Regulatory reference

Regulatory reference — checked against the sources

Regulatory answers state the date on which they were checked against the source given. Sections are reviewed quarterly and whenever a relevant change is published.

Plain-language client questions →

No answer matches that search. Try a shorter word, browse the topics above, or send us the question through the contact form.
What is DORA and who does it apply to? #

DORA is the EU regulation on digital operational resilience for the financial sector. It has applied since 17 January 2025 to the listed financial entities, with lighter rules for some categories, and affects their ICT providers through mandatory contract terms. The competent authority depends on the entity and licence: in Bulgaria it is commonly BNB or FSC, while ECB or another authority may apply. DORA requires an ICT risk-management framework approved by the management body, incident classification and reporting, resilience testing, a register of ICT third-party arrangements and specific contract terms.

Checked on 12.09.2026 · Source: Regulation (EU) 2022/2554 (DORA)

How does NIS2 apply in Bulgaria? #

Bulgaria transposed NIS2 by amending the Cybersecurity Act (State Gazette No. 17 of 13 February 2026), applicable from 17 February 2026; a transitional period with sanctions reduced by half ended on 1 June 2026. You are in scope if you operate in one of the eighteen listed sectors and are at least a medium-sized enterprise — 50 or more staff, or turnover and balance-sheet total above €10 million, counted with linked and partner enterprises. Some entities are covered regardless of size: public electronic-communications providers, trust-service providers, top-level-domain registries and DNS providers, and entities that are the sole provider of an essential service, whose disruption would affect public safety or health, that pose systemic risk, or that are critical nationally or regionally. Administrative bodies, judicial authorities and certain public-service organisations are covered as well. Cloud, data-centre, content-delivery, managed-service and online-platform providers are covered under the general sector-and-size test and have a separate duty to supply their establishment details to the competent authority within two months. Management bodies approve the measures, oversee them and train at least every two years. Fines reach €10 million or 2% of worldwide turnover for essential entities (statutory minimum €25,000) and €7 million or 1.4% for important ones (minimum €12,500); members of management bodies face personal fines of €500 to €5,000. The statutory deadlines for the secondary acts differ: six months for the identification methodology, eight months for the ordinances on minimum measures, nine months for the national strategy; whether each has been adopted is checked at the time of your engagement.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026, State Gazette 17/2026

Who must comply with NIS2 — the sectors and tiers? #

NIS2 covers eighteen sectors. Eleven are high-criticality (Appendix I of the Cybersecurity Act): energy; transport; banking; financial market infrastructure; health; drinking water; wastewater; digital infrastructure; ICT service management (business-to-business); public administration; and space. Seven are other critical sectors (Appendix II): postal and courier services; waste management; chemicals; food; manufacturing of medical devices, electronics, electrical equipment, machinery and vehicles; digital providers (online marketplaces, search engines, social networks); and research organisations. Within those sectors, medium-sized and larger entities are in scope. After establishing whether the organisation is in scope, we separately determine whether it is an essential or important entity under Article 4a of Bulgaria’s Cybersecurity Act. The category depends on the entity type, size and specific statutory grounds. Being in scope regardless of size does not, by itself, determine the category. A customer’s contract can extend requirements to you even when the Act does not.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026, State Gazette 17/2026

Do municipalities and other public bodies have to comply? #

Yes. Administrative bodies are essential entities by category, not by size, so all 265 Bulgarian municipalities are in scope together with central-government administration; judicial authorities are covered too. The mayor, as head of the administration, approves the security measures and oversees them; a head of an administrative body or a member of a management body who fails to do so can be fined €500 to €5,000. The turnover-based fine does not apply to essential entities that are administrative bodies; enforcement takes the form of binding instructions, warnings, public disclosure and the personal fine. The national competent authority for administrative bodies is the Ministry of Innovation and Digital Transformation. The municipal associations have published their own guidance.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026, NAMRB guidance for municipalities

Who decides that we are in scope, and do we register? #

Two things run in parallel. The duties apply by operation of law from 17 February 2026 to any entity that meets the sector-and-size test or falls into a listed category — whether or not a letter has arrived. Formal identification is administrative: the national competent authorities designate essential and important entities under a methodology adopted by the Council of Ministers and notify the Ministry of Innovation and Digital Transformation, which keeps the register; the register is not public. Certain digital providers — DNS, TLD registries, domain-registration services, cloud, data-centre, content-delivery, managed and managed-security services, online marketplaces, search engines and social-network platforms — must themselves supply their establishment details to the competent authority within two months; all entities notify changes within two weeks. We prepare the register data in advance and tell you what will be asked.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026

