Supervision of Cybersecurity
Cybersecurity Certification
The network and information systems and services play a vital role in society and have become the backbone of economic growth. Increased digitalisation increases cybersecurity risks. In order to mitigate these risks, the digital products and services used by citizens and businesses should be better protected from cyber threats.
As one of the means of this protection, SARA performs the tasks of cybersecurity certification for digital products in Hungary, under the Regulation (EU) 2019/881 on the European Union Agency for Cybersecurity and on information and communications technology cybersecurity certification.
Certification aims to ensure that the ICT devices and services that citizens and businesses can buy and use compliant with the constantly evolving cybersecurity requirements. Based on the information contained in the certificate, consumers can decide on the level of cybersecurity capability they want to buy and use a product with. As a result, consumer confidence in ICT products can be effectively enhanced.
The Authority supervises the cybersecurity certification process of digital products and services, as well as the activities of accredited conformity assessment bodies and testing laboratories, manufacturers and distributors. To this end, the Authority carries out audits of conformity assessment bodies, holders of cybersecurity certificates and issuers of ‘statements of conformity’ to verify their compliance with the relevant legislation.
Through its cybersecurity activities, the Authority promotes the compliance of domestically manufactured and developed products and services with cybersecurity requirements, thereby facilitating the enforcement of cybersecurity as a competitive advantage in the market, as well as the appearance of these products and services in the EU Single Market.
Cybersecurity supervision
The Act XXIII of 2023 on Cybersecurity Certification and Cybersecurity Supervision designated SARA with cybersecurity supervisory powers over companies and organisations that provide services that are essential for the functioning of society and the economy, as well as infrastructure services that are essential for the development of digitalisation. SARA may keep records and order administrative audits, extraordinary checks and extraordinary audits. The purpose of a cybersecurity audit is to ensure that the parties involved are aware of the risks to their own electronic information systems, so that they can take specific measures to reduce and eliminate the shortcomings.
Cybersecurity awareness and education
SARA carries out awareness-raising activities in the field of cybersecurity, focusing on credibility, comprehensibility and the education of the general public. The main objective is to make citizens aware of the importance of safe internet use, the dangers of the online space and the safe use of ICT devices.