Cybersecurity risk-management / protective-measures catalogue: Hungary's binding risk-management measures, transposing NIS2 Art. 21. Under the Cybersecurity Act (Act LXIX of 2024) and Ministerial Decree 7/2024 (VI. 24.), every in-scope organisation must apply the protective measures assigned to its system's security class (Basic / Significant / High). The Protective Measures Catalogue (Decree Annex 2) is built on the NIST SP 800-53 Rev. 5 control catalogue, organised into control families covering administrative, logical and physical safeguards, with each control marked as required or not per security class. Where an organisation's own risk analysis justifies deviating from a control, it must document and justify this. Measures are "closed, comprehensive, continuous and risk-proportionate," as required by the Act.
Sources: https://nki.gov.hu/intezet/kozlemenyek/elektronikus-informacios-rendszerek-es-szervezetek-kiberbiztonsagi-kovetelmenykatalogusanak-alkalmazasi-utmutatoja/
https://net.jogtar.hu/jogszabaly?docid=a2400007.mkf
https://net.jogtar.hu/jogszabaly?docid=a2400418.kor
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
National Cyber Security Centre of Hungary (NCSC HU) application guide and mandatory cybersecurity audit
The practical compliance-and-verification layer. The National Cyber Security Centre of Hungary (NCSC HU) issues an official Application Guide to the protective-measures catalogue, explaining the risk-management framework, the security-classification process and how to tailor and implement each control in the Hungarian legal context, control-family by control-family. Compliance is verified through a mandatory cybersecurity audit: in-scope entities must contract an accredited cybersecurity auditor and complete a first audit, then repeat at least every two years or as directed by SZTFH.
Sources: https://nki.gov.hu/it-biztonsag/kiadvanyok/segedletek/eir-utmutato/
https://sztfh.hu/tevekenysegek/kiberbiztonsagi-tanusitasok/
https://sztfh.hu/supervision-of-cybersecurity/?lang=en