Establish scope before planning the programme

Start with the actual service your organisation provides. Match it to the categories in the act, then apply Article 4 and its size rules and exceptions. Only after establishing coverage should you classify the entity under Article 4a as essential or important. Being mentioned in an annex does not automatically bring every small business into scope.

The Bulgarian Small and Medium-Sized Enterprises Act matters to the calculation. Headcount, turnover and balance-sheet total work together; partner and linked enterprises can change the result. A subsidiary cannot reliably determine scope from its local headcount alone. Equally, group turnover alone is not a complete test. Record the calculation, sources and assumptions.

Some categories are covered regardless of size. Check the precise category rather than extending an exception to every business in the sector. A written NIS2 applicability assessment is the useful starting document. It should explain both why an organisation is covered and why an exclusion is justified.

Essential and important entities: similar measures, different supervision

The distinction changes supervision and sanctions. Essential entities can face proactive supervision, including inspections and audits. Supervision of important entities is generally triggered by evidence or indications of non-compliance. Important does not mean optional.

Question Essential entity Important entity
Supervisory approach Proactive and reactive powers Primarily reactive supervision
Main monetary sanction under Article 29 From €25,000, with a ceiling of €10 million or 2% of worldwide annual turnover, whichever is higher From €12,500, with a ceiling of €7 million or 1.4%, whichever is higher
Management involvement Approves and oversees the measures Approves and oversees the measures
Practical evidence Decisions, configurations, tests and incident records Decisions, configurations, tests and incident records

These are statutory ranges, not an automatic fine for every deficiency. Article 29 contains specific exceptions, including for essential administrative bodies. The facts, infringement and applicable procedure matter. Management members also have their own duties under Article 21, including training every two years; breach of those duties carries a separate personal fine.

The 2026 transition: distinguish the clocks

Section 51 halves the Chapter Three sanctions for infringements committed up to and including 1 June 2026. That reduction does not apply to later infringements. It was a reduction in sanctions, not a declaration that security measures were unnecessary.

The transitional provisions also set deadlines for public authorities. Section 47(1) provides six months from entry into force for designation of competent authorities and the identification methodology. Section 47(2)–(3) provides eight months for secondary regulations. Under Section 48, identification of essential and important entities follows within five months of the actual Council of Ministers decision under Section 47(1).

The last period depends on a decision date. Adding six and five months does not establish a universal January 2027 compliance deadline for businesses. Check the adopted decisions, the current consolidated act and your sector's instructions. An absence of correspondence is not enough to establish an exemption.

Find both your supervisor and your incident-reporting route

The competent authority depends on the sector and on the applicable designation or special law. Record the authority, official contact, submission channel and the date you verified them. Avoid keeping only a general ministry homepage in the incident plan.

The relevant sectoral computer security incident response team is the СЕРИКС. The national incident response team, НЕРИКС, and the national single point of contact are distinct roles; do not treat their names as interchangeable.

For significant incidents, the general NIS2 sequence is an early warning within 24 hours of awareness, a notification within 72 hours and a final report within one month of that notification. Trust service providers have a 24-hour notification exception; ongoing incidents also need separate handling of progress and final reporting. Use the first-24-hours reporting guide to build the actual decision and reporting procedure.

Registration and updates need an owner

Article 6 provides for a non-public register. The information duties depend on the entity category. Certain digital infrastructure and digital service providers must supply information about their EU establishments within the specified two-month period; changes to registered information have a two-week update deadline under Article 6(3).

Check which duty applies to your entity and how the competent authority accepts the data. Keep a copy of the submission and acknowledgement. Give changes of contact details, activity or establishment an owner, so the register does not become a one-time administrative exercise.

What to do first

  1. Write down the activity, legal entity, group structure and size calculation. Identify any applicable exception.
  2. Have management approve the priorities and responsible roles. An email forwarding the issue to IT does not settle management accountability.
  3. Verify the reporting channel and deputies. Practise classification and initial reporting with incomplete information.
  4. Test a small set of material controls. MFA coverage and session protection, a restore test and removal of former users provide better evidence than a list of purchased products.
  5. Keep the decisions, tests and open gaps together, with dates and owners. Use security-budget priorities to connect the gaps to business impact.

A company outside direct NIS2 scope can still receive security requirements from customers. The supplier-to-a-bank guide explains how that happens contractually. Scope and commercial expectations are separate assessments.

Turn the assessment into a defined engagement

For financial entities, first check the relationship between DORA and NIS2. DORA acts as sector-specific Union legislation for corresponding areas; avoid turning that into a blanket statement about every obligation.

An Evidence Sprint can turn an agreed scope into a gap assessment and an organised evidence pack. Agree the systems, responsibilities and deliverables before setting a completion date. If your own team can perform and maintain the assessment, the same structure works internally.

General information as of 13 September 2026, not an entity-specific legal determination. Consult the current legislation and competent authority for your actual activity and circumstances.