NIS2 Bulgaria: the Cybersecurity Act (ЗКС), Reporting & Fines
Bulgaria transposed the NIS2 Directive by amending its Cybersecurity Act (Закон за киберсигурност, ЗКС). The amendments have been in force since 17 February 2026. Risk-management, governance and reporting duties bind you now — but the authorities that will formally identify you as an essential or important entity are still being designated.
Introduction: NIS2 Directive & the Bulgarian context
Bulgaria transposed the NIS2 Directive by amending its existing Cybersecurity Act (Закон за киберсигурност, commonly abbreviated ЗКС) rather than by passing a new standalone law. The National Assembly adopted the amending act on 5 February 2026 and it was promulgated in the State Gazette (Държавен вестник) issue 17 of 13 February 2026.
The amendments took effect on 17 February 2026. They replace the old model, under which an authority designated individual operators, with automatic coverage based on your sector and your size, and they widen the law well past its original set of operators — as far as the judiciary and research-active educational institutions.
What you must do in Bulgaria
These duties bind essential and important entities today. They did not wait for the register, and they do not wait for you to be formally identified.
- Put risk-management measures in place. Article 22 requires appropriate and proportionate technical, operational and organisational measures, judged against your exposure, your size and the likelihood and severity of incidents.
- Get the board to approve and supervise them. Article 21(1) puts approval and oversight of those measures on the management body itself, not on an IT function.
- Train the management body every two years. Article 21(2) sets a recurring two-year cycle. Article 21(3) makes management responsible for arranging staff training as well.
- Be able to report an incident in 24 hours. Significant incidents go to your sectoral CSIRT (СЕРИКС) on a 24-hour, 72-hour and one-month chain. See Incident reporting.
- Keep your registration data current. Any change must reach the competent authority within two weeks under Article 6(3).
- If you are a named digital provider, act within two months. Cloud, data centre, CDN, DNS, TLD, domain registration, managed service, managed security, marketplace, search and social network providers have their own duty under Article 6(2). See Registration.
NIS2 implementation in Bulgaria
Bulgaria transposed NIS2 through the Act amending and supplementing the Cybersecurity Act, adopted by the 51st National Assembly on 5 February 2026, signed into law by Presidential Decree 52 of 11 February and promulgated in State Gazette issue 17 of 13 February 2026. It amends the Cybersecurity Act of 2018 (State Gazette issue 94 of 2018).
The act entered into force on 17 February 2026. That date is worth explaining, because the statute does not state it: the amending act contains no commencement clause at all, so the default rule in the Normative Acts Act applies and it took effect three days after promulgation. Bulgaria missed the EU transposition deadline of October 2024 by some margin, and the law arrived with no general transition period — only a temporary halving of fines that expired on 1 June 2026.
Status
In force since 17 February 2026. Obligations on risk management, governance and incident reporting apply now. The supporting machinery — competent authorities, the identification methodology, two ordinances and a national strategy — is still being put in place through 2026.
Which law applies
The Cybersecurity Act (ЗКС) of 2018, as substantially amended in February 2026. Bulgaria chose to amend rather than replace, so there is no separate “NIS2 act” to look for — the operative text is the consolidated ЗКС.
What changed
Coverage became automatic by sector and company size instead of by individual designation. The Annexes now list 10 sectors in Annex I and 7 in Annex II, the essential and important categories were introduced, management became personally liable, and the penalty scale was rewritten with statutory minimum fines.
Compliance & obligations
Coverage is automatic. If you are of a type listed in Annex I or Annex II and you meet the size test, the Cybersecurity Act applies to you by operation of law — there is no decision to wait for and no application to make. Which of the two categories you fall into determines how hard supervision bites.
Essential entities (съществени субекти)
- Annex I types above the medium-enterprise ceiling.
- Qualified trust service providers, top-level domain name registries and DNS service providers — at any size.
- Providers of public electronic communications networks or services meeting the medium-enterprise criteria.
- Administrative bodies.
- Anyone already designated an operator of essential services when the amendments took effect.
Important entities (важни субекти)
Everything else of a type listed in Annex I or Annex II that does not meet the essential test. The category is residual, so if you are in scope at all and not essential, you are important.
