Skip to content

NIS2 is now law in Bulgaria: what it means for your company

Bulgaria has transposed the EU NIS2 directive. The amended Cybersecurity Act was published in the State Gazette on 13 February 2026 and is in force. It replaces the 2018 rules and brings many more companies under cybersecurity obligations than before.

If you run a medium or large company, here is what you need to know.

Who is covered

The law applies automatically to companies in 18 sectors, based on their sector and size. Nobody will send you a notice first. As a rule, it covers companies with 50 or more employees or an annual turnover above €10 million, in sectors such as:

  • Energy, transport, banking, healthcare, water and digital infrastructure
  • Manufacturing: machinery, vehicles, electronics, electrical equipment, medical devices
  • Food production and distribution, chemicals, waste management
  • Postal and courier services, digital providers and managed ICT services

Some providers are covered regardless of size, for example telecoms, DNS and trust service providers.

What the law requires

  • Risk management: documented risk analysis and security policies, approved by management.
  • Incident reporting: an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month.
  • Business continuity: backups, disaster recovery and crisis management.
  • Supply chain security: security requirements for your suppliers and service providers.
  • Technical measures: access control, multi-factor authentication and encryption.
  • Training: regular training for staff, and cybersecurity training every two years for management.

Management is personally accountable

This is the biggest change. The management body must approve the security measures and oversee them. Managers who fail their obligations can be fined personally, from €500 to €5,000. For essential entities, authorities can also ask a court to bar individuals from management roles.

The fines

Essential entities face fines of up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4%. Authorities can also order security audits and issue binding instructions.

Where to start

  1. Check whether you are in scope and whether you are an essential or important entity.
  2. Brief your management. They carry the responsibility and need the training.
  3. Do a gap assessment of your systems, processes and policies against the requirements.
  4. Fix the biggest risks first: backups, MFA, remote access, updates.
  5. Prepare your incident procedure, so you can meet the 24-hour deadline.

We help companies with every step: from the scope check to implementing the technical measures ourselves. Velox is certified to ISO 27001, the information security standard NIS2 builds on.

This article is a summary, not legal advice. Sources: amended Cybersecurity Act (State Gazette, 13 February 2026) and published legal analyses.