What is NIS2 for? #

NIS2 is an EU directive whose purpose is to raise the common level of cybersecurity across the services society and the economy depend on — power, water, health, transport, finance, digital infrastructure and public administration — because a failure in one spreads quickly to the rest. It does this by making cybersecurity a management responsibility, by setting minimum measures and common incident-reporting rules, and by extending duties down the supply chain. The consequences of ignoring it are concrete: fines, personal fines and a possible temporary management ban for directors at essential entities, targeted audits at the entity’s own expense and public disclosure of a breach. Beyond the law, regulated customers increasingly require evidence of compliance in their contracts.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026

What does “management accountability” mean under NIS2 and DORA? #

Under the Cybersecurity Act the management bodies of essential and important entities, and the heads of administrative bodies, approve the cybersecurity risk-management measures and oversee their implementation; members of management bodies must undergo training at least every two years and organise it for their staff. A manager who does not can be fined €500 to €5,000 personally, and at essential entities the authority can seek a temporary ban from management functions. Under DORA the management body defines, approves and oversees the ICT risk-management framework and bears ultimate responsibility for ICT risk; verification tasks may be outsourced, but the responsibility stays with the entity. Delegating the work does not delegate the accountability.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026, Regulation (EU) 2022/2554 (DORA)

Incident reporting under NIS2 (Cybersecurity Act): what are the deadlines? #

Essential and important entities report significant incidents to the sectoral CSIRT (СЕРИКС) under Article 23(5) of the Cybersecurity Act. Early warning: within 24 hours of establishing the incident. Incident notification: within 72 hours of establishing it — for trust-service providers this second deadline is 24 hours. Intermediate report: on the CSIRT’s request. Final report: no later than one month after the incident notification. If the incident is still being handled when that month ends, an intermediate report is submitted instead and the final report follows within one month of handling the incident. Recipients of the service are informed where appropriate, and of measures they can take against a significant cyber threat. The deadlines run from establishing the incident, not from a decision to classify it.

Checked on 12.09.2026 · Source: Bulgarian Cybersecurity Act — State Gazette 17/2026, State Gazette 17/2026

Incident reporting under DORA: what are the deadlines and exceptions? #

Major ICT-related incidents are reported to the competent supervisory authority (Article 19 DORA) within the time limits of Delegated Regulation (EU) 2025/301, Article 5. General rule: the initial notification is due within 4 hours of classifying the incident as major and no later than 24 hours from becoming aware of it. If the incident is classified as major only after those 24 hours, the initial notification is due within 4 hours of the classification. The intermediate report is due within 72 hours of the initial notification, with updates without undue delay and in any case when regular activities are recovered; the final report no later than one month after the intermediate report or its latest update. Where a deadline falls on a weekend or a bank holiday, the report may be submitted by noon of the next working day — but for the initial notification and the intermediate report this extension does not apply to credit institutions, central counterparties, trading venue operators and entities that are essential or important under NIS2, and competent authorities may exclude other entities they designate. A national CSIRT channel, where one exists, does not replace the report to the supervisor.

Checked on 12.09.2026 · Source: Delegated Regulation (EU) 2025/301, Art. 5, Regulation (EU) 2022/2554 (DORA)

Incident and vulnerability reporting under the CRA and the GDPR: what are the deadlines? #

CRA (manufacturers of covered products, from 11 September 2026, Article 14): for an actively exploited vulnerability — early warning within 24 hours of becoming aware, vulnerability notification within 72 hours of becoming aware, final report no later than 14 days after a corrective or mitigating measure is available; for a severe incident with an impact on the product’s security — early warning within 24 hours of becoming aware, incident notification within 72 hours, final report within one month after the incident notification. Reports go to the CSIRT designated as coordinator and to ENISA through the single reporting platform. GDPR (Article 33): a personal-data breach is notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk. One incident can trigger several regimes at once; the process is designed once and run from one playbook.

Checked on 12.09.2026 · Source: CRA, Art. 14 (Regulation (EU) 2024/2847), European Commission — Cyber Resilience Act

What is required for suppliers and third parties? #

A register of the suppliers that matter, a risk assessment of each, contract clauses that give you security requirements, incident cooperation, audit rights, exit terms and — under DORA — the locations where services are provided and data is processed, plus evidence that you actually monitor them. DORA is prescriptive about the register and the contract content (Articles 28 to 30); NIS2 requires supply-chain security measures proportionate to risk.

