In short: The amendments to Bulgaria’s Cybersecurity Act, published on 13 February 2026, bring in the requirements of the EU’s NIS2 directive. As a rule they cover medium-sized and large companies in certain sectors, and through supply chain requirements they also reach those companies’ suppliers. Significant incidents are reported with an early warning within 24 hours and a notification within 72 hours of becoming aware of them, and a final report is due within one month of the notification. Fines reach €10 million or 2% of turnover, and members of management can be fined too.
What has changed in Bulgaria’s Cybersecurity Act?
Bulgaria’s National Assembly adopted the Act amending and supplementing the Cybersecurity Act on 5 February 2026, and the text was published in the State Gazette, issue 17 of 13 February 2026. It transposes Directive (EU) 2022/2555, known as NIS2, around 16 months after the EU deadline.
Until now the rules mainly concerned operators of key services such as energy, transport and banking. The scope is now much wider and includes sectors where many mid-sized companies operate. The law divides the organisations it covers into two groups: essential entities and important entities. The group determines the level of supervision and the size of fines.
What does this mean for your business? If your company is in one of the sectors and is at least a medium-sized enterprise, it is sensible to assume the law probably applies to you until you have checked otherwise.
Is your company in scope?
1. Check your sector
The law lists two kinds of sectors. The first group includes energy, transport, banking, financial market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, ICT service management and space. The second group includes postal and courier services, waste management, chemicals, food production and distribution, manufacture of medical devices and electronics, digital service providers and research.
2. Check your size
As a rule, the directive covers medium-sized and large enterprises in these sectors. As a guide, a company with 50 or more employees, or with annual turnover and balance sheet total both above €10 million, is no longer small. Size is determined under the Small and Medium-Sized Enterprises Act, with the exceptions set out in the Cybersecurity Act. If in doubt, check with a lawyer.
There are also exceptions where size does not matter, such as DNS service providers, top-level domain name registries, trust service providers and providers of public electronic communications networks.
3. Check your role as a supplier
Even if your company is not directly in scope, the law requires the organisations it covers to manage supply chain security, including their relationships with direct suppliers. In practice, if you supply software, hosting, website maintenance, accounting or logistics services to such an organisation, it may ask you for evidence of security measures, contract clauses or answers to a questionnaire. That makes the topic important for IT companies serving other businesses too, even when they are not in scope themselves.
ScaleLab tip: Ask your larger clients whether they fall under NIS2 and what they will expect from their suppliers. It is better to find out now than when the contract comes up for renewal.
What are the incident reporting deadlines?
For a significant incident, Article 23(5) of the Cybersecurity Act sets the main deadlines. The early warning and the notification run from the moment you become aware of the incident. The final report is due no later than one month after the notification.
| Step | Deadline | What it contains |
|---|---|---|
| Early warning | Within 24 hours | That a significant incident has occurred |
| Incident notification | Within 72 hours | Initial assessment and technical details |
| Final report | Within one month of the notification | Description, causes and measures taken |
| Interim report | By the same deadline, if the incident is still ongoing | Progress in handling the incident |
If the incident is still ongoing when the final report deadline arrives, you file an interim report, and the final report is then due within one month of the incident being handled.
Twenty-four hours is not long. If nobody in the company knows who decides whether an incident is significant, who writes the notification and where it goes, the day is spent looking for answers. That is exactly why the response plan is written in advance.
What are the fines and management’s responsibilities?
The penalties are serious and depend on the group:
- Essential entities: up to €10,000,000 or up to 2% of total worldwide annual turnover, whichever is higher, with a minimum of €25,000.
- Important entities: up to €7,000,000 or up to 1.4% of total worldwide annual turnover, whichever is higher, with a minimum of €12,500.
- Members of management bodies: a fine of €500 to €5,000.
The law puts cybersecurity on the board’s agenda. Management bodies approve the risk management measures, oversee how they are applied and undergo training every two years so they can recognise risks and assess how security is managed. This is no longer a task that can be left entirely to the IT department or an outside supplier.
