2026-06-18 | IT Law

Unification of requirements for auditors
The most significant conceptual change is realized through the amendment of Decree No. 7/2024. (VI. 24.) SZTFH on the register of auditors authorized to conduct cybersecurity audits. The new regulation eliminates the previous differentiation in expectations toward auditors tied to security classes. Thanks to this, the requirements for auditors have been unified, meaning all auditors must meet the same, eased expectations. Compliance with the requirements is henceforth independent of what security class (for example, "basic", "significant", or "high") of electronic information system audit the auditor performs.
However, the regulations continue to strictly ensure that only organizations possessing the necessary expertise and infrastructural conditions can examine the security classification of systems and the compliance of protective measures. In line with this approach, Decree No. 1/2025. (I. 31.) SZTFH on the rules for conducting cybersecurity audits has also been clarified, repealing the previous restrictive provisions.
Of course, there continue to be specific conditions for registration. During the procedure, the auditor must prove that they employ at least two persons standing in a relationship aimed at work performance under the Labor Code, in the positions recorded in the relevant statutory regulation. In addition, a professional liability insurance extending up to a minimum annual limit of 15,000,000 forints is indispensable for the auditor qualification, furthermore, the presentation of at least 5 references is also required, which relate to the auditing of software products or electronic information systems implementing IT security functions based on domestic or international methodology.
New rules for organizations conducting vulnerability assessments
In line with the amendment of the Cybersecurity Act with effect from January 1, 2026, the new decree also updates Decree No. 5/2025. (VI. 20.) SZTFH, which regulates the register of organizations and persons conducting vulnerability assessments. Eligible economic operators must continue to meet strict expectations in the future: they must employ at least two experts (natural persons authorized to conduct vulnerability assessments) meeting the statutory conditions, as well as possess an information security policy and a certified information security management system.
Furthermore, a key requirement is the use of secure communication tools and software that guarantee the confidentiality, integrity, and authenticity of the data used for the assessment during contact with the assessed organizations. They must also ensure compliance with statutory requirements through erasure procedures and solutions that guarantee the irreversible erasure of data from their systems and archival backups. On the other hand, it is a significant ease for applicants that if the facility security clearance is not attached to the application, the cybersecurity authority will from now on obtain it ex officio.
Transparency, fees, and EU compliance
A further key objective of Decree No. 6/2026. (VI. 8.) SZTFH is to clarify the scope of data published from authentic official registers. The supervisory authority publicly publishes on its website the list of registered auditors as well as economic operators authorized to conduct vulnerability assessments, which in both cases includes the name, electronic mail address, and telephone number of the given organization or auditor.
With the amendment of Decree No. 15/2023. (VII. 31.) SZTFH, the fee structure has also been significantly simplified and unified. The administrative service fee for the procedure aimed at the supervisory registration of auditors has become uniformly 390,000 HUF, by which the legislator abolished the previous distinction regarding the basic security class. The fee for the registration procedure of economic operators authorized to conduct vulnerability assessments is likewise 390,000 HUF, while the fee for the procedure aimed at registering changes to the registered data is 60,000 HUF for both groups. A key transitional provision is that in registration procedures pending at the time of the entry into force of the amendment, the authority already disregards which security class of systems the applicant intends to perform activities on.
Finally, the legislation clarifies that the creation of the decree closely aligns with the European Union's cybersecurity strategy. The introduced measures serve compliance with Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 – that is, the NIS 2 Directive, which is increasingly well-known in our country as well – which is intended to ensure a uniformly high level of cybersecurity throughout the whole territory of the Union.

