Checked on September 27, 2026
NIS2 in Bulgaria
How Bulgaria applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- In force
- National law
- Cybersecurity Act (as amended to transpose NIS2) · Закон за киберсигурност (ЗКС) · from February 17, 2026
- Competent authority
- Ministry of Electronic Governance (single point of contact); reportedly merged into the Ministry of Innovation and Digital Transformation on 2026-05-08 (Министерство на електронното управление / Министерство на иновациите и дигиталната трансформация)
- National CSIRT
- CERT Bulgaria (national CSIRT); sectoral CSIRTs
- Registration
- Required
Entities self-assess scope; secondary reporting says in-scope entities must submit information to the competent authority within 3 months of falling in scope. No uniform registration portal confirmed.
- Incident reporting
- Significant incidents to the sectoral CSIRT: early warning 24h, notification 72h (24h for trust service providers), final report 1 month. Where sectoral CSIRTs are not yet set up, confirm the route with CERT Bulgaria.
- National specifics
- Amendments adopted 2026-02-05, published State Gazette No. 17 of 2026-02-13.
- Fines: essential up to EUR 10m or 2% of turnover; important up to EUR 7m or 1.4%; management members up to EUR 5,000.
- As of Aug 2026, sectoral competent authorities/CSIRTs were reported as not yet designated.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.