NIS2 Directive — Complete Guide for Bulgarian Business (2026)
As of October 18, 2024, the NIS2 directive is in effect across Europe. For thousands of Bulgarian companies, it brings new obligations, strict deadlines and fines up to €10 million.
What is NIS2?
NIS2 (Network and Information Security Directive 2) is a European directive that replaces the original NIS directive from 2016. It dramatically expands the scope of organizations required to comply with cybersecurity standards and introduces significantly stricter sanctions.
Who is Affected in Bulgaria?
Essential Entities
Organizations in critical sectors with over 250 employees or turnover over €50M:
Electricity, gas, oil, thermal energy, hydrogen.
Aviation, railways, waterways, road transport.
Credit institutions, trading venues.
Hospitals, laboratories, medical device and pharmaceutical manufacturers.
Cloud services, data centers, CDN, DNS, trust services.
Important Entities
Organizations in additional sectors with over 50 employees or turnover over €10M: postal, waste management, chemicals, food, manufacturing, digital services, research.
Key Requirements
1. Risk Management (Article 21)
You must have a documented cybersecurity risk management framework covering risk analysis, incident handling, business continuity, supply chain security, MFA, encryption, and employee training.
2. Incident Reporting (Article 23)
3. Management Accountability (Article 20)
The revolutionary change: C-level management personally approves cybersecurity measures, bears responsibility for compliance, must undergo cybersecurity training, and can be personally fined or temporarily removed from management positions.
Fines and Sanctions
Up to €10,000,000 or 2% of global annual turnover (whichever is greater).
Up to €7,000,000 or 1.4% of global annual turnover (whichever is greater).
How to Prepare — 10 Steps
- Determine if you fall under NIS2 — use our free NIS2 Assessment
- Conduct a Gap Analysis
- Appoint a responsible person — CISO or vCISO
- Document policies — InfoSec Policy, Incident Response Plan, BCP/DRP
- Implement technical measures — MFA, endpoint protection, SIEM, backup
- Train management — NIS2 requires management to undergo training
- Train all employees — Security Awareness with phishing simulations
- Assess suppliers — security assessment of critical vendors
- Prepare Incident Response plan — with 24/72h notification procedure
- Conduct regular audits — penetration tests and vulnerability assessments
How Defend.bg Can Help
Don't know where to start with NIS2?
Free NIS2 Consultation — we'll assess your situation and give you a concrete action plan. No obligations.