Checked on 12.09.2026 · Source: Regulation (EU) 2022/2554 (DORA), Bulgarian Cybersecurity Act — State Gazette 17/2026

Which functions are actually required by law? #

The legal duty and the job title are different questions. DORA requires covered non-micro financial entities to assign ICT-risk management and oversight to a control function with appropriate independence; compliance-verification tasks may be outsourced, while the entity retains the function and responsibility. DORA also requires a role monitoring ICT-provider arrangements or senior-management responsibility, and a crisis-management function, without prescribing those job titles. A DPO is required only in the cases in GDPR Article 37. Bulgarian whistleblowing rules generally apply to private employers with 50 or more staff and, below that threshold, to the activities specifically identified in Part I, letter B and Part II of the statutory annex; an external party may receive and register written reports, while examination remains internal. We confirm the exact basis before proposing a role.

Checked on 12.09.2026 · Source: EDPB — Data protection officer, КЗЛД — Методически указания по ЗЗЛПСПОИН, 15.05.2025, Regulation (EU) 2022/2554 (DORA), ЗЗЛПСПОИН, чл. 12 (текст, публикуван от КЗЛД)

What does the EU AI Act require today? #

As of September 2026, prohibited practices, measures supporting AI literacy, general-purpose AI obligations and applicable transparency duties are already in force on their respective dates. Regulation (EU) 2026/1744 rewrote Article 4: providers and deployers must take measures supporting staff AI literacy, considering their context and knowledge, but do not have to guarantee a particular level for each person; national supervision of this duty began on 3 August 2026. Article 50 duties differ by role and use. A transition to 2 December 2026 applies to the machine-readable marking duty for qualifying generative systems placed on the market before 2 August 2026; pre-August-2025 GPAI models have a separate transition to 2 August 2027. High-risk obligations were rescheduled to 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products. Article 26 applies to deployers of high-risk systems, not every organisation using an ordinary AI tool.

Checked on 12.09.2026 · Source: European Commission — AI Act, AI Act, Art. 50 (consolidated text), AI Act, Art. 26 (consolidated text)

What does the GDPR have to do with your services? #

Two things. Article 37 makes a data protection officer mandatory for public authorities and bodies and for organisations whose core activities involve large-scale regular and systematic monitoring or large-scale processing of special-category data; the DPO may be external and must be free of conflicts of interest. We provide the DPO function as an external role where those conditions allow. Second, personal-data breaches must be notified to the supervisory authority within 72 hours where required — a duty we build into the same incident process as NIS2 and DORA reporting. We do not provide general GDPR legal advice.

Checked on 12.09.2026 · Source: EDPB — Data protection officer

What is the Cyber Resilience Act and does it affect me? #

The CRA assigns duties to manufacturers, importers, distributors and other specified actors for products with digital elements placed on the EU market; open-source software stewards have a distinct regime. The reporting duties for covered products have applied since 11 September 2026, and the main product-security obligations apply from 11 December 2027. An organisation that only uses software is not a manufacturer for that reason alone. Our support concerns reporting readiness and the process around it; we do not offer CRA conformity assessment.

Checked on 12.09.2026 · Source: Regulation (EU) 2024/2847 (CRA) — EUR-Lex

What is the whistleblowing-channel duty and what can be outsourced? #

Private employers with 50 or more workers and public-sector bodies generally need an internal reporting channel. Below 50 workers, the exception is tied to the activities identified specifically in Part I, letter B and Part II of the annex to the Bulgarian Act, not every activity mentioned anywhere in the annex. Current CPDP guidance allows a private-sector obliged entity to outsource receipt and registration of written reports, while examination remains with a designated internal employee; public bodies cannot outsource these functions. We confirm the legal design with your lawyer.

Checked on 12.09.2026 · Source: КЗЛД — Методически указания по ЗЗЛПСПОИН, 15.05.2025, ЗЗЛПСПОИН, чл. 12 (текст, публикуван от КЗЛД)

Are ISO 27001, ISO 42001, ISO 22301 and SOC 2 legal requirements? #

No. They are voluntary frameworks that customers, tender rules or regulators increasingly ask for as proof. ISO/IEC 27001, ISO/IEC 42001 and ISO 22301 are certified by independent certification bodies; SOC 2 is an attestation report issued by a licensed CPA firm — not a certificate. We prepare you and can act as your external officer where a standard requires one; the certificate or report comes from the independent body, never from us.

Our provider is compliant. Does that make us compliant too? #

No. A provider’s certification or compliance can support part of your supply-chain evidence, but it does not discharge your own duties to govern, report, contract and test. Your authority or customer can still require evidence from your organisation.