Which companies fall within scope, and what management has to do about it
YARD Law Co. · Legal status checked 21 September 2026
Bulgaria has now transposed the NIS2 Directive. The new rules do not touch every company, but for businesses in certain sectors they turn cybersecurity from an IT matter into a direct duty of management, backed by reporting deadlines, supervision and substantial penalties.
The amendments to the Cybersecurity Act were promulgated in State Gazette No. 17 of 13 February 2026 and are in force. In June 2026 the Act was further amended in connection with institutional restructuring, and the central functions are now assigned to the Minister of Innovation and Digital Transformation. The practical question for a business is not whether it uses computers, but whether its particular activity, size and significance make it an essential or an important entity under the Act.
Scope is determined in a sequence of steps. First, whether the company is of a type listed in Annex I or Annex II to the Act. Then, the size of the undertaking and whether any of the exceptions applies under which size is irrelevant. Finally, whether the entity is essential or important.
| Group | Sectors | Examples of entities covered |
|---|---|---|
| Annex I | Sectors of high criticality | Energy, transport, banking, financial market infrastructures, health, drinking water and waste water, digital infrastructure, B2B ICT service management, public administration and space. |
| Annex II | Other critical sectors | Postal and courier services, waste management, chemicals, food, certain manufacturing, online marketplaces, online search engines, social networks and research organisations. |
As a general rule the Act covers public and private entities of the listed types that meet or exceed the criteria for medium-sized enterprises and operate or provide services in the EU. This means that micro and small enterprises do not, in principle, fall within scope automatically merely because they work in an affected sector.
The assessment should not be reduced to the headcount of the Bulgarian company alone. The relevant size-determination rules of the Small and Medium-Sized Enterprises Act should be applied, including the rules on linked and partner enterprises, together with the specific adjustment in Article 4(2) of the Cybersecurity Act. Groups of companies need a separate legal and factual review, not a mechanical comparison against a single financial figure.
Some entities fall within scope regardless of size. They include certain providers of public electronic communications networks or services, trust service providers, top-level domain name registries and DNS service providers. Individual designation is also possible, for example where the entity is the sole provider of an essential service, or where disruption of the service would create a significant risk to public safety, health or other sectors.
Broadly, large entities under Annex I are essential, and the remaining covered entities that do not meet the criteria for essential are important. The Act adds special categories of essential entities, including administrative authorities, certain critical entities, qualified trust service providers, top-level domain name registries and DNS service providers. The classification matters for the supervisory model and for the level of penalties.
Working with a bank, a hospital, an energy operator or another NIS2 entity does not automatically bring the supplier within the Act.
The real effect is different: the regulated client must manage supply-chain risk and will probably pass part of the requirements down through contracts, questionnaires, audits, notification rights and rules on subcontractors. A small supplier may therefore carry heavy contractual obligations without itself being an essential or important entity under the Act.
The Act does not require the purchase of a particular product or certificate. It requires appropriate and proportionate technical, operational and organisational measures, calibrated to the risk, the size of the entity, the likelihood of incidents and their possible societal and economic impact.
Documentation is part of compliance but is not sufficient on its own. On inspection the authority may require policies, data, audit results and evidence that the measures are actually applied. A policy without technical implementation, training and an audit trail is not real compliance.
Article 21 of the Cybersecurity Act requires management bodies to approve the cyber risk-management measures and to oversee their implementation. Members of management bodies must undergo training every two years and must offer and organise training for staff as well.
This is not automatic unlimited personal liability for every cyber incident. The personal penalty under Article 29(4) attaches to a breach of the management duties in Article 21 and ranges from EUR 500 to EUR 5,000.
Separately, where certain supervisory measures against an essential entity are not complied with, the competent authority may request a temporary prohibition on a natural person with managerial functions or a legal representative exercising such functions in the same entity. The risk to a director is therefore real, but it should be described precisely rather than as general strict liability for any attack.
Essential and important entities notify the relevant sectoral computer security incident response team. The deadlines run from becoming aware of the significant incident, not from the conclusion of the internal investigation.
| Deadline | Action |
|---|---|
| Within 24 hours | Early warning with the information available, including any suspicion of malicious action and possible cross-border impact. |
| Within 72 hours | Incident notification with an initial assessment of severity and impact. For trust service providers the deadline is 24 hours. |
| On request | Intermediate report with updated information. |
| Within one month | Final report. If the incident is still ongoing, an intermediate report is filed and the final report is due within one month of handling it. |
Other regimes can be triggered in parallel. If the incident is a personal data breach, the deadline and duties under the GDPR must be analysed separately. Further notifications may be required under sectoral legislation, contracts, insurance policies and to customers. An incident procedure has to allocate in advance who takes the decision, who preserves the evidence and who sends each notification.
The Act provides for a non-public central register. The national competent authorities designate essential and important entities under a methodology adopted by the Council of Ministers and supply the data for the register. For some digital providers there are also specific duties to submit and update data on their establishment in the EU.
It is not safe for a company to wait for an official letter. The duties under the Act are in force, while the secondary framework and the administrative designation roll out under the transitional deadlines during 2026. An organisation that probably falls within scope should document its own assessment and begin work on risk management, rather than treating the absence of a notification as an exemption.
| Addressee | Breach | Penalty |
|---|---|---|
| Essential entity | Failure to implement the measures under Article 22 or to report under Article 23 | Up to EUR 10 million or up to 2% of total worldwide annual turnover, whichever is higher; minimum EUR 25,000. |
| Important entity | Failure to implement the measures under Article 22 or to report under Article 23 | Up to EUR 7 million or up to 1.4% of total worldwide annual turnover, whichever is higher; minimum EUR 12,500. |
| Director or member of a management body | Breach of Article 21 | Fine of EUR 500 to EUR 5,000. |
The fine is only one part of the risk. Supervisory authorities may carry out inspections and audits, demand documents and evidence, issue binding instructions, and order notification of affected persons or public disclosure of a breach. For an essential entity, and under certain conditions, temporary suspension of a licence, registration, certificate or authorisation and a temporary restriction on managerial functions are also possible.
NIS2 should not be analysed in isolation. Where sector-specific legislation imposes cyber risk-management or reporting measures of at least equivalent effect, the Cybersecurity Act allows its corresponding rules on measures, notification, supervision and enforcement to be disapplied. This matters particularly for the financial sector and DORA. Digital providers should also check the directly applicable requirements of Implementing Regulation (EU) 2024/2690. Where an incident involves personal data, the GDPR remains relevant. The aim is a single coherent map of obligations, not duplicated and conflicting procedures.
See also our notes on the AI Act in August 2026 and on AI call recording and GDPR, and our data protection practice.
The new regime does not turn every Bulgarian company into a NIS2 entity. It does, however, place a substantial share of medium-sized and large undertakings in critical sectors, together with some smaller specialist providers, under direct regulatory supervision. The biggest practical risk is an organisation assuming that cybersecurity is a matter for the IT department alone, or that the absence of an official notification means the absence of obligations. The right approach starts with an accurate scope assessment, a management decision, demonstrable measures and a reporting process prepared in advance.
This article is general information as at 21 September 2026 and does not replace an individual assessment of the activity, size, group structure and applicable sector-specific legislation. Prepared by the legal team at YARD Law Co., a law firm based in Sofia, Bulgaria.
Does your company fall within NIS2?
Scope assessment, classification, Article 22 measures, incident procedure and ICT supplier contracts.