Directive NIS2 European Union
BG · Member state

NIS2 in Bulgaria


What binds you in Bulgaria is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
Ministry of e-Government
National CSIRT
VAT on your purchase
20%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


Status of the national text · Promulgated and in force

National law

Закон за изменение и допълнение на Закона за киберсигурност (Act amending and supplementing the Cybersecurity Act of 2018)

Adopted
In force

Adopted by the National Assembly on 5 February 2026 and promulgated in State Gazette issue 17 of 13 February 2026. Bulgaria transposed by amending its 2018 Cybersecurity Act rather than by passing a new one. The entry into force date needs stating carefully: the consolidated act carries no "в сила от" provision for this amendment, so the default of article 5(5) of the Constitution applies and the text takes effect three days after promulgation — 17 February 2026. One law-firm commentary instead dates it to the day of promulgation. The difference is four days and matters only for conduct in that window. Detailed minimum requirements come by secondary legislation — a Council of Ministers ordinance and a new national strategy — which were still awaited at review.

Registration

Central register of essential and important entities (Ministry of e-Government)

The register is held by the Ministry of e-Government and is NOT public, unlike the Belgian or French portals. There was no transitional compliance period: the core obligations applied on entry into force, with reduced sanctions only for breaches committed up to 1 June 2026 — a window that has now closed.

Who supervises you

Ministry of e-Government is the competent authority designated by Bulgaria. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to CERT Bulgaria, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Bulgaria legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0