Legal framework

Penalties under the Cybersecurity Act

The amounts set out in the law, with the relevant articles - including the minimum values and the fine for managers, which are often left out of summaries.

01

What the law provides

The law sets a pecuniary penalty for failure to comply with the obligations under Art. 22 and Art. 23. The amount depends on whether the entity is essential or important, and is determined as the higher of two values: a fixed upper limit or a percentage of turnover.

A particularity of the Bulgarian transposition is that, in addition to an upper limit, minimum amounts are also set. This means that even for a small organisation the penalty has a lower bound, rather than being reduced to a token sum.

The penalty is not the only consequence. A separate personal fine is provided for managers in the event of an infringement of the obligations under Art. 21, as well as a penalty for failure to comply with a coercive administrative measure.

02

How the amount is determined

In determining the penalty, the circumstances under Art. 29b are taken into account: the degree of impact, the duration, the remedial action taken, cooperation with the authorities and previous infringements. This means that a documented response matters.

This has a practical consequence. If the organisation can show when it identified the problem, what it did, and who confirmed the result, the conversation with the supervisory authority is conducted with evidence, not with assumptions.

  • The penalty is imposed independently of the coercive administrative measures the authority may apply.
  • When a supervisory authority under Regulation (EU) 2016/679 imposes a penalty for the same act, the competent authorities under this law may impose only measures, not a second pecuniary penalty.
  • For infringements committed up to 1 June 2026, fines and pecuniary penalties are imposed at amounts reduced by 50 per cent (Final provisions, § 51).
03

What this means in practice

The penalty rarely comes from the absence of a single measure. Much more often it comes from the inability to prove that the measures were adopted, applied and reviewed. The absence of a trail is treated as the absence of a process.

That is why the approach that works is the reverse of intuition: first the scope is determined, then the current state is assessed, and evidence is attached to every answer. The gaps identified become tasks with an owner and a deadline, and the result goes through a second-person review.

Next step

The penalty is measured in evidence, not in intentions.

We will show you what a traceable process looks like: from the assessment to the verified result, with an owner and a deadline for every gap.

Request a demo

Amounts by type of entity

Art. 29(2)

Essential entity

up to 10 000 000 euro or up to 2% of total worldwide annual turnover, the higher amount applies

not less than 25 000 euro

Legal basis: failure to comply with the obligations under Art. 22 and Art. 23

Art. 29(3)

Important entity

up to 7 000 000 euro or up to 1.4% of total worldwide annual turnover, the higher amount applies

not less than 12 500 euro

Legal basis: failure to comply with the obligations under Art. 22 and Art. 23

Art. 29(4)

Managers and directors

a fine of 500 to 5 000 euro

Legal basis: infringement of the obligations under Art. 21

Art. 28

Failure to comply with a coercive measure

from 2 500 to 12 000 euro, for a repeated infringement, from 5 000 to 25 000 euro

Legal basis: failure to comply with a coercive administrative measure under Art. 27i

For infringements committed up to 1 June 2026, fines and pecuniary penalties are imposed at amounts reduced by 50 per cent (Final provisions, § 51).