Bulgaria and NIS2: A New Stage in Integration into the European Cybersecurity System

    Bulgaria continues to align its national cybersecurity legislation with the requirements of the European Union. A key element of this process has been the implementation of the NIS2 Directive, aimed at increasing the resilience of critical digital infrastructure and strengthening the protection of organizations against cyberattacks.

     

    In May 2025, the European Commission sent Bulgaria a reasoned opinion over the failure to notify the Commission of the full transposition of the NIS2 provisions into national law. Bulgaria was among 19 EU member states that received such reasoned opinions. Member states were required to complete the transposition of the directive by October 17, 2024.

    In response, Sofia introduced amendments to the existing Cybersecurity Act. The amendments were adopted by the National Assembly in February 2026 and formed the basis for transposing NIS2 requirements into national legislation. The new rules provide for the classification of regulated organizations as “essential” and “important” entities, while also introducing additional requirements for cybersecurity risk management and incident response.

    NIS2 significantly expands the range of organizations subject to European cybersecurity requirements. The directive covers 18 critical sectors, including energy, transport, healthcare, digital infrastructure, public administration, banking, the production of critical goods, and water supply.

    This is particularly significant for Bulgaria given the strategic role of the country’s energy and transport infrastructure. Important energy and transport routes run through Bulgarian territory, while the national infrastructure is simultaneously integrated into European networks. As a result, protecting the digital systems of the energy and transport sectors, financial institutions, and public authorities has become part of the broader task of ensuring the resilience of critical infrastructure.

    The new requirements also increase the responsibility of organizational management. Companies and institutions covered by NIS2 are required to implement cybersecurity risk-management measures, ensure the protection of information systems, and establish mechanisms for responding to serious incidents. At the same time, requirements for reporting cyberattacks and cooperating with national cybersecurity authorities are being strengthened.

    At the EU level, the full implementation of NIS2 is regarded as one of the key elements in strengthening the Union’s overall cyber resilience. The European Commission states that the directive is intended to improve the ability of governments and the private sector to prevent cyber incidents, respond to attacks, and ensure the continuity of critical services.

    The current process is taking place against the backdrop of broader efforts by the EU to strengthen digital security requirements for Bulgaria. In October 2026, for example, the European Commission again sent Sofia an additional formal notification concerning other digital legislation, the Digital Services Act, citing problems with the full functioning of the national Digital Services Coordinator.

     

    Thus, the implementation of NIS2 is part of a broader restructuring of Bulgaria’s digital security system. At the same time, the final assessment of Bulgaria’s compliance remains with the European Commission: the Commission itself notes that information on the state of transposition reflects data provided by the member states and does not replace a formal assessment of whether national measures comply with NIS2 requirements.


    CCBS Research Desk


    #ANALYSIS
    #BULGARIA

    02.10.2026 08:31





Latest news

    Moldova Ready to Accept as Many Ukrainians as Necessary if Situation Worsens This Winter

    09.Oct.2026

    Turkmenistan Turns Avaza into a Regional Diplomatic Hub as Caspian, Central Asian and CIS Agendas Converge

    08.Oct.2026

    Romania Scrambles Spanish F-18s After Aerial Targets Detected Near Ukrainian Border

    07.Oct.2026

    Berlin Deepens Defence Partnership with Kyiv: Germany to Provide Ukraine with €1 Billion in Military Aid

    07.Oct.2026

    European Parliament Against Georgian Dream: EU Prepares New Response to Tbilisi

    06.Oct.2026

    Bulgarian Foreign Minister to Discuss European Security and International Law in the Netherlands

    05.Oct.2026

    Rheinmetall in Bulgaria: Sofia Emerges as a New NATO Defence-Industrial Hub in the Balkans

    05.Oct.2026

    The Cost of a Long War: Moscow Expands Spending Plans Through 2029

    05.Oct.2026

    Trump Steps Up Pressure on Iran: Washington Puts Tehran Before a Choice Between a Deal and Further Escalation

    04.Oct.2026

    Russia Warns Diplomats Amid New Wave of Strikes on Ukraine

    04.Oct.2026

    Turkiye Expands Defense Capabilities: Ankara Aligns European Cooperation with the Development of Its Domestic Defense Industry

    04.Oct.2026

    Azerbaijan Expands Defense Industry as Growing Production Increases Military Burden on the Economy

    03.Oct.2026

    Germany Scales Back Political Presence in Georgia as Konrad Adenauer Foundation Closes Tbilisi Office

    03.Oct.2026

    Russia Prepares to Ease Fuel Restrictions as Moscow Seeks Balance Between Gasoline Shortages and Diesel Exports

    03.Oct.2026

    Bulgaria and NIS2: A New Stage in Integration into the European Cybersecurity System

    02.Oct.2026

All news