Multiple organizations share the responsibility of ensuring Hungary’s cybersecurity. In the following article, we will provide an overview—at least in broad strokes—of these organizations and their respective roles.
On January 1st, the law titled „On Hungary’s Cybersecurity” came into effect, providing a unified framework for defense activities and measures that were previously regulated by multiple laws. Part of the legislation is the restructuring and reassessment of responsibilites among various state agencies and institutions.
Let’s take a look at the key players in the bigger picture! (Naturally, this list does not include private sector actors that provide first-level cybersecurity protection as service providers for companies or organizations.)
National Cybersecurity Task Force
At the highest, strategic level, the National Cybersecurity Coordination Council, established in 2013, has played a crucial role. However, it will soon be dissolved in its current form. The Council was composed of representatives from various ministries and cybersecurity agencies. Its primary responsibilities included formulating the national cybersecurity strategy, breaking down its execution into tasks, and monitoring its implementation. The Council also served as an advisory body for the government on cybersecurity matters.
With the new law in effect, the organization will be restructured as the National Cybersecurity Task Force, led by the Cybersecurity Commissioner, who will be appointed by the Minister responsible for IT. Similar to its predecessor, the Task Force will serve as the government’s advisory and consultative body on cybersecurity issues and will ensure coordination of activities defined in laws and regulations. According to plans, any legislative amendments related to cybersecurity or the introduction of new regulations will require prior consultation with the Task Force and the Cybersecurity Commissioner. (The exact responsibilities are specified in the government decree implementing the new law.)
The Task Force will be supported by subgroups and an Operational Task Force. The latter will have a crucial role, as it will have the authority to escalate a significant cybersecurity incident and declare a cybersecurity crisis, which enables immediate intervention measures. A crisis could be triggered by a major attack on a Hungarian government body or critical infrastructure, or by a lesser incident that affects at least one other EU member state alongside Hungary. The Defense Administration Office will also be represented in the Operational Task Force, playing a vital role in general crisis management, including cybersecurity emergencies.
Additionally, the existing National Cybersecurity Forum will continue to operate within the Task Force framework, facilitating collaboration with non-governmental stakeholders.
National Cyber Defense Coordination Center
A relatively new and somewhat tumultuous player in Hungary’s cybersecurity landscape is the National Cyber Defense Coordination Center (NKK-HU), established last year. The center serves as Hungary’s national representative and point of contact within the European Network of National Coordination Centers and works with the European Cybersecurity Competence Center (ECCC) to enhance cybersecurity at both national and European levels.
Initially, a government decree designated the Governmental Agency for IT Development (KIFÜ) as the agency responsible for establishing and operating the NKK-HU. However, KIFÜ ceased operations on December 31st, and its responsibilities were reassigned to other organizations. The new law designates the Special Service for National Security (NBSZ) as the organization responsible for carrying out NKK-HU’s duties.
Supervisory Authority for Regulated Activities (SZTFH)
The Supervisory Authority for Regulated Activities (SZTFH) gained prominence last year when Hungary began implementing the NIS2 Directive. The authority is responsible for overseeing the directive’s implementation, particularly concerning the private sector.
SZTFH has multiple responsibilities, including processing and approving registration applications for organizations subject to the NIS2 Directive—between January 2024 and now, it has evaluated 3,000–3,500 applications. The authority will continue to register organizations falling under the directive’s scope. While SZTFH itself will not conduct audits, it will oversee the appointed auditors responsible for them. Additionally, SZTFH will supervise organizations authorized for vulnerability assessments and incident management. Some overlap may exist—auditors may also conduct vulnerability assessments, but not necessarily vice versa due to stricter regulations governing auditors.
The new law may require certain organizations to purchase or use only certified ICT products and services. The companies certifying these products and services will also be supervised by SZTFH. Additionally, SZTFH will have responsibilities related to post-quantum encryption. The law designates specific organizations that are obligated to use post-quantum encryption (i.e., encryption that cannot be cracked even by quantum computers). Furthermore, there are organizations that can provide such encryption services, as well as certifiers that verify their capability to offer these services. The supervision of these latter two groups of companies will also fall under SZTFH’s authority.
Constitution Protection Office (AH)
The Constitution Protection Office (AH) plays an indirect but significant role in Hungary’s cybersecurity framework. Many organizations and individuals under SZTFH’s supervision require thorough vetting by AH before being registered. This applies particularly to cybersecurity auditing firms (currently, there are nine such firms), which must meet stringent requirements, including national security compliance, certified by AH. The same scrutiny applies to organizations authorized for vulnerability assessments and post-quantum encryption.
Special Service for National Security (NBSZ)
Among the four designated cybersecurity authorities, NBSZ—in simple terms—focuses on protecting public sector entities (except those under the defense sector). Its responsibilities fall into three categories: regulatory activities, incident management, and vulnerability assessments. Unlike SZTFH, which does not conduct audits or vulnerability assessments, NBSZ performs all three tasks.
- Regulatory Activities:
This involves bureaucratic oversight, ensuring that required cybersecurity measures are implemented, documentation is completed, and responsible personnel are designated. - Vulnerability Assessments:
NBSZ-NKI has the authority to conduct vulnerability assessments both as a regulatory body and as an operational entity. Additionally, NBSZ operates an automated vulnerability detection system, which governmental organizations can use for free. This system provides monthly security assessments, reducing exposure to cyber threats.A significant change introduced by the new law is that vulnerability assessments will now be mandatory during the development phase of IT projects in the public sector. This proactive approach aims to identify issues early, preventing costly post-deployment fixes. - Incident Management:
NBSZ-NKI serves as Hungary’s national CSIRT (Computer Security Incident Response Team), making it the country’s official cybersecurity incident response center. By definition, there can be only one national CSIRT, responsible for liaising with international counterparts. (Sector-specific CSIRTs can be establlished, but currently, there is only one such body, HUNCERT, which serves the scientific community under HUN-REN SZTAKI.) The national CSIRT receives cybersecurity incident reports. While state and municipal clients must report all incidents, those under SZTFH’s supervision only need to report significant incidents. Under NIS2, affected entities must submit an initial report within 24 hours, a detailed report within 72 hours, and a comprehensive report within 30 days.The CSIRT does not aim to handle all incidents directly but provides assistance when needed. It also organizes cybersecurity drills.
Cybersecurity Exercises Begin
For years, the National Cybersecurity Center (NKI), operating within NBSZ, has organized cybersecurity exercises, and the new law introduces mandatory participation for several organizations. These exercises primarily test personnel and defense procedures—specifically, incident response capabilities—rather than technical vulnerabilities. They simulate incidents in a controlled environment where teams must resolve the issues. Following each exercise, NKI provides detailed feedback, and participants review and discuss their experiences. This allows teams to refine their processes in a safe setting, making exercises one of the most effective tools for assessing and strengthening organizational cybersecurity.
The Defense Sector
For military-related organizations, as of this year, the Minister of Defense oversees regulatory functions, while the Military National Security Service (KNBSZ) handles incident response and vulnerability assessments, as well as product and service certification.
The Hungarian Defense Forces Cyber Operations Command was established two years ago. It develops strategic directions for cyber defense and operations within the military and oversees cyber and information operations. It operates under the Cyber and Information Operations Center, which coordinates Hungary’s cyber forces and collaborates with allied organizations.
Hungarian National Bank (MNB)
The fourth Hungarian cybersecurity authority, MNB, oversees cybersecurity compliance for the financial sector, including banks and financial institutions. It enforces cybersecurity requirements based on the DORA regulation.







