SNM Support

NIS2 Compliance in Bulgaria: Is Your Company Affected?

Monday morning. The managing director of a manufacturing company in Sofia opens an email from a major customer: "Please complete the attached cybersecurity questionnaire and confirm compliance with NIS2 requirements by the end of the month." The company has 60 employees, one server in the warehouse, and accounting software that "just works." The first question is: does this even apply to us? The second: where do we start? If you're asking the same questions, this article gives you a clear picture of NIS2 compliance in Bulgaria — what the law says, who it affects, and the first practical steps.

An important note: this article is for information only and is not legal advice. For a definitive assessment of whether your organization is in scope, consult a lawyer or the competent authority. At SNM Support we help with the technical side — the measures the law actually requires you to put in place.

What NIS2 is and why it matters right now

NIS2 is Directive (EU) 2022/2555 — the EU-wide cybersecurity framework that replaced the original NIS Directive from 2016. Its goal is to raise the baseline level of protection in key sectors of the economy across the European Union.

Bulgaria transposed the directive through amendments to its Cybersecurity Act. Parliament adopted them on February 5, 2026; they were published in the State Gazette, issue 17, on February 13, 2026, and have been in force since February 17, 2026. That closed Bulgaria's transposition more than a year after the EU deadline of October 2024.

October is also European Cybersecurity Month — an annual campaign run by ENISA and the European Commission. It's a good moment to check where your company stands.

Who falls under NIS2 in Bulgaria

The old system, in which the state designated specific "operators of essential services," has been replaced by scope based on sector and company size. There are now 18 sectors.

Sectors of high criticality

Energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, ICT service management (for example, managed IT service providers), public administration, and space.

Other critical sectors

Postal and courier services, waste management, chemicals, production and distribution of food, manufacturing (including medical devices, electronics, machinery, and vehicles), digital providers (online marketplaces, search engines, social networks), and research.

The size threshold

As a rule, medium and large enterprises in these sectors are in scope. As a guide, a medium enterprise has 50 or more employees, or annual turnover and a balance sheet above €10 million. Some categories are covered regardless of size — for example DNS service providers, top-level domain registries, trust service providers, and providers of public electronic communications networks.

Essential and important entities

The law divides covered organizations into two categories. Essential entities are mostly large enterprises in the high-criticality sectors. Important entities are the other organizations in scope. The obligations are similar, but the level of supervision and the size of the penalties differ.

How entities are identified

In Bulgaria, entities are identified by the national sectoral competent authorities under a methodology adopted by the Council of Ministers, and entered in a national register kept by the Minister of e-Government. As of late summer 2026, the methodology and the updated ordinance with the minimum requirements were still pending. Legal analyses agree, however, that the obligations for security measures and incident reporting have applied since February 17, 2026, and that registration is an administrative step. Don't wait for a letter from the government — check the status of these acts with the competent authority or your lawyer.

"We're a small company" — the supply chain effect

Even if your company is below the threshold, NIS2 can affect you indirectly. The law requires covered organizations to manage the risk that comes from their suppliers and subcontractors. In practice, this means:

  • large customers will send you security questionnaires;
  • contracts will start to include clauses on multi-factor authentication, backups, and incident notification;
  • you may be asked for evidence — policies, logs, audit results.

An accounting firm serving a hospital, an IT company maintaining a courier firm's network, or a small manufacturer supplying a food chain — all of them may soon be asked, "How do you protect our data?" A well-prepared supplier earns trust and wins contracts.

What measures the Cybersecurity Act requires

The law requires "appropriate and proportionate" technical, operational, and organizational measures. The specific minimum requirements are detailed in an ordinance, but the main areas are clear.

Risk management

  • risk analysis and information system security policies;
  • incident handling and a response plan;
  • business continuity — backups, disaster recovery, and crisis management;
  • supply chain security;
  • security in acquiring, developing, and maintaining systems, including vulnerability management;
  • encryption, where appropriate;
  • access control and asset management;
  • multi-factor authentication and secured communications;
  • basic cyber hygiene and staff training.

