On 5 February 2026, the Bulgarian National Assembly adopted final amendments to the Cybersecurity Act, replacing the 2018 framework and fully aligning national legislation with the EU NIS2 Directive.
Key changes include:
- Expansion of the regulated scope to 18 sectors, adding areas such as manufacturing, food production, and waste management.
- Introduction of personal responsibility for senior management regarding the implementation and oversight of cybersecurity measures.
- Significant penalties for essential entities, reaching up to EUR 10 million or 2% of global annual turnover.
- A new 24‑hour incident reporting requirement, reinforcing cybersecurity as a core operational obligation for businesses in Bulgaria.
- Temporary reduction of fines during the initial months after the Act enters into force to support a smoother transition for affected organizations.
- Authorization for the Ministry of е-Government to restrict the use of specific applications or websites on government‑issued devices (e.g., the potential prohibition of TikTok for civil servants).
- Provision for limiting high‑risk technologies originating from third countries, based on coordinated EU‑level risk assessments (pending implementation at EU level).
At last Bulgaria’s cybersecurity standards match those of the other EU countries, eliminating the risk of significant fines stemming from its delayed transposition of NIS2.
This article was prepared by Nikola Stoychev, Partner at Dimitrov, Petrov & Co. (DPC) Law Firm. For more information, please contact DPC via the following link.