NIS2 in Bulgaria — delayed transposition, compressed timelines, and a regime now in force.
Bulgaria completed its NIS2 transposition through the National Cybersecurity Law, entering into force in late 2024. The E-government and cybersecurity coordination bodies serve as the competent authority, with the National CERT operating as the national CSIRT. Bulgaria was among the last member states to complete transposition, and the delay means entities operating in Bulgaria had less time to prepare than those in earlier-adopting member states. The regime is now fully operational, with registration and compliance requirements in effect.
The transposition follows the standard EU structure but places particular emphasis on critical sectors in the Bulgarian economy — energy, transport, and digital infrastructure. Entities that meet the size thresholds in these sectors are classified as essential or important and must register, file risk-management declarations, and maintain documented controls. The delayed transposition means compliance timelines are compressed, and teams that waited for the national law to act are now racing to meet obligations that have already been in force for months in other member states.
Who it applies to
Essential and important entities across NIS2 sectors, with particular focus on energy, transport, and digital infrastructure. Entities that meet the size thresholds must register and submit initial risk-management documentation. The delayed transposition means some entities are just now understanding obligations that have been in force elsewhere for over a year.
The clock
Competent authority: E-government and cybersecurity coordination bodies. Transposition: National Cybersecurity Law (NIS2 transposition).
| When | What happens |
|---|---|
| Late 2024 | National Cybersecurity Law enters into force · authority confirmed |
| On registration | Initial risk-assessment filing · compliance clock starts |
| Ongoing | Incident reporting to National CERT · annual updates |
Delayed transposition, compressed timelines
Bulgaria was among the last member states to complete transposition, and the delay has practical consequences. Entities operating in Bulgaria had less time to prepare than those in earlier-adopting member states, and the compressed timeline means compliance activities are condensed. For teams that waited for the national law before acting, the regime is now in force and the compliance clock is already ticking.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Bulgaria transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register immediately | Entity profile · expedited registration given compressed timeline |
| File initial risk-management declaration | Risk register · accelerated assessment, with controls mapped to Bulgarian implementation |
| Report incidents to National CERT | Incident workflow · clocked reporting, with Bulgarian statutory timeframes |
| Document controls and evidence | Control library · evidence collection prioritized for high-risk areas |
| Address delayed preparation | Compliance roadmap · accelerated Resilience Sprint to address compressed timeline |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Registration
- complete · filed under accelerated process
- Risk assessment
- priority · high-risk controls addressed first
- Controls evidenced
- 67/95 · 28 open, prioritized by risk and deadline
- Compliance timeline
- accelerated · compressed into 90-day baseline
- Export
- sealed · sha256:9a4d...1c8f
Where teams usually start
With a demo walked through by TruSecure — your compressed timeline assessed, the Bulgarian transposition mapped against EU requirements, and an accelerated compliance roadmap. A Resilience Sprint produces the first baseline in weeks; the subscription keeps it current.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Bulgaria by E-government and cybersecurity coordination bodies. TruSecure determines applicability against Bulgaria's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.