As of September 2026 there are two more things worth watching. According to Schoenherr, the detailed minimum requirements in secondary legislation were expected within eight months of the February 2026 amendments. We could not confirm whether they have been adopted, so check the official sources, such as the State Gazette. In addition, on 20 January 2026 the European Commission proposed targeted amendments to the NIS2 directive itself to increase legal clarity and ease compliance. Check how far negotiations on the proposal have progressed; until then the current law applies.
What should you do now? First steps
The directive lists the measures organisations in scope must put in place: risk analysis policies, incident handling, business continuity and backups, supply chain security, vulnerability handling, basic cyber hygiene and training, encryption, access control and asset management, and multi-factor authentication. You do not have to start with everything at once. We recommend the following order.
1. Make an asset inventory
Write down the systems, devices, accounts and data the company has: servers, cloud services, website, email, accounting software, laptops, phones. For each asset, note who is responsible for it and how important it is to the business. You cannot protect something you do not know about.
2. Carry out a risk assessment
For each important asset, ask what could happen, how likely it is and what the consequences would be. Start with the few scenarios that would stop the business: data encrypted by malware, a compromised email account, a website or online store that is down.
3. Write an incident response plan
The plan answers simple questions: who detects the incident, who decides whether it is significant, who sends the early warning within 24 hours, how systems are restored and how customers are informed. Run at least one tabletop exercise to see where the plan breaks down.
4. Review supplier security
List the suppliers with access to your systems or data. Check what the contracts say about security, incident notification and access, and where they need strengthening.
5. Put website and email basics in order
Many incidents start with things that are quick to fix. Check:
- Accounts: multi-factor authentication for email, hosting, the domain and the website admin area.
- Updates: regular updates to the website platform and its plugins. What this means for a WordPress site is covered in our article on WordPress security.
- Backups: automatic, stored separately from the website and tested with a real restore.
- Email: SPF, DKIM and DMARC set up, so it is harder for anyone to send email in your name. What each of them does is explained in our article on protecting email with SPF, DKIM and DMARC.
ScaleLab tip: Pick one date each month to check backups, stale accounts and pending updates. A short regular check does more than a big review once a year.
This article is general information, not legal advice. Whether a particular company is in scope and what its obligations are depends on its sector, size and activities, so consult a lawyer and follow current guidance from the competent authorities.
How to organise the work
NIS2 requirements look extensive, but at heart they ask for three things: know what you have, protect it sensibly and respond quickly when something happens. Check scope, list your assets and write the plan. If you would first like to see where your website and marketing stand today, start with a free website and marketing audit. Our work on cybersecurity and data protection starts with the website: checking for weaknesses, protecting the admin login, round-the-clock monitoring and incident response.
Frequently asked questions
Does NIS2 apply to small companies?
As a rule, the law covers medium-sized and large enterprises in the listed sectors. Some activities are covered regardless of size, such as DNS services and trust services. A small company can also be affected indirectly if it supplies an organisation that is in scope.
How quickly do we have to report an incident?
For a significant incident, an early warning is due within 24 hours and a notification with an initial assessment within 72 hours of becoming aware of it. The final report is due within one month of the notification, and if the incident is still ongoing, you file an interim report and then the final report within one month of the incident being handled. That is why it should be clear in advance who assesses the incident and who sends the notifications.
Can the managing director be fined personally?
Yes. The law provides for a fine of €500 to €5,000 for members of management bodies. Separately, the organisation can face a penalty of up to €10 million or 2% of turnover for essential entities and up to €7 million or 1.4% for important entities.
Where do we start if we have no IT department?
Start by checking whether you are in scope, then list your systems and data and assess the main risks. Quick measures such as multi-factor authentication, updates, backups and SPF, DKIM and DMARC for email can be put in place with outside help.
Sources
- State Gazette: Act amending and supplementing the Cybersecurity Act, issue 17 of 13 February 2026 (in Bulgarian)
- Schoenherr: Bulgaria implements NIS 2 Directive, key changes to the Cybersecurity Act
- EUR-Lex: Directive (EU) 2022/2555 (NIS2)
- European Commission: NIS2 Directive FAQs
- European Commission: NIS2 Directive, securing network and information systems
- EUR-Lex: Micro, small and medium-sized enterprises, definition and scope