NIS2 in Bulgaria — no transition period; obligations live since 17 February 2026.
Bulgaria transposed NIS2 by amending its 2018 Cybersecurity Act — adopted on 5 February 2026, promulgated on 13 February, and in force on 17 February 2026, sixteen months past the EU deadline. The structure is a coordinator-plus-regulators model: a National Cybersecurity Coordinator oversees the regime while sectoral regulators supervise their own sectors — the BNB for banks, the CRC for electronic communications, the FSC for capital markets.
What makes Bulgaria singular is the absence of any runway. Risk-management, governance and incident-reporting obligations applied in full from day one — there is no transition period. The only softening was temporary: a 50% reduction on fines for violations committed before 1 June 2026. Entities register in a non-public register maintained by the e-government ministry (since May 2026 part of the Ministry of Innovation and Digital Transformation) within three months of falling into scope — for day-one entities, that window closed around 17 May 2026. Fines reach the directive ceilings, and members of management bodies face personal fines of EUR 500 to EUR 5,000.
Who it applies to
Essential and important entities across the NIS2 sectors meeting the medium-enterprise thresholds, plus certain providers regardless of size — public electronic communications networks, trust services, TLD registries, DNS providers, and sole providers of critical services. Registration is within three months of falling into scope, in the ministry's non-public register; failing to register is itself a sanctionable breach. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.
The clock
Competent authority: National Cybersecurity Coordinator · sectoral regulators. Transposition: Act amending the Cybersecurity Act (State Gazette No. 17/2026).
| When | What happens |
|---|---|
| 17 Feb 2026 | Amended Cybersecurity Act in force — all obligations apply immediately, no transition |
| 17 May 2026 | Three-month registration window closes for day-one entities |
| 1 Jun 2026 | 50% fine reduction ends — full penalties apply |
| 17 Oct 2026 | Two ordinances setting minimum security measures due |
The compressed transposition — everything was due yesterday
Bulgaria is the opposite of Portugal. Where Portugal legislated late but gave entities until 2028 to reach full measures, Bulgaria legislated late and gave entities nothing: the amended act applies from the day it entered into force, and the only transitional relief — half-price fines — expired on 1 June 2026. Meanwhile parts of the regime are still being built: the deadline for designating sectoral competent authorities passed on 17 August 2026, and the two ordinances setting minimum security measures are due by 17 October 2026. Bulgarian entities are therefore fully liable under a regime whose detailed rules are still arriving. TruSecure's answer is to anchor on what is fixed — the directive's measures, the registration duty, the reporting clocks — and to track the pending ordinances as dated regulatory-watch items, so the file updates when the detail lands instead of being rebuilt.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Bulgaria transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register within three months — non-registration is itself a breach | Entity profile · registration facts held as dated records |
| Meet the obligations with no transition period | Control library · directive measures mapped now, ordinances tracked |
| Report incidents: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Show management oversight — personal fines of EUR 500–5,000 | Governance workspace · approvals and training records, dated |
| Track the pending measures ordinances (due 17 Oct 2026) | Regulatory watch · the file updates when the detail lands |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Registration
- filed 30 Apr 2026 · ministry non-public register
- Scope basis
- essential entity · in scope from entry into force
- Controls evidenced
- 64/96 · directive baseline; ordinances watch active
- Incident reports
- 0 filed · workflow tested against the clocks
- Export
- sealed · sha256:97d4...b2e6
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your registration position confirmed, the directive baseline mapped while the ordinances land, and the reporting clocks rehearsed. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Bulgaria by National Cybersecurity Coordinator · sectoral regulators. TruSecure determines applicability against Bulgaria's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.