NIS2 in Bulgaria
Bulgaria's Cybersecurity Act amendments were finally adopted in February 2026 and entered into force on 17 February 2026. The transitional grace period on management fines ended on 1 June 2026.
Key Deadlines
Competent Authority
Bulgaria utilizes a centralized competent authority model under the Ministry, working alongside sectoral CSIRTs for incident handling and proactive auditing.
Registration Process
Registration is handled through the national cybersecurity register maintained under the Ministry of Electronic Governance, accessible via Bulgaria's single administrative services portal.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Registration with the national cybersecurity registry
- 2Adoption of rigorous risk management controls based on ISO 27001
- 3Symmetrical incident reporting to the national CERT within 24 hours
National Additions
FAQ: NIS2 in Bulgaria
What is the primary reporting center in Bulgaria?
Are Bulgarian board members personally liable yet?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.