Bulgaria Adopts Amendments to the Cybersecurity Act in Line with NIS 2

16/04/2026

The National Assembly adopted, at second reading, amendments to the Cybersecurity Act introducing expanded European requirements for risk assessment and incident reporting. With these changes, Bulgaria transposes the provisions of the NIS 2 Directive, aimed at achieving a high level of security of network and information systems across the European Union.

Expanded scope of the law

The new legislation significantly broadens the scope of affected organizations. In addition to previously covered entities, it now includes:

  • public and private organizations
  • providers of qualified trust services
  • domain name registries
  • educational institutions conducting critical scientific research
  • judicial authorities

The number of sectors covered by the law increases from 8 to 18, with new additions including:

  • space sector
  • wastewater management
  • ICT services between enterprises
  • postal and courier services
  • waste management
  • production and distribution of chemicals and food
  • manufacturing industries (including medical devices, electronics, machinery, and automotive)
  • providers of digital services
  • scientific research

New incident reporting requirements

The law introduces stricter rules for notifying cyber incidents. Organizations classified as essential and important must:

  • notify the relevant sectoral CSIRT team within 24 hours of detecting an incident
  • within 72 hours provide updated information and an initial assessment (including severity, impact, and technical details)
  • submit a final report within one month after the update

For providers of trust services, the deadline for updating information is 24 hours.

Control over technologies used

The adopted amendments also introduce mechanisms for controlling the technologies used. Upon proposal by the Cybersecurity Council, the Council of Ministers may require organizations to use:

  • specific ICT products and services
  • technologies certified under European cybersecurity schemes
  • solutions proven effective from both operational and economic perspectives

Additionally, at the EU level, risk assessments may lead to proposals to restrict certain technologies or supply chains, particularly when originating from non-EU countries.

If a technology is restricted by a government decision, organizations must discontinue its use within three years, except in cases of high national security risk, where the deadline may be shorter.

Importance of the changes

According to the acting Minister of e-Government, the adoption of these amendments marks an important step toward strengthening Bulgaria’s national cybersecurity.

The new rules aim to improve risk management, incident response, and control over critical technologies, while aligning national legislation with European standards.

Fortinet Launches FortiSOC: Unified AI-Powered Platform for Modern Security Operations
03/08/26

Fortinet has announced the availability of FortiSOC, a new cloud-delivered Security Operations Center (SOC) platform that combines SIEM, SOAR, t...

Google Encourages Developers to Embrace AI for PostgreSQL Development
31/07/26

Google Cloud is encouraging its engineers to make extensive use of AI-powered coding tools when contributing to PostgreSQL and other open-source...

SAP Will Provide AI Capabilities for ECC and On-Premises S/4HANA Environments
27/07/26

SAP is changing its previous strategy and will make part of its AI solutions available to customers using SAP ECC and on-premises SAP S/4HANA en...

Extreme Networks CEO: Delivering Predictability, Simplicity and AI-Driven Networking for the Channel
24/07/26

Extreme Networks is strengthening its channel-first strategy with predictable pricing, simplified licensing, and new AI-powered networking capab...

Huawei Recognized as a Leader in the 2026 Gartner Magic Quadrant for Enterprise Wired and Wireless LAN Infrastructure for the Fourth Consecutive Year
20/07/26

Huawei has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Enterprise Wired and Wireless LAN Infrastructure for the fourt...