NIS2 and the Bulgarian Cybersecurity Act: scope, personal liability and contractual consequences

Directive (EU) 2022/2555 (NIS2) was transposed into the Bulgarian Cybersecurity Act (the CSA) by amendments promulgated in the State Gazette, issue 17 of 13 February 2026. The reduced penalties ceased to apply on 1 June 2026. This article addresses the scope of the regime, the liability of management bodies and the contractual consequences for companies which formally remain outside the scope of the Act.

Download the full newsletter in PDF (BG/EN)

1. The new legal framework

1.1. What Parliament adopted. On 5 February 2026 the National Assembly adopted the Act amending and supplementing the CSA. It was promulgated in the State Gazette, issue 17 of 13 February 2026, and entered into force on the same date. Through it Bulgaria took the national measures transposing NIS2, which replaced Directive (EU) 2016/1148 (NIS1).

A point of terminology with practical significance: the Directive itself does not become Bulgarian law. The transposing instrument is the national act, while the Directive remains an act of European Union law capable of producing vertical direct effect only under the conditions established in the case-law of the Court of Justice.

The change is not editorial. NIS1 covered a narrow group of operators of essential services. NIS2 establishes a regime which, in its scope, supervisory powers and severity of penalties, approaches the model of the General Data Protection Regulation.

1.2. Deadlines already running. The obligations under Articles 22 and 23 CSA have applied since 13 February 2026. They are not deferred pending secondary legislation. Until 1 June 2026 a transitional regime halved the penalties; the full amounts now apply.

The ordinance under Article 3(2) CSA, which will set the minimum scope of the measures, is still to be adopted. The accurate formulation is this: part of the duties are laid down in the Act itself, while the minimum scope of the measures and the procedural detail depend on the secondary rules. It does not automatically follow that any infringement may be penalised without difficulty before the ordinance is adopted, since the principle of legality and the requirement of sufficient precision carry particular weight in administrative penal matters.

2. Scope of the Act

2.1. The sectors in Annexes I and II. Annex I covers the sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, business-to-business ICT service management and space. Annex II covers postal and courier services, waste management, chemicals, production, processing and distribution of food, manufacture of medical devices and in vitro diagnostic medical devices, computers, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles and other transport equipment, digital providers and research organisations.

The summary above is intended for orientation. Each category is specifically described in the Annexes, and applicability is assessed against that description rather than against the general name of the sector.

Administrative authorities (Article 4(1) CSA) and the bodies of the judiciary (Article 4(9) CSA) also fall within scope. Their bases are not identical, however: Article 4a(1)(4) CSA classifies administrative authorities as essential entities but does not place the bodies of the judiciary in the same express category.

2.2. Size thresholds and the exceptions. Under Article 4(2) CSA the Act covers entities of the types listed in Annexes I and II which meet the criteria for medium-sized enterprises or exceed the ceiling for medium-sized enterprises and which provide services or carry out activities within the European Union.

The exceptions are underestimated. Regardless of size, Article 4(3) CSA brings within scope providers of public electronic communications networks and services, trust service providers, DNS service providers, top-level domain name registries, the sole provider of a service of essential importance, entities whose disruption could affect public safety, security or health, entities whose disruption could give rise to significant systemic risk, and entities of critical importance nationally or regionally. Separately, Article 4(5) CSA covers entities providing domain name registration services.

2.3. Relationship with sector-specific acts and DORA. Under Article 6a CSA a sector-specific act of equivalent effect displaces the CSA, but only in respect of the entities and the matters that act governs. Regulation (EU) 2022/2554 (DORA) is such an act in respect of certain financial entities.

It is not correct to assert without qualification that DORA excludes the application of the CSA. The assessment has three steps: (i) whether the entity in question falls within the scope of DORA; (ii) whether its specific obligations, including notification, are governed by DORA; and (iii) whether national rules on coordination, competence or activities not covered remain applicable.

2.4. Essential and important entities. Article 4a(1) CSA sets out seven categories of essential entities: Annex I entities exceeding the ceiling for medium-sized enterprises; qualified trust service providers, top-level domain registries and DNS service providers regardless of size; medium-sized providers of public electronic communications networks or services; administrative authorities; critical entities under Directive (EU) 2022/2557; the entities under Article 4(3)(d) to (g); and the existing operators of essential services. Important entities are the remaining entities under Annex I or Annex II (Article 4a(2) CSA). The distinction governs the intensity of supervision and the maximum penalty.

