Legal blog

New regulation on cybersecurity auditors and vulnerability assessors (Decree No. 6/2026. (VI. 8.) SZTFH)

2026-06-18 | IT Law

New regulation on cybersecurity auditors and vulnerability assessors (Decree No. 6/2026. (VI. 8.) SZTFH)

Unification of requirements for auditors

The most significant conceptual change is realized through the amendment of Decree No. 7/2024. (VI. 24.) SZTFH on the register of auditors authorized to conduct cybersecurity audits. The new regulation eliminates the previous differentiation in expectations toward auditors tied to security classes. Thanks to this, the requirements for auditors have been unified, meaning all auditors must meet the same, eased expectations. Compliance with the requirements is henceforth independent of what security class (for example, "basic", "significant", or "high") of electronic information system audit the auditor performs.

However, the regulations continue to strictly ensure that only organizations possessing the necessary expertise and infrastructural conditions can examine the security classification of systems and the compliance of protective measures. In line with this approach, Decree No. 1/2025. (I. 31.) SZTFH on the rules for conducting cybersecurity audits has also been clarified, repealing the previous restrictive provisions.

Of course, there continue to be specific conditions for registration. During the procedure, the auditor must prove that they employ at least two persons standing in a relationship aimed at work performance under the Labor Code, in the positions recorded in the relevant statutory regulation. In addition, a professional liability insurance extending up to a minimum annual limit of 15,000,000 forints is indispensable for the auditor qualification, furthermore, the presentation of at least 5 references is also required, which relate to the auditing of software products or electronic information systems implementing IT security functions based on domestic or international methodology.

New rules for organizations conducting vulnerability assessments

In line with the amendment of the Cybersecurity Act with effect from January 1, 2026, the new decree also updates Decree No. 5/2025. (VI. 20.) SZTFH, which regulates the register of organizations and persons conducting vulnerability assessments. Eligible economic operators must continue to meet strict expectations in the future: they must employ at least two experts (natural persons authorized to conduct vulnerability assessments) meeting the statutory conditions, as well as possess an information security policy and a certified information security management system.

Furthermore, a key requirement is the use of secure communication tools and software that guarantee the confidentiality, integrity, and authenticity of the data used for the assessment during contact with the assessed organizations. They must also ensure compliance with statutory requirements through erasure procedures and solutions that guarantee the irreversible erasure of data from their systems and archival backups. On the other hand, it is a significant ease for applicants that if the facility security clearance is not attached to the application, the cybersecurity authority will from now on obtain it ex officio.

Transparency, fees, and EU compliance

A further key objective of Decree No. 6/2026. (VI. 8.) SZTFH is to clarify the scope of data published from authentic official registers. The supervisory authority publicly publishes on its website the list of registered auditors as well as economic operators authorized to conduct vulnerability assessments, which in both cases includes the name, electronic mail address, and telephone number of the given organization or auditor.

With the amendment of Decree No. 15/2023. (VII. 31.) SZTFH, the fee structure has also been significantly simplified and unified. The administrative service fee for the procedure aimed at the supervisory registration of auditors has become uniformly 390,000 HUF, by which the legislator abolished the previous distinction regarding the basic security class. The fee for the registration procedure of economic operators authorized to conduct vulnerability assessments is likewise 390,000 HUF, while the fee for the procedure aimed at registering changes to the registered data is 60,000 HUF for both groups. A key transitional provision is that in registration procedures pending at the time of the entry into force of the amendment, the authority already disregards which security class of systems the applicant intends to perform activities on.

Finally, the legislation clarifies that the creation of the decree closely aligns with the European Union's cybersecurity strategy. The introduced measures serve compliance with Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 – that is, the NIS 2 Directive, which is increasingly well-known in our country as well – which is intended to ensure a uniformly high level of cybersecurity throughout the whole territory of the Union.

The Legal Price of ChatGPT: Copyright and GDPR Mazes Behind Artificial Intelligence

2026-09-11
The Legal Price of ChatGPT: Copyright and GDPR Mazes Behind Artificial Intelligence

The revolution of artificial intelligence has forced not only the technology sector but also legislators to take action. Although ChatGPT and similar large language models may appear to users to be simple chat programs, an astonishing amount of data processing takes place in the background. The European Union’s legal framework has highlighted that these models raise serious copyright and data protection challenges, which cause significant headaches for developers.

Read more

Know Your Agent – Who Is Liable When AI Acts on Our Behalf?

2026-09-10
Know Your Agent – Who Is Liable When AI Acts on Our Behalf?

The next stage in the development of AI is no longer simply about artificial intelligence answering questions or making recommendations. So-called AI agents are increasingly capable of acting autonomously on behalf of users: initiating purchases, booking appointments, carrying out financial transactions, or even managing processes across multiple digital systems.

This, however, raises a new question, primarily of a legal nature: how can it be determined whether an AI agent was actually authorised to perform a particular action, and who is liable if it exceeds the limits of its authority?

Read more

Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services

2026-08-07
Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services

The market of digital finance and crypto-assets is continuously developing, to which domestic legislation must also dynamically adapt. Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services, entering into force on 7 August 2026, constitutes a significant milestone in this doctrinal field.

The focus of the legislation is the phasing out of the previously introduced validation obligation, as well as the termination of the related criminal law and administrative authority proceedings, the purpose of which is to establish uniform regulation and to create the conditions for customers to use services in a safe and transparent manner.

Read more