Bulgaria transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Act Amending and Supplementing the Cybersecurity Act (Zakon za izmenenie i dopalnenie na Zakona za kibersigurnost), adopted by the 51st National Assembly on 5 February 2026 and promulgated in the State Gazette, issue 17, on 13 February 2026, well past the Directive's 17 October 2024 transposition deadline.
The amended Cybersecurity Act (Zakon za kibersigurnost, ZKS, originally promulgated as State Gazette No. 94 of 2018) now binds every essential and important entity the competent authorities designate by sector under the Act's annexes, which the amendment expands to name, among the newly reached digital service providers, a provider of an online marketplace, an online search engine, or a social networking services platform.
Article 22 sets the risk-management measures each essential or important entity must take, transposing NIS2 Article 21, with Article 21 putting approval and oversight of those measures on the entity's own management body and requiring every management-body member to complete cybersecurity training every two years.
Article 23 sets a 24-hour early-warning, 72-hour incident-notification, and one-month final-report clock for reporting a significant incident to СЕРИКС, the sectoral Computer Security Incident Response Team, transposing NIS2 Article 23.
Chapter Three's Article 29 arms both duties with a fine or property sanction of up to EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, whichever is higher but not less than EUR 25,000, and up to EUR 7,000,000 or 1.4 percent for an important entity, not less than EUR 12,500, plus a personal fine of EUR 500 to 5,000 on a management-body member for an Article 21 governance failure; a violation committed before 1 June 2026 carried a fine reduced by half from these figures under the amending Act's own transitional provision.
No Bulgarian instrument found here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and not restated here.
No general reasonable-security or information-security-programme statute with no sector gate was found; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Personal Data Protection Act's breach-notification duties to the Commission for Personal Data Protection, both of which sit in the privacy topic rather than here.
Both the risk-management and incident-reporting duties bind a wider class of essential and important entity by sector and size that no activity in this vocabulary expresses; only the digital-provider slice of that class (an online marketplace, online search engine, or social networking services platform) is flagged here, and the broader sector classes the amended annex names (energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, and others) are recorded here as law the lint does not yet reach rather than flagged on a guess.