Incident reporting

For a significant incident, the deadlines are tight:

  1. Within 24 hours — an early warning to the computer security incident response team (CSIRT).
  2. Within 72 hours — an incident notification with an initial assessment.
  3. Within 1 month — a final report.

If personal data is involved, the 72-hour GDPR deadline for notifying the Commission for Personal Data Protection runs in parallel — more on that in our article GDPR: Taking Stock Seven Years On.

Management accountability

This is one of the most significant changes. The management body approves the cybersecurity risk-management measures and oversees their implementation. Its members must complete cybersecurity training at least once every two years and make sure employees are trained as well. Cybersecurity is no longer "an IT task" — it's a management responsibility.

Penalties

The maximum fines follow the directive:

  • essential entities — up to €10 million or 2% of worldwide annual turnover (whichever is higher);
  • important entities — up to €7 million or 1.4% of worldwide annual turnover;
  • members of management — personal fines from €500 to €5,000.

The law provided for reduced penalties for violations committed before June 1, 2026 — that period has now ended. Check the current text of the law for the exact minimum amounts and conditions.

A practical checklist: first steps toward NIS2 compliance in Bulgaria

You don't need to start with thick manuals. Here's a realistic plan for the first few weeks:

  1. Determine whether you're in scope — sector, headcount, turnover. If in doubt, get legal advice.
  2. Check your customers — which of them are covered by NIS2, and what they will ask of you.
  3. Build an asset inventory — computers, servers, cloud services, network equipment, accounts.
  4. Turn on multi-factor authentication for email, VPN, cloud services, and every admin account.
  5. Check your backups — the 3-2-1 rule, an offline copy, a tested restore. There's a detailed guide in our article Data Backup: The Complete Guide for Small Business.
  6. Set up centralized logging — without logs, you can't tell what happened or report on time.
  7. Update your systems — operating systems, router and firewall firmware, applications.
  8. Write an incident response plan — who notifies whom, about what, and by when.
  9. Document your policies — access control, passwords, backups, remote work.
  10. Train your team and management — phishing, passwords, reporting suspicious events.

Many of these measures are the same ones we recommend to every business — see also Cybersecurity for small business — 10 essential measures.

Frequently Asked Questions

Does NIS2 affect small businesses in Bulgaria?

Directly — as a rule, no, since the threshold is a medium-sized enterprise, except for certain specific categories such as DNS providers and trust service providers. Indirectly — yes: if you supply products or services to a covered organization, it must assess the risk you pose as a supplier and will likely set requirements in your contract.

Do we have to register ourselves?

Under Bulgarian law, entities are identified by the sectoral competent authorities using a Council of Ministers methodology and entered in a register kept by the Minister of e-Government. The obligations for security measures, however, have applied since February 17, 2026. Check the current procedure with the competent authority or a lawyer.

What are the incident reporting deadlines?

An early warning within 24 hours, a notification with an initial assessment within 72 hours, and a final report within one month. To meet these deadlines, you need a plan prepared in advance, clearly assigned responsibilities, and logs that let you establish what happened.

Can SNM Support certify us as NIS2 compliant?

No — we don't issue legal opinions or compliance certificates. We help with the technical measures: IT environment audits, multi-factor authentication, backups, logging, network security, and documenting your policies. That's the foundation your lawyer or compliance consultant can build the compliance assessment on.

How SNM Support helps with NIS2

The law requires measures, and measures need someone to implement and maintain them. We help companies in Sofia and across Bulgaria with the technical preparation:

  • an audit and gap assessment — where your IT environment stands against the requirements;
  • rolling out multi-factor authentication, backups, and centralized logging;
  • upgrading and securing the network, firewalls, and segmentation;
  • documenting your security policies and procedures;
  • ongoing support and monitoring through subscription IT support.

Don't wait for the customer questionnaire or the regulator's inspection. Request an IT security audit — get in touch with us for a free initial consultation.