The size test
Medium-enterprise criteria under Article 3(1) of the Small and Medium-Sized Enterprises Act. Bulgaria disapplies Article 4(9) of that act, so partner and linked company figures are not aggregated into your headcount and turnover.
Standards & frameworks
Article 22 sets the duty; the detailed minimum measures come from ordinances that the Council of Ministers must adopt by 17 October 2026. Until they are published, the statutory text is the operative standard. No certification is mandated, so aligning with ISO/IEC 27001 or the NIST CSF remains the practical way to structure the work — and Article 22 explicitly requires technology neutrality, so no ordinance may force a particular product on you.
Registration & the national register
Bulgaria does not work the way Germany or Luxembourg do. There is no general self-registration duty and no registration deadline for most entities, because the register is compiled by the state rather than filled in by you.
Who builds the register
Article 6(1) puts the register in the hands of the Ministry of Innovation and Digital Transformation. The sectoral competent authorities identify which organisations are essential and which are important, under a methodology adopted by the Council of Ministers, and pass that up to the ministry. You are placed on it; you do not apply to join it.
The register is not public
Article 6(5) states it plainly. You cannot check whether a supplier, a customer or a competitor is on it, and you should not expect a public list of Bulgarian essential and important entities to appear.
What it holds
Name, address and current contact details including email and telephone, IP ranges, your sector, subsector and entity type, the member states where you provide in-scope services, and contact details for your EU representative where you have one.
The two duties that are on you
- Named digital providers, within two months. Article 6(2) applies to DNS service providers, top-level domain registries, domain name registration services, cloud providers, data centre providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines and social networking platforms. You must give the sectoral competent authority the address of your main establishment and your other EU establishments — or your representative's details if you have none in the EU — within two months of them arising.
- Everyone, within two weeks. Article 6(3): any change to information already provided must reach the competent authority within two weeks. The authority then has one week to pass it to the ministry and the Single Point of Contact. Two weeks is far shorter than the three months the Directive allows, and it is easy to miss.
Incident reporting
Significant incidents are reported to your sectoral CSIRT (СЕРИКС) under Article 23. The clock starts when you become aware of the incident, not when you finish investigating it.
| Stage | Deadline | What it must contain |
|---|---|---|
| Early warning | 24 hours | Whether the incident is suspected to be unlawful or malicious, and whether it could have cross-border impact. |
| Incident notification | 72 hours 24 hours for trust service providers |
An updated early warning plus an initial assessment of severity and impact, and any technical detail you have. |
| Interim report | On request | Whatever the sectoral CSIRT asks for. |
| Final report | 1 month after the 72-hour notification | Full description including scope and impact, the threat type or likely root cause, mitigation applied and ongoing, and cross-border impact. |
| Still unresolved? | Progress report at 1 month, then a final report 1 month after resolution | The same content, once you have actually handled the incident. |
- They owe you a response in 24 hours. Article 23(6) requires the sectoral CSIRT to reply to your early warning within 24 hours with initial information, and on request with guidance or technical support.
- Report once. Escalation is the CSIRT's job: to ГДБОП where a crime is suspected, and to ДАНС where a critical system, national security or a foreign state may be involved.
- Tell your customers where relevant. Article 23(2) requires you to notify recipients of your services about incidents likely to affect service delivery, and about significant cyber threats.
- Notifying does not increase your liability. Article 23(1) says so expressly.
NIS2 timeline & key dates (Bulgaria)
Sector-specific notes for Bulgaria
- Annex I — 10 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business to business), and space. Each is defined by reference to the relevant Bulgarian sectoral statute, so the Energy Act definitions decide who counts as an energy undertaking, not the Directive's wording.
- Annex II — 7 sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research.
- Digital infrastructure is the broadest entry. It covers internet exchange points, DNS providers, top-level domain registries, cloud, data centres, content delivery networks, trust services, and providers of public electronic communications networks and services.
- Public administration is handled separately. Administrative bodies are pulled in by Article 4(1) rather than by the Annexes, and they are always essential entities. This is why counting “18 sectors” depends on how you tally — the Annexes themselves list 10 and 7.
