Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Bulgaria: Parliament Reviews Cybersecurity Act Amendments at Second Reading

1739196714107

Bulgaria: Parliament Reviews Cybersecurity Act Amendments at Second Reading

Today (29.01.2026), the National Assembly of the Republic of Bulgaria is reviewing amendments to Bulgaria’s Cybersecurity Act at second reading. The proposed changes are part of the country’s ongoing alignment with Directive (EU) 2022/2555 (NIS2) and reflect the broader shift across the European Union toward stronger cybersecurity governance and enforcement.

From EU directive to national enforcement

NIS2 entered into force at EU level in January 2023, with a deadline for transposition into national law set for October 17, 2024. While implementation timelines vary across member states, the period 2025–2026 marks the transition from legislative preparation to active supervision and enforcement.

Within this context, the amendments under discussion aim to strengthen Bulgaria’s national framework and prepare organizations for regulatory oversight that goes beyond formal compliance.

Expanded scope and clearer obligations

The proposed changes broaden the scope of regulated entities and introduce more structured requirements related to:

  • cybersecurity risk assessment and management

  • timely incident reporting

  • coordination between national authorities and EU-level mechanisms

The focus is on improving the resilience of services with significant public and economic importance across both the public and private sectors in Bulgaria.

Telecom operators and supply chain security in focus

Mobile network operators are among the entities facing increased obligations under the proposed amendments. They are expected to implement a comprehensive risk management approach, covering organizational, technical, and operational measures to protect networks and information systems.

Particular emphasis is placed on supply chain security. Operators will be required to assess and manage risks related to vendors of equipment, software, and services, including those involved in 5G infrastructure. This reflects the EU-wide recognition that cybersecurity risks extend across interconnected ecosystems rather than remaining confined to individual organizations.

DIAMATIX perspective

From DIAMATIX’s perspective, the proposed amendments underline a clear regulatory shift. Cybersecurity is increasingly treated as an operational capability that must be demonstrable under supervision and during real incidents, not merely documented through policies and procedures.

If adopted in their current form, the changes will require organizations in scope to show effective monitoring, incident response, reporting processes, and control over critical supply chain dependencies. This represents a move from formal compliance toward measurable and verifiable cyber resilience.

Related resource

For additional context on how NIS2 fits alongside ISO 27001, DORA, and GDPR at EU level, see our analysis:
 ISO 27001, NIS2, DORA and GDPR. Mapping the EU Cybersecurity Landscape


Sources used

  • National Assembly of the Republic of Bulgaria. Public information and legislative agenda

  • Directive (EU) 2022/2555 (NIS2)

  • European Commission. Information on NIS2 transposition and enforcement

  • Bulgarian national media reports, 29 January 2026

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.