ESG software regulations have been supplemented
On 17 August 2026, a decree of the Supervisory Authority for Regulatory Affairs (abbreviated in Hungarian: SZTFH) was published, amending two SZTFH decrees relating to ESG matters. The decree supplements the transitional provisions of SZTFH Decree with regard to the conditions for the registration of ESG software.
The scope of the Hungarian ESG Act also applies to companies that distribute or manufacture ESG software within Hungary. Under the ESG Act, ESG software is defined as a product that assists a company or a legal or natural person authorized by it in complying with ESG reporting obligations, collecting and processing data, and conducting performance evaluations.
Under the ESG Act, an enterprise subject to the Act shall establish an appropriate and effective risk management system to ensure compliance with sustainability-related due diligence obligations. The purpose of the risk management system is for the enterprise to identify and minimise ESG risks within its own sphere of business operations and throughout its supply chain.
Only ESG software specified in the ESG Act and duly registered may be used for supply chain due diligence and for the analysis and classification of risks. SZTFH registers the ESG software if the cybersecurity certificate issued for the ESG software certifies that the ESG software meets at least the “ava_van.2” compliance level.
The decree supplemented the transitional provisions on the cybersecurity compliance of ESG software. Based on the new rules, when registering ESG software, until 30 November 2027, the cybersecurity compliance requirement may also be met if the manufacturer of the ESG software complies with the cybersecurity requirements and has a cybersecurity audit based on which the organization’s resilience index is rated at least “audited”. Compliance with this requirement may be certified by attaching an audit certificate issued to the ESG software manufacturer. For the ESG software registered on the basis of the audit certificate, the certifying authority’s registration decision shall be submitted to SZTFH by 31 December 2027. Failure to provide such certification will result in the SZTFH deleting the ESG software from the registry. In addition to the above, the decree amended further SZTFH decrees to ensure consistency with the amended provisions of the ESG Act.
The above provisions of the decree entered into force on the third day following their publication. Due to the diversity of ESG, the relevant legislation is constantly changing and may change, so it is worth monitoring the updates.