Hungary issues new notification rules for cybersecurity conformity assessment bodies
On 4 September 2026, Hungary’s Supervisory Authority for Regulatory Affairs (SZTFH) issued and published SZTFH Decree 9/2026 (IX.4.) in the Hungarian Gazette, which sets down the national rules for notifying and registering conformity assessment bodies under Regulation (EU) 2024/2847, commonly known as the Cyber Resilience Act (CRA).
A cornerstone of the EU’s cybersecurity framework, the CRA establishes horizontal cybersecurity requirements for products with digital elements throughout their entire lifecycle. Its Chapter IV, which covers the notification of conformity assessment bodies, has applied since 11 June 2026.
Under the Hungarian Cybersecurity Act, the SZTFH is the notifying authority, which must receive and process notification requests specified in the CRA.
To submit a notification request, a conformity assessment body must apply using an electronic form provided by the SZTFH and provide the body’s basic information: name, tax number, company registration number, registered seat, and contact details. The body must also identify the conformity assessment module or modules under Annex VIII of the CRA.
The application must include the following three items:
- a description of the conformity assessment activity and the product type or types concerned;
- the accreditation certificate issued by the national accreditation body, showing compliance with Article 39(2)–(12) of the CRA, which sets out the requirements that a conformity assessment body must meet in order to become a notified body; and
- proof that the administrative service fee has been paid.
The Decree also allows the notifying authority to verify the accreditation certificate’s authenticity with the national accreditation body.
Once it receives an application, the SZTFH registers the conformity assessment body ex officio in the register maintained under the Cybersecurity Act. After registration, the body must report any change in the registered data to the SZTFH within eight days of the change. Changes include bankruptcy, liquidation, dissolution, or involuntary de-registration proceedings, non-compliance with the requirements of the CRA’s Article 39(2)–(12) and any change in accreditation status.
The SZTFH must then notify the national accreditation body within 15 days of learning that a notified body no longer meets the applicable requirements.
Registration is followed by a yearly reporting requirement. By 31 January of each year, every notified body must send the SZTFH an electronic report covering its conformity assessment activities during the preceding year. The report must describe the procedures conducted for each product type and conformity assessment module. It must also cover complaints received from economic operators and the results of their investigation, training and cooperation activities, and the number of withdrawn certificates.
The Decree also amends SZTFH Decree 15/2023 (VII.31.) on administrative service fees by adding two new fee items. The notification application procedure costs EUR 1,074 (HUF 390,000), while the data change registration procedure costs EUR 165 (HUF 60,000).
The Decree enters into force on 5 October 2026, which will give conformity assessment bodies sufficient time to become familiar with the new procedural rules and prepare the necessary documentation.
These measures allow Hungary to fulfil its member state obligation under Chapter IV of the CRA and provide the domestic legal framework for the notification and ongoing supervision of conformity assessment bodies in the field of cybersecurity.
For more information on these proposed changes and how they could impact your business operations in Hungary, contact your CMS client partner or the CMS experts who contributed to this article.
This article was co-authored by Péter Dani and Hunor Bendegúz Jávorszky.