Is your company ready for NIS2?
Bulgaria’s amended Cybersecurity Act has been in force since February 2026. If you are a medium or large company in one of 18 sectors, it already applies to you — and your management is personally accountable.
- 18 sectorsFrom energy and transport to manufacturing, food and waste management
- 24 hoursTo send an early warning after a significant incident
- Up to €10 millionOr 2% of global turnover in fines for essential entities
- Personal finesFor managers who fail their obligations
Does NIS2 apply to your company?
Coverage is automatic. Nobody will send you a letter first. Check two things: your sector and your size.
1. Is your sector on the list?
Sectors of high criticality
- Energy: electricity, oil, gas, heating, hydrogen
- Transport: air, rail, water, road
- Banking and financial market infrastructure
- Healthcare
- Drinking water and waste water
- Digital infrastructure and managed ICT services (B2B)
- Public administration and space
Other critical sectors
- Postal and courier services
- Waste management
- Chemicals: production and distribution
- Food: production, processing and distribution
- Manufacturing: medical devices, electronics, electrical equipment, machinery, vehicles
- Digital providers: online marketplaces, search engines, social networks
- Research organisations
2. Are you medium-sized or larger?
As a rule, NIS2 covers companies with 50 or more employees or an annual turnover above €10 million. Some providers are covered regardless of size, for example telecoms, DNS and trust service providers, and the only provider of an essential service.
Small company, but a supplier to one that is covered?
You may not be in scope yourself, but your clients must manage the security of their supply chain. Expect them to ask for evidence of your security measures in contracts and audits.
What the law requires
NIS2 is not a certificate you buy. It requires measures that work, approved and overseen by management.
What happens if you ignore it
Authorities can order security audits, issue binding instructions and require public disclosure. For essential entities they can ask a court to suspend licences or bar individuals from management roles.
| Essential entities | Important entities | |
|---|---|---|
| Maximum fine | €10 million or 2% of global annual turnover | €7 million or 1.4% of global annual turnover |
| Minimum fine | €25,000 | €12,500 |
| Managers personally | €500 to €5,000 | €500 to €5,000 |
Source: amended Bulgarian Cybersecurity Act, State Gazette, 13 February 2026. This page is a summary, not legal advice.
How we get you compliant
- Free scope checkA short call to confirm whether NIS2 applies to you and as which type of entity.
- Gap assessmentWe compare your systems, processes and policies with the requirements, and rank the gaps by risk.
- Fix the gapsWe implement the technical measures ourselves: firewalls, MFA, backup, monitoring, secure remote access.
- Policies and supportWe write the policies and incident procedures, train your team and stay on as your support.
Why companies choose Velox for NIS2
Common questions
When do we need to be compliant?
The amended Cybersecurity Act is already in force, so the obligations apply now. Detailed minimum requirements are set out in secondary legislation. The sooner you start, the easier it is.
Does ISO 27001 certification make us compliant?
Not automatically, but it covers much of the same ground. It is a practical framework to build NIS2 compliance on.
We are a small company. Can we ignore NIS2?
Usually you are not in scope, unless you provide certain digital services. But if your clients are covered, they will ask you to meet their security requirements.
How long does it take?
It depends on your size, your sector and where you start from. After the gap assessment you get a clear plan with priorities, effort and cost.
Who supervises NIS2 in Bulgaria?
National competent authorities designated by the Council of Ministers. Significant incidents are reported to the sectoral CSIRT.
Get a free NIS2 scope check
Tell us your sector and size. We will tell you whether NIS2 applies and what the first steps are.
- Sales and consultations+359 888 504559
- Emailoffice@velox-systems.com