Legal framework

The Cybersecurity Act: what it requires and who is obliged

The Bulgarian law introduces the requirements of Directive (EU) 2022/2555. This page sets out the requirements, the obliged entities and the institutions that supervise them - with precisely cited provisions.

01

What the Act is

The Cybersecurity Act (the Act) is the Bulgarian law that transposes the requirements of Directive (EU) 2022/2555 (NIS2) into national law. It does not create a new framework from scratch; instead, it replaces the previous regime with that of the directive: cyber risk management, reporting of significant incidents and management accountability.

For organisations this means a change in the very nature of the work. Until now, security was reported mainly in technical terms. Now a demonstrable process is required: adopted measures, a designated owner, reviews carried out and a trail of the decisions.

  • Adopted on 5 February 2026, published in State Gazette No. 17 of 13 February 2026.
  • Transposes Directive (EU) 2022/2555 (NIS2) into Bulgarian law.
  • The addressees are designated essential and important entities, not all organisations.
  • The competent authorities designate the obliged entities under a methodology adopted by the Council of Ministers (Art. 4a).
02

Who is obliged

The Act does not apply to everyone. The obligations apply to entities of the types listed in Annex I and Annex II, when the size criteria are also met. That is why the first practical step is not filling in a questionnaire, but a judgement about scope.

An entity of a type listed in Annex I that exceeds the upper threshold for a medium-sized enterprise, as well as providers of electronic communications networks or services that meet the criteria for a medium-sized enterprise (Art. 4a(1)).

An entity of a type listed in Annex I or II that does not meet the criteria for an essential entity (Art. 4a(2)).

Size is determined by the criteria for small and medium-sized enterprises (Art. 3(1) of the Small and Medium-sized Enterprises Act): fewer than 250 staff and annual turnover of up to 50 000 000 euro and/or assets of up to 43 000 000 euro.

Changes to the data provided are notified to the relevant national competent authority within two weeks of their occurrence (Art. 4(3)).

  • Scope is determined by type of activity and by size, not by self-assessment.
  • An entity that does not meet the criteria for essential is considered important.
  • Public authorities, providers of electronic communications services and organisations providing administrative services electronically have their own grounds for inclusion.
03

What the obligations are

The obligations are grouped in several articles that work together. Management accountability comes first, because the measures must be approved at the highest level, not merely adopted by the technical team.

  • Art. 21 - the management bodies approve the cyber risk management measures and oversee their implementation. Their members undergo training every two years.
  • Art. 22 - appropriate and proportionate technical, operational and organisational measures are applied for the security of network and information systems.
  • Art. 23 - significant incidents are notified to the sector CSIRT using the prescribed template. The notification does not create increased liability for the notifying party.
  • Art. 24 - the Council of Ministers may require the use of ICT products and services certified under the European cybersecurity certification schemes.
  • Art. 26 - a coordinated risk assessment at EU level is possible for critical supply chains.
04

Who supervises and who receives the notifications

The Act distributes the obligations among several institutions. This is practical information for every team: it matters to know which authority receives the notifications, which one designates the obliged entities and which one imposes the measures.

  • Sector CSIRT - sector computer security incident response team; receives notifications of significant incidents (Art. 23)
  • National CSIRT - national computer security incident response team; responds to incidents at national level
  • Single point of contact - national single point of contact; coordinates with partners in the European Union
  • NCA - national competent authorities (Art. 16); designate the essential and important entities and supervise compliance
  • MEU - Ministry of Electronic Governance; the minister conducts the policy and coordinated vulnerability disclosure
  • CRC - Communications Regulation Commission; takes part in setting the minimum scope of measures for electronic communications
05

What the penalties are

The Act provides for a pecuniary penalty for failure to comply with the obligations under Art. 22 and Art. 23: up to 10 000 000 euro or up to 2% of total worldwide annual turnover for an essential entity, and up to 7 000 000 euro or up to 1.4% for an important entity, whichever amount is higher.

A characteristic feature of the Bulgarian transposition is that minimum amounts have also been set: not less than 25 000 euro for an essential entity and not less than 12 500 euro for an important entity. Separately, a personal fine is provided for managers in the event of a breach of the obligations under Art. 21.

  • The full description with articles and amounts is on the penalties page.
06

What this means for the team

The hardest part is not adopting the measures, but maintaining evidence that they have been adopted, applied and reviewed. That is exactly where the usual tools break down: the documents are in folders, the decisions are in emails, and the tasks are tracked separately.

That is why the work needs structure: an assessment of the current state against the requirements, linked evidence, identified gaps, tasks with an owner and a deadline, and a separate review of the result. This is also the logic of the platform - it does not replace judgement, but makes it traceable.

Next step

Turn the requirements into a traceable process.

Show us how you work today and we will follow one requirement from the assessment to the verified action.

Request a demo