- The judiciary is in scope. Article 4(9) covers judicial bodies, supervised by the Plenum of the Supreme Judicial Council. Few member states go this far.
- Research-active education is in scope. Article 4(6) covers educational institutions when they carry out critical research in an Annex I or Annex II sector.
- Electronic public services pull in more bodies. Article 4(7) and 4(8) cover organisations exercising public functions or providing public services, when they deliver administrative services electronically, even if nothing else in the law would reach them.
- Defence and anti-corruption are out. Article 5 excludes the Ministry of Defence and structures directly subordinate to it, the Bulgarian Army, and the Commission for Countering Corruption.
How Bulgaria differs
Five things here work differently from the member states we see most often. If you are running a multi-country programme, these are the ones that will not carry across.
- You do not register yourself. Germany, Luxembourg and Italy all put a registration duty with a deadline on the entity. Bulgaria puts the register on the ministry and the identification on the sectoral authority. There is nothing to submit and nothing to miss — but equally, nothing to confirm that you are compliant.
- The register is closed. Article 6(5) makes it non-public, so there is no Bulgarian equivalent of a searchable list of regulated entities.
- Fines have a floor, not just a ceiling. The Directive sets maxima. Bulgaria adds statutory minima of EUR 25,000 and EUR 12,500. A minor breach by a small in-scope entity cannot be settled for a token amount.
- Management training is on a two-year cycle. The Directive requires training without saying how often. Article 21(2) sets two years, and Article 29(4) attaches a personal fine of EUR 500 to 5,000 to getting it wrong.
- Group aggregation is switched off. Article 4(9) of the Small and Medium-Sized Enterprises Act is disapplied, so partner and linked company figures do not count towards your size. A Bulgarian subsidiary of a large group can therefore sit outside the size test where its German equivalent would not. Compare Germany, which relieves aggregation only where the entity is IT-independent, and Luxembourg, which applies it.
Bulgarian terms you will meet
The register, the reporting forms and all correspondence are in Bulgarian. These are the strings worth recognising.
| Bulgarian | English | What it is |
|---|---|---|
| Закон за киберсигурност (ЗКС) | Cybersecurity Act | The law itself. NIS2 lives inside it as amendments, not as a separate act. |
| Държавен вестник (ДВ) | State Gazette | Where laws are promulgated. The NIS2 amendments are issue 17 of 2026. |
| съществени субекти | essential entities | The heavier of the two categories. |
| важни субекти | important entities | The residual category. |
| СЕРИКС | sectoral CSIRT | Where you report incidents. |
| НЕРИКС | national CSIRT | CERT Bulgaria, at govcert.bg. |
| НЕЗК | National Single Point of Contact | Cross-border liaison, inside МИДТ. |
| МИДТ | Ministry of Innovation and Digital Transformation | Holds the register. Formerly the Ministry of e-Government. |
| ДАНС | State Agency for National Security | Receives national-security escalations. |
| ГДБОП | Directorate for Combating Organised Crime | Receives criminal escalations. |
| значителен инцидент | significant incident | The trigger for the 24-hour clock. |
| имуществена санкция / глоба | corporate fine / personal fine | Bulgarian law separates the two. Article 29(4) fines individuals. |
Penalties for non-compliance
Chapter Three sets the penalties. Bulgaria adopted the euro on 1 January 2026, so the law states them in euro directly — there is no lev figure to convert.
| Breach | Who | Amount |
|---|---|---|
| Failure to meet the risk-management (Article 22) or reporting (Article 23) duties | Essential entity | Up to EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher — but not less than EUR 25,000 |
| Failure to meet the same duties | Important entity | Up to EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher — but not less than EUR 12,500 |
| Breach of the management duties in Article 21 | Individuals — heads of administrative bodies, managers, members of management bodies | EUR 500 to 5,000, personally |
| Ignoring a coercive administrative measure | Essential or important entity | EUR 2,500 to 12,000 — EUR 5,000 to 25,000 on repeat |
- The minimums are the unusual part. The Directive sets ceilings; Bulgaria adds floors. For a small in-scope entity, EUR 25,000 will almost always be the operative figure rather than the percentage.
