Hungary
EU roadmap Standard-takerHungary now has a national binding basis for its post-quantum transition. Act LXIX of 2024 on Hungary's Cybersecurity, in force from 1 January 2025, transposes the EU NIS2 Directive and adds a dedicated chapter on post-quantum encryption (sections 51 to 56) that obliges designated organisations to deploy post-quantum cryptography against quantum-computer attacks, sets up a certification scheme for post-quantum cryptography providers, and gives supervisory powers to the Regulated Activities Supervisory Authority (SZTFH). Alongside the law, the National Cyber Security Institute (NKI) has covered post-quantum and quantum-resistant cryptography in its IT security news and weekly press reviews, including the need to develop a migration plan that accounts for existing systems, and government-linked work appears through KIFU and the QCI Hungary project, the national node of the EU EuroQCI initiative. Beyond the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, the documents do not set out a specific algorithm suite or a single standards camp.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | High |
| Coherence | 2.0 / 2 | High |
| Effectiveness | 1.5 / 2 | High |
| Efficiency | 2.0 / 2 | High |
| Governance | 2.0 / 2 | High |
| Impact | 2.0 / 2 | High |
Regulatory basis
- Act LXIX of 2024 on Hungary's Cybersecurity, Chapter V (sections 51-56) on post-quantum encryption
- NIS2 Directive (EU) 2022/2555, Art. 21(2)(h)
- DORA, Regulation (EU) 2022/2554 (financial sector)
- Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap
- NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035)
Legal status: Binding
Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.
Standards and algorithms
No standards or algorithms specified.
Hybrid stance
None stated
Migration timeline
- 2025Act LXIX of 2024 in force, binding post-quantum encryption obligations begin for designated organisations
- 2030High-risk use cases migrated (EU coordinated roadmap)
- 2035Full migration of all systems complete (EU coordinated roadmap)
Target completion: 2035
International standards processes
- NIS Cooperation Group co-authored the EU coordinated PQC roadmap
Governmental and standards bodies
- Országgyűlés / Kormány (Hungarian Parliament / Government) enacted Act LXIX of 2024 on Hungary's Cybersecurity, with a dedicated chapter on post-quantum encryption
- SZTFH Regulated Activities Supervisory Authority, supervises post-quantum encryption obligations and certifies post-quantum cryptography providers under Act LXIX of 2024
- NKI Hungary's National Cyber Security Institute, publishes IT security news and press reviews
- KIFU / QCI Hungary Hungarian Governmental Agency for IT Development, national node of the EU EuroQCI initiative
Key institutional documents
Advising on this transition, or your own sector's? Request a briefing →