Skip to main content
In forceNIS2

NIS2 in Bulgaria

Bulgaria's Cybersecurity Act amendments were finally adopted in February 2026 and entered into force on 17 February 2026. The transitional grace period on management fines ended on 1 June 2026.

Transposition law
Закон за изменение и допълнение на Закона за киберсигурност (Cybersecurity Act amendments)
In force since
17 February 2026
Competent authority
Ministry of Electronic Governance
Max fine (Essential)
€10 million or 2% of global annual turnover
Max fine (Important)
€7 million or 1.4% of global annual turnover
Law adopted
17 February 2026

Key Deadlines

First reading in Parliament
1 February 2025
Final adoption
1 February 2026
Amendments in force
17 February 2026
Grace period on management fines ends
1 June 2026

Competent Authority

Ministry of Electronic Governance
National NIS2 competent authority and cybersecurity coordinator
https://egov.bg

Bulgaria utilizes a centralized competent authority model under the Ministry, working alongside sectoral CSIRTs for incident handling and proactive auditing.

Registration Process

Registration is handled through the national cybersecurity register maintained under the Ministry of Electronic Governance, accessible via Bulgaria's single administrative services portal.

📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

Key Requirements

  • 1Registration with the national cybersecurity registry
  • 2Adoption of rigorous risk management controls based on ISO 27001
  • 3Symmetrical incident reporting to the national CERT within 24 hours

National Additions

Specific requirements for government digital services and integration with public infrastructure portals

FAQ: NIS2 in Bulgaria

What is the primary reporting center in Bulgaria?
The Bulgarian National CERT (cert.bg) coordinates security incident response across public and private sectors.
Are Bulgarian board members personally liable yet?
Yes. A transitional grace period applied reduced penalties to management until 1 June 2026. Since that date board members face the full personal fine levels set out in the amended Cybersecurity Act.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.