Protection of essential and important entities under the Cybersecurity Act (NIS2): The Cybersecurity Act (Act LXIX of 2024) and Government Decree 418/2024 classify operators across the covered sectors (energy, transport, health, water, digital infrastructure, ICT management, public administration, space, plus postal, waste, chemicals, food, manufacturing, digital providers, research) as essential or important entities, with mandatory registration, security classification, protective measures, audit, and incident reporting. Banking/financial market infrastructure under DORA.
Sources: https://sztfh.hu/supervision-of-cybersecurity/?lang=en
https://en.nki.gov.hu/
https://nki.gov.hu/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
Sector-specific OT/ICS security guidance - electricity (SeConSys handbook): Hungary's dedicated cybersecurity guidance for operational-technology/industrial control systems in the electric power sector, the "Cybersecurity Handbook for Electric Power Industrial Control Systems," published and recommended by by the National Cyber Security Centre of Hungary (NCSC HU) within the SeConSys (Security for Control Systems) collaboration of Hungarian energy, control-engineering and cybersecurity experts, the National University of Public Service and state bodies. First issued December 2020 and updated annually (current edition 2023), it covers IT/OT/ICS distinctions, a threat map, the Zero Trust model, an incident list, and mandatory/recommended measures per cybersecurity level for the sector treated as the "most critical" critical infrastructure.
Sources: https://seconsys.eu/
https://nki.gov.hu/it-biztonsag/kiadvanyok/segedletek/seconsys-harmadik-alkalommal-kerult-aktualizalasra-a-kiberbiztonsagi-kezikonyv/
https://seconsys.eu/wp-content/uploads/2023/02/SeConSys_kezikonyv_aktual_2023_jan.pdf