The Cybersecurity Act (the Act) is the Bulgarian law that transposes the requirements of Directive (EU) 2022/2555 (NIS2) into national law. It does not create a new framework from scratch; instead, it replaces the previous regime with that of the directive: cyber risk management, reporting of significant incidents and management accountability.
For organisations this means a change in the very nature of the work. Until now, security was reported mainly in technical terms. Now a demonstrable process is required: adopted measures, a designated owner, reviews carried out and a trail of the decisions.
- Adopted on 5 February 2026, published in State Gazette No. 17 of 13 February 2026.
- Transposes Directive (EU) 2022/2555 (NIS2) into Bulgarian law.
- The addressees are designated essential and important entities, not all organisations.
- The competent authorities designate the obliged entities under a methodology adopted by the Council of Ministers (Art. 4a).