11/08/2026
NIS2 has been transposed into the Bulgarian Cybersecurity Act. The reduced penalties have ceased to apply.
By the amendments to the Cybersecurity Act (the CSA), promulgated in the State Gazette, issue 17 of 13 February 2026, Bulgaria took the national measures transposing Directive (EU) 2022/2555 (NIS2). Until 1 June 2026 a transitional regime halved the penalties; the full amounts now apply.
Three points merit attention:
1. The obligations are already running, even though designation of the entities is still pending. Official designation is made by the national competent authorities under a methodology adopted by the Council of Ministers (Article 16(3)(8) CSA). The obligations under Articles 22 and 23 CSA have nonetheless applied since 13 February 2026. Waiting for an official notification is no defence in a subsequent inspection.
2. The liability of management bodies is independent. Article 21 CSA requires management bodies to approve the risk management measures and oversee their implementation, and their members to undergo training every two years. Technical ex*****on may be assigned to an internal function or an external provider; approval, oversight and training remain with the body. An infringement attracts a fine of EUR 500 to EUR 5,000 on heads of administrative authorities, managers and members of management bodies (Article 29(4) CSA).
3. The effect reaches companies outside the scope of the Act. Article 22(2)(4) CSA turns supply chain security into a statutory duty. Entities within scope are likely to impose security requirements contractually on their direct suppliers, including suppliers outside the scope.
Penalties reach EUR 10,000,000 or 2 per cent of worldwide turnover for essential entities, and EUR 7,000,000 or 1.4 per cent for important entities, whichever is higher.
The full newsletter and analysis are available here:
https://stoychevlaw.com/nis2-bulgarian-cybersecurity-act/
Stoychev & Stoycheva Law Firm
[email protected] | +359 2 43 700 73