Bulgaria’s NIS2 Transposition Is Complete. The Next Challenge Is Operational Compliance
What Happened
The European Commission has closed infringement procedure No. 2024/0257 against Bulgaria concerning delays in notifying measures fully transposing Directive (EU) 2022/2555, known as NIS2 (Network and Information Security Directive 2).
The procedure was closed following amendments to Bulgaria’s Cybersecurity Act and the country’s formal notification to the European Commission on 6 March 2026 that the Directive had been fully transposed.
The amendments to the Cybersecurity Act were adopted by the Bulgarian Parliament on 5 February 2026 and published in State Gazette No. 17 on 13 February 2026.
On 1 October 2026, the Ministry of Innovation and Digital Transformation confirmed that it had received formal notification that the infringement procedure had been closed.
This completes an important legislative stage. For organizations within scope, however, the more difficult phase now begins: implementing the requirements and demonstrating that they work in day-to-day operations.
What Changes for Organizations
The updated framework significantly broadens the scope of Bulgaria’s cybersecurity regime and introduces the categories of essential and important entities.
Applicability is not determined by sector alone. The organization’s sector, type of service, size and applicable exceptions all matter.
Relevant areas include:
energy;
transport;
healthcare;
digital infrastructure;
public administration;
certain manufacturing activities;
postal and courier services;
waste management;
certain food and chemical activities;
providers of certain digital and managed ICT (Information and Communication Technology) services.
Organizations should therefore perform a scoping assessment rather than assume automatically that they are either inside or outside the regime.
Compliance Is Now an Operational Question
Essential and important entities are required to implement appropriate and proportionate technical, operational and organizational measures for cybersecurity risk management.
These include areas such as:
risk management and risk assessment;
incident response;
business continuity and recovery;
supply-chain security;
vulnerability handling and disclosure;
access control;
encryption;
cyber hygiene and training;
security in system acquisition, development and maintenance.
Management accountability is also important. Management bodies must approve and oversee the implementation of cybersecurity risk-management measures.
The question therefore shifts from:
“Do we have a policy?”
to:
“Can we demonstrate that the control actually works?”
Significant Incidents Trigger Defined Reporting Timelines
NIS2 establishes a staged reporting process for significant incidents.
After becoming aware of such an incident, an affected entity must be able to provide:
an early warning within 24 hours, including available information on whether unlawful or malicious activity may be involved and whether there could be cross-border impact;
an incident notification within 72 hours, updating the initial information and providing a preliminary assessment of severity and impact;
intermediate information where required or requested;
a final report within one month of the incident notification, with additional reporting arrangements where the incident remains ongoing.
These are more than administrative deadlines.
To provide meaningful information within 24 or 72 hours, an organization needs functioning processes for detection, triage, investigation, escalation and decision-making before the incident occurs.
If investigation only begins after operational impact becomes obvious, much of the available reporting window has already been lost.
What This Means for Financial Entities
The situation is more specific for financial organizations.
DORA (Digital Operational Resilience Act) operates as the sector-specific regime for financial entities within its scope in areas including ICT risk management, ICT-related incident management and reporting, resilience testing and aspects of third-party ICT risk.
Financial entities therefore need to determine which regulatory regime applies to the specific obligation, rather than treating NIS2 and DORA as two identical parallel frameworks.
Other requirements may still remain relevant to organizations and service providers across the broader financial ecosystem depending on their activities and regulatory status.
What Organizations Should Review Now
With the infringement procedure closed, the practical question becomes:
Can we demonstrate how we meet the requirements?
A useful starting point is to review:
whether the organization falls within scope and under which category;
which systems and services are critical to operations;
who makes decisions during a significant incident;
how incidents are assessed against the significance threshold;
how monitoring and detection operate;
whether log coverage and retention are sufficient;
whether escalation paths are clearly defined;
how vulnerabilities and critical patches are managed;
how privileged and administrative accounts are controlled;
how supplier risk is assessed;
whether backup, recovery and incident response procedures have been tested;
what evidence can be produced during an audit or after an incident.
DIAMATIX Comment
From the DIAMATIX perspective, the closure of the infringement procedure changes the nature of the conversation. Until now, much of the attention has focused on when Bulgaria would complete NIS2 transposition. The more relevant question now is: Can an organization demonstrate that its security measures work when a real incident occurs?
This is where the difference between documented compliance and operational readiness becomes visible. An incident response plan may exist on paper. But the 24- and 72-hour reporting windows matter only if the organization can detect the incident, determine its scope, escalate it to the right people and collect enough reliable information to make decisions in time.
The same applies to vulnerability management, access control, supply-chain risk and recovery.
Regulation defines the expectation. Day-to-day security operations produce the evidence.
Practical Takeaway
Closing the infringement procedure does not mean the NIS2 work is finished.
For organizations in Bulgaria, the focus now moves from:
“When will the framework be adopted?”
to:
“Can we demonstrate that we operate according to it in real conditions?”
The next phase is operational compliance. Processes, responsibilities, monitoring, logging, escalation and response need to function before an audit or significant incident occurs.
Assess how ready your organization is to demonstrate NIS2 compliance in real operational conditions.
Sources
Ministry of Innovation and Digital Transformation. European Commission closes NIS2 cybersecurity infringement procedure against Bulgaria, 1 October 2026.
Bulgarian News Agency. European Commission Closes Cybersecurity Directive Infringement Procedure against Bulgaria, 1 October 2026.
Bulgarian Parliament / State Gazette. Amendments to the Cybersecurity Act, State Gazette No. 17, 13 February 2026.
Directive (EU) 2022/2555. NIS2, Article 23. Significant incident reporting.
European Commission. Guidelines on Article 4 of NIS2 and sector-specific Union legal acts, including DORA.
CMS Bulgaria. Bulgaria adopts NIS2-aligned cybersecurity law, 17 February 2026.






