Checked on September 27, 2026

NIS2 in Bulgaria

How Bulgaria applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.

Transposition status
In force
National law
Cybersecurity Act (as amended to transpose NIS2) · Закон за киберсигурност (ЗКС) · from February 17, 2026
Competent authority
Ministry of Electronic Governance (single point of contact); reportedly merged into the Ministry of Innovation and Digital Transformation on 2026-05-08 (Министерство на електронното управление / Министерство на иновациите и дигиталната трансформация)
Registration
Required

Entities self-assess scope; secondary reporting says in-scope entities must submit information to the competent authority within 3 months of falling in scope. No uniform registration portal confirmed.

Incident reporting
Significant incidents to the sectoral CSIRT: early warning 24h, notification 72h (24h for trust service providers), final report 1 month. Where sectoral CSIRTs are not yet set up, confirm the route with CERT Bulgaria.
National specifics
  • Amendments adopted 2026-02-05, published State Gazette No. 17 of 2026-02-13.
  • Fines: essential up to EUR 10m or 2% of turnover; important up to EUR 7m or 1.4%; management members up to EUR 5,000.
  • As of Aug 2026, sectoral competent authorities/CSIRTs were reported as not yet designated.

Where does your company stand?

The free assessment applies these national rules to your answers and scores every area of the law.

Sources

National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.

NIS2 in other countries

NIS2 in Bulgaria: national law, authority and registration | Parendum