages.

This is of particular relevance to software developers, technology suppliers, and undertakings marketing digital products.


Should you have any questions regarding the amendment or its implications for your business, please feel free to contact our experienced colleagues.

Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services

2026-08-07
Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services

The market of digital finance and crypto-assets is continuously developing, to which domestic legislation must also dynamically adapt. Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services, entering into force on 7 August 2026, constitutes a significant milestone in this doctrinal field.

The focus of the legislation is the phasing out of the previously introduced validation obligation, as well as the termination of the related criminal law and administrative authority proceedings, the purpose of which is to establish uniform regulation and to create the conditions for customers to use services in a safe and transparent manner.

Read more

Changes to the Rules on the Authorisation of Crypto-Asset Service Providers in Hungary

2026-08-06
Changes to the  Rules on the Authorisation of Crypto-Asset Service Providers in Hungary

On 2 August 2026, Decree No. 7/2026 (VII. 30.) of the Supervisory Authority for Regulatory Affairs (SZTFH)entered into force. The Decree lays down the detailed rules governing the authorisation and registration of crypto-asset service providers engaged in crypto-asset exchange validation activities. At the same time, it repeals the previously applicable SZTFH Decrees No. 10/2025 (VI. 26.) and No. 12/2025 (VI. 26.), which regulated the same subject matter.

The primary objective of the new Decree is to align the Hungarian regulatory framework with the European Union's legal framework governing crypto-assets while ensuring a more coherent and transparent system for the authorisation and supervision of service providers operating in this sector.

Read more

New regulation on cybersecurity auditors and vulnerability assessors (Decree No. 6/2026. (VI. 8.) SZTFH)

2026-06-18
New regulation on cybersecurity auditors and vulnerability assessors (Decree No. 6/2026. (VI. 8.) SZTFH)

The President of the Supervisory Authority for Regulated Activities (SZTFH) has issued Decree No. 6/2026. (VI. 8.) SZTFH, which comprehensively amends certain decrees on the subject of cybersecurity. The explicit intention of the legislator is to ease the situation of enterprises, significantly reduce administrative burdens, and promote market competition in the information technology security sector.

Read more