Skip to main content
NIS2 · BULGARIA

NIS2 in Bulgaria — delayed transposition, compressed timelines, and a regime now in force.

Bulgaria completed its NIS2 transposition through the National Cybersecurity Law, entering into force in late 2024. The E-government and cybersecurity coordination bodies serve as the competent authority, with the National CERT operating as the national CSIRT. Bulgaria was among the last member states to complete transposition, and the delay means entities operating in Bulgaria had less time to prepare than those in earlier-adopting member states. The regime is now fully operational, with registration and compliance requirements in effect.

The transposition follows the standard EU structure but places particular emphasis on critical sectors in the Bulgarian economy — energy, transport, and digital infrastructure. Entities that meet the size thresholds in these sectors are classified as essential or important and must register, file risk-management declarations, and maintain documented controls. The delayed transposition means compliance timelines are compressed, and teams that waited for the national law to act are now racing to meet obligations that have already been in force for months in other member states.

Who it applies to

Essential and important entities across NIS2 sectors, with particular focus on energy, transport, and digital infrastructure. Entities that meet the size thresholds must register and submit initial risk-management documentation. The delayed transposition means some entities are just now understanding obligations that have been in force elsewhere for over a year.

The clock

Competent authority: E-government and cybersecurity coordination bodies. Transposition: National Cybersecurity Law (NIS2 transposition).

NIS2 in Bulgaria · timeline
WhenWhat happens
Late 2024National Cybersecurity Law enters into force · authority confirmed
On registrationInitial risk-assessment filing · compliance clock starts
OngoingIncident reporting to National CERT · annual updates

Delayed transposition, compressed timelines

Bulgaria was among the last member states to complete transposition, and the delay has practical consequences. Entities operating in Bulgaria had less time to prepare than those in earlier-adopting member states, and the compressed timeline means compliance activities are condensed. For teams that waited for the national law before acting, the regime is now in force and the compliance clock is already ticking.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Bulgaria transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Bulgaria requirements · how TruSecure answers them
What the law asksWhere it is answered
Register immediatelyEntity profile · expedited registration given compressed timeline
File initial risk-management declarationRisk register · accelerated assessment, with controls mapped to Bulgarian implementation
Report incidents to National CERTIncident workflow · clocked reporting, with Bulgarian statutory timeframes
Document controls and evidenceControl library · evidence collection prioritized for high-risk areas
Address delayed preparationCompliance roadmap · accelerated Resilience Sprint to address compressed timeline

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Bulgaria NIS2 readiness file · excerptSample data
Registration
complete · filed under accelerated process
Risk assessment
priority · high-risk controls addressed first
Controls evidenced
67/95 · 28 open, prioritized by risk and deadline
Compliance timeline
accelerated · compressed into 90-day baseline
Export
sealed · sha256:9a4d...1c8f

Where teams usually start

With a demo walked through by TruSecure — your compressed timeline assessed, the Bulgarian transposition mapped against EU requirements, and an accelerated compliance roadmap. A Resilience Sprint produces the first baseline in weeks; the subscription keeps it current.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Bulgaria by E-government and cybersecurity coordination bodies. TruSecure determines applicability against Bulgaria's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Has Bulgaria transposed NIS2 yet?
Bulgaria's transposition has tracked more slowly than several regional peers — TruSecure tracks the current legislative status directly and flags when your obligations shift from the EU baseline to confirmed national law.