2.5. Who designates the entities. Official designation is not made by the entities themselves. Under Article 16(3)(8) CSA the national competent authorities designate them in accordance with a methodology adopted by the Council of Ministers.

That does not mean entities have no obligations of their own. The Minister of Innovation and Digital Transformation maintains a register which is not public (Article 6(5) CSA), and entities must notify the relevant national competent authority of any change in the data provided within two weeks (Article 6(3) CSA).

This is the principal practical risk. Designation is still pending, whereas the obligations under Articles 22 and 23 CSA have applied since February 2026. Waiting for an official notification is no defence in a subsequent inspection.

3. Liability of management bodies

For the first time Bulgarian cybersecurity legislation imposes express obligations on the management body as such.

Under Article 21 CSA, management bodies approve the cybersecurity risk management measures and oversee their implementation (paragraph 1). Their members must undergo training every two years (paragraph 2), a requirement stricter than that of the Directive, which uses a general formulation. Management bodies must also offer and organise such training for employees (paragraph 3).

An important qualification: the Act does not prohibit assigning technical or operational execution to an internal function or to an external provider. What remains with the management body is approval, oversight and training. Responsibility under Article 21 CSA is not transferred by outsourcing, but this does not mean that every technical activity must be carried out personally by the members of the body.

Consequences of non-compliance. Under Article 29(4) CSA a fine of EUR 500 to EUR 5,000 is imposed on heads of administrative authorities, on managers and on members of management bodies. That liability is independent of any penalty imposed on the entity.

It is not, however, automatic. An infringement of Article 21 CSA attributable to the person concerned is required. The case-law of the Supreme Administrative Court in comparable matters holds that a manager bears personal administrative penal liability where personal culpable conduct is established, and not by reason of holding the office alone.

For essential entities, Article 27k(2) CSA provides a more severe consequence: the national competent authority may ask a court or another State body to impose a temporary ban on a person exercising managerial functions. The measure applies where the steps required under Article 23 CSA or under Article 27i(1)(1) to (4) and (6) CSA are not taken, rather than upon any infringement of the Act, and it does not apply to administrative authorities (Article 27k(4) CSA).

4. Risk measures and the supply chain

Article 22(2) CSA lists twelve points, eleven of which set out specific measures. Some apply where appropriate, and the assessment is made against the degree of risk exposure, the size of the entity, the likelihood of an incident, its significance, the societal and economic impact, the cost and the state of the art: (i) risk analysis and security policies; (ii) incident handling; (iii) business continuity and recovery; (iv) supply chain security; (v) security in acquisition and maintenance; (vi) assessment of the effectiveness of the measures; (vii) cyber hygiene and training; (viii) cryptography and encryption; (ix) human resources security, access control and asset management; (x) multi-factor or continuous authentication, secured communications and secured emergency communication systems; (xi) change management.

The contractual dimension. Article 22(2)(4) CSA turns supply chain security into a statutory duty. Under paragraph 3, the vulnerabilities specific to each direct supplier or service provider and the quality of its practices, including its secure development procedures, must be taken into account.

This produces the consequence with the widest reach: entities within the scope of the CSA are likely to impose security requirements contractually on their direct suppliers, including suppliers outside the scope of the Act.

The formulation is deliberately cautious. Article 22 CSA does not of itself bind a company outside the scope. A contractual obligation arises where the requirements are validly incorporated into the contract or follow from another applicable regime. Contracts therefore call for review as regards: (i) security requirements; (ii) audit rights and evidence of compliance; (iii) contractual notification deadlines aligned with the customer’s 24-hour deadline towards the CSIRT; (iv) liability; (v) requirements for subcontractors. These mechanisms are reasonable, but Article 22 CSA does not prescribe them as an exhaustive set of mandatory clauses, and the 24-hour deadline is the entity’s deadline towards the CSIRT which does not pass automatically to its suppliers.

