Bulgaria and NIS2: A New Stage in Integration into the European Cybersecurity System

Bulgaria
continues to align its national cybersecurity legislation with the requirements
of the European Union. A key element of this process has been the
implementation of the NIS2 Directive, aimed at increasing the resilience of
critical digital infrastructure and strengthening the protection of
organizations against cyberattacks.
In
May 2025, the European Commission sent Bulgaria a reasoned opinion over the
failure to notify the Commission of the full transposition of the NIS2
provisions into national law. Bulgaria was among 19 EU member states that
received such reasoned opinions. Member states were required to complete the
transposition of the directive by October 17, 2024.
In
response, Sofia introduced amendments to the existing Cybersecurity Act. The
amendments were adopted by the National Assembly in February 2026 and formed
the basis for transposing NIS2 requirements into national legislation. The new
rules provide for the classification of regulated organizations as “essential”
and “important” entities, while also introducing additional requirements for
cybersecurity risk management and incident response.
NIS2
significantly expands the range of organizations subject to European
cybersecurity requirements. The directive covers 18 critical sectors, including
energy, transport, healthcare, digital infrastructure, public administration,
banking, the production of critical goods, and water supply.
This
is particularly significant for Bulgaria given the strategic role of the
country’s energy and transport infrastructure. Important energy and transport
routes run through Bulgarian territory, while the national infrastructure is
simultaneously integrated into European networks. As a result, protecting the
digital systems of the energy and transport sectors, financial institutions,
and public authorities has become part of the broader task of ensuring the resilience
of critical infrastructure.
The
new requirements also increase the responsibility of organizational management.
Companies and institutions covered by NIS2 are required to implement
cybersecurity risk-management measures, ensure the protection of information
systems, and establish mechanisms for responding to serious incidents. At the
same time, requirements for reporting cyberattacks and cooperating with
national cybersecurity authorities are being strengthened.
At
the EU level, the full implementation of NIS2 is regarded as one of the key
elements in strengthening the Union’s overall cyber resilience. The European
Commission states that the directive is intended to improve the ability of
governments and the private sector to prevent cyber incidents, respond to
attacks, and ensure the continuity of critical services.
The
current process is taking place against the backdrop of broader efforts by the
EU to strengthen digital security requirements for Bulgaria. In October 2026,
for example, the European Commission again sent Sofia an additional formal
notification concerning other digital legislation, the Digital Services Act,
citing problems with the full functioning of the national Digital Services
Coordinator.
Thus, the implementation of NIS2 is part of a broader restructuring of Bulgaria’s digital security system. At the same time, the final assessment of Bulgaria’s compliance remains with the European Commission: the Commission itself notes that information on the state of transposition reflects data provided by the member states and does not replace a formal assessment of whether national measures comply with NIS2 requirements.
CCBS Research Desk
Latest news
Latest newsMoldova Ready to Accept as Many Ukrainians as Necessary if Situation Worsens This Winter
09.Oct.2026
Turkmenistan Turns Avaza into a Regional Diplomatic Hub as Caspian, Central Asian and CIS Agendas Converge
08.Oct.2026
Romania Scrambles Spanish F-18s After Aerial Targets Detected Near Ukrainian Border
07.Oct.2026
Berlin Deepens Defence Partnership with Kyiv: Germany to Provide Ukraine with €1 Billion in Military Aid
07.Oct.2026
European Parliament Against Georgian Dream: EU Prepares New Response to Tbilisi
06.Oct.2026
Bulgarian Foreign Minister to Discuss European Security and International Law in the Netherlands
05.Oct.2026
Rheinmetall in Bulgaria: Sofia Emerges as a New NATO Defence-Industrial Hub in the Balkans
05.Oct.2026
The Cost of a Long War: Moscow Expands Spending Plans Through 2029
05.Oct.2026
Trump Steps Up Pressure on Iran: Washington Puts Tehran Before a Choice Between a Deal and Further Escalation
04.Oct.2026
Russia Warns Diplomats Amid New Wave of Strikes on Ukraine
04.Oct.2026
Turkiye Expands Defense Capabilities: Ankara Aligns European Cooperation with the Development of Its Domestic Defense Industry
04.Oct.2026
Azerbaijan Expands Defense Industry as Growing Production Increases Military Burden on the Economy
03.Oct.2026
Germany Scales Back Political Presence in Georgia as Konrad Adenauer Foundation Closes Tbilisi Office
03.Oct.2026
Russia Prepares to Ease Fuel Restrictions as Moscow Seeks Balance Between Gasoline Shortages and Diesel Exports
03.Oct.2026
Bulgaria and NIS2: A New Stage in Integration into the European Cybersecurity System
02.Oct.2026

09 Oct 2026