- Turnover is measured across the undertaking you belong to, not just the Bulgarian entity — even though group figures are ignored when deciding whether you are in scope at all.
- Public bodies are treated differently. Article 29(5) disapplies the corporate fine to essential entities that are administrative bodies. The personal fine on their leadership still applies.
- Mitigating circumstances are codified in Article 29b and are taken into account both for coercive measures and for fines.
Beyond fines
Supervisors can issue warnings, binding instructions, cease-and-desist orders, orders to bring measures into line with Article 22, orders to tell your customers about a threat, orders to implement audit recommendations, and orders to make the breach public. For essential entities they may also appoint a monitoring officer to supervise compliance.
Two sanctions are reserved for essential entities only: temporary suspension of a licence, registration, certificate or authorisation, and a court-imposed temporary ban on an individual exercising management functions in the entity. Neither applies to administrative bodies.
How to prepare for NIS2 in Bulgaria
- Check if you are likely in scope: map your services and customers against NIS2 sectors and size thresholds.
- Perform a gap assessment: compare your current controls to NIS2 requirements for risk management, incident handling and governance.
- Book the board training: Article 21(2) requires members of the management body to be trained every two years, and Article 21(1) requires them to approve and supervise the security measures. Diarise it — a personal fine attaches to getting this wrong.
- Assemble your register data now: legal name, addresses, current contacts, public IP ranges, sector and subsector, and the EU member states where you provide services. The authorities will ask for exactly this, and Article 6(3) then gives you only two weeks to report any change to it.
- Rehearse the 24-hour clock: set up monitoring, logging and playbooks that can produce an early warning within 24 hours of becoming aware, and confirm in advance which sectoral CSIRT channel you use.
- Review third-party risk: update supplier contracts to include security obligations, audit rights and incident-notification clauses.
- Align with a recognised framework: begin or strengthen implementation of an ISMS based on ISO 27001 or an equivalent framework.
- Train staff: run awareness campaigns and exercises so employees recognise and respond correctly to cyber incidents.
Operating in more than one EU country
NIS2 is one Directive and 27 national laws. If you operate across borders, the Bulgarian rules will not match what you built elsewhere.
- Jurisdiction usually follows establishment. Most entities answer to the member state where they are established. The named digital providers in Article 6(2) instead answer to the state of their main establishment in the EU, and must appoint a representative if they have none.
- Register once per country where you are established, but expect the mechanics to differ sharply. Bulgaria identifies you; Germany and Luxembourg make you register yourself against a deadline.
- Size tests are not portable. Bulgaria switches off group aggregation, Germany relieves it only where the entity is IT-independent, and Luxembourg applies it. The same group can be in scope in one country and out in another.
- Reporting clocks are the most portable part. The 24-hour, 72-hour and one-month chain is broadly consistent across member states — but Bulgaria shortens the notification to 24 hours for trust service providers, and sends reports to a sectoral rather than a national CSIRT.
- Sector rules can displace the general regime. Article 6a switches off the Cybersecurity Act where a sector-specific law imposes at least equivalent duties. Financial entities under DORA are the usual case.
Official links & resources
FAQ: NIS2 in Bulgaria
Has Bulgaria transposed NIS2, and is it in force?
Which law implements NIS2 in Bulgaria?
Do we have to register, and by when?
We were not covered by the old Cybersecurity Act. Are we now?
Nobody has contacted us. Are we compliant?
Sources & verification
Every date and figure on this page was read out of the Bulgarian statutory text on 3 August 2026, not from summaries. Public NIS2 trackers contradict each other and are not used here.
- State Gazette issue 17 of 13 February 2026 — the amending act: scope, register, reporting chain, penalties, and the transitional deadlines.
- Consolidated Cybersecurity Act (ЗКС), current to State Gazette issue 69 of 31 July 2026 — the current text of Articles 16, 17 and 18, which is where the ministry rename shows up.
- State Gazette issue 55 of 2026 — renamed the responsible ministry throughout the Cybersecurity Act.
- CERT Bulgaria — the national CSIRT and its incident reporting channel.