5. Reporting of significant incidents

Notification is made to the sectoral computer security incident response team (CSIRT) in the following sequence (Article 23(5) CSA):

  1. within 24 hours of becoming aware, an early warning stating, where applicable, suspected malicious acts and cross-border impact;
  2. within 72 hours, a notification with an initial assessment of severity and impact; for trust service providers the deadline is 24 hours;
  3. upon request, an intermediate report;
  4. within one month of the notification under point 2, a final report. If the incident is not resolved by the expiry of that period, an intermediate report is filed and the final report is submitted within one month of resolution.

The CSIRT sends a response no later than 24 hours, unless objective reasons prevent compliance with that deadline, in which case the response is sent as soon as possible (Article 23(6) CSA).

Notifying the recipients. Article 23(2) CSA is frequently overlooked. The entity must notify the recipients of its services of significant incidents likely to affect adversely the provision of those services, such notification being made where appropriate and without undue delay. In exceptional circumstances a delay is permitted with the consent of the relevant national competent authority.

Separately, Article 23(4) CSA requires the entity to communicate to the recipients the measures and remedies they may take and, where appropriate, the nature of the significant cyber threat.

Notification to the CSIRT does not entail increased liability (Article 23(1) CSA). Failure to notify is an independent ground for a penalty.

Interaction with the GDPR. Article 16(12) CSA provides for cooperation between the national competent authorities and the Commission for Personal Data Protection in respect of incidents resulting in a personal data breach. Under Article 27n CSA, if that Commission has already imposed a fine for the same conduct, no second financial penalty is imposed. The bar should not be treated as automatic in every parallel proceeding.

6. Supervision and penalties

Chapter Two „c“ CSA (Articles 27e to 27o) governs supervision.

Essential entities are subject to ex ante supervision: scheduled and unscheduled inspections, regular and targeted security audits, requests for information and access to documents (Article 27g(1) CSA). Important entities are subject to ex post supervision: on-site inspections and remote supervision, targeted audits, security scans based on objective and transparent risk assessment criteria, and requests for information and evidence (Article 27g(2) CSA). The ex post character of that supervision does not mean that every inspection presupposes an established infringement.

The cost of a targeted audit carried out by an independent body is borne by the audited entity (Article 27h(3) CSA), and the competent authority may order the entity to make the infringement public (Article 27i(1)(7) CSA).

Essential entities Important entities
Who Seven categories under Article 4a(1) CSA The rest under Annexes I and II
Supervision Ex ante Ex post
Maximum penalty, whichever is higher EUR 10,000,000 or 2% of turnover EUR 7,000,000 or 1.4% of turnover
Minimum for Articles 22 and 23 EUR 25,000 EUR 12,500
Management ban Possible Not applicable

Two qualifications to the table. First, the percentage is calculated on the total worldwide annual turnover for the preceding financial year of the undertaking to which the entity belongs, and not necessarily on the turnover of the entity alone. Second, the amounts of EUR 25,000 and EUR 12,500 are the lower limits under Article 29(2) and (3) CSA for infringements of Articles 22 and 23 CSA, and not a general minimum penalty for every infringement of the Act.

Failure to comply with an order under Article 27i(1)(2) to (7) CSA attracts a fine of EUR 2,500 to EUR 12,000, and EUR 5,000 to EUR 25,000 for a repeated infringement (Article 28 CSA).

7. What comes next

Designation of the entities and the ordinance under Article 3(2) CSA are pending. Until then the priorities are four:

  1. assess scope, including under the exceptions which do not depend on size and under the relationship with sector-specific acts;
  2. run a gap analysis against Article 22 CSA;
  3. build a 24-hour notification process, including notification of the recipients of the services;
  4. review contracts with customers and suppliers.

Questions about whether the CSA applies to your company?
Contact us for a scope assessment, a gap analysis against Article 22 CSA and a contract review.

Yavor Stoychev, LL.M., PhD (cand.), MAcc, Attorney-at-Law – Managing Partner
Mirela Lazarova, LL.M., Attorney-at-Law – Managing Associate
office@stoychevlaw.com | +359 2 43 700 73

This publication has been prepared by Stoychev & Stoycheva Law Firm to provide general information and does not constitute legal advice. Before taking any action that may impact your finances or business, please consult a qualified attorney.