Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)
Закон за киберсигурност (ЗКС) чл. 21 и 22, изм. с §§ 25 и 26 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Arts. 21 and 22, as substituted by §§ 25 and 26 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 7 months, effective 17 February 2026.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds you where you are an essential or important entity designated under the Cybersecurity Act's sector annexes, which name a provider of an online marketplace, an online search engine, or a social networking services platform among the digital service providers it reaches expressly; the wider sector classes it also reaches (energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing and others) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems you use in your core activity or in providing your services, sized to your exposure, your size, and the likelihood and severity of an incident.
- Cover, at minimum: risk-analysis and information-system-security policies, incident-handling procedures, business-continuity and backup management, supply-chain security, security in the acquisition, development and maintenance of your systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of your own risk-management measures, basic cyber-hygiene practices and training, cryptography and encryption policies, and human-resources security and access control.
- Have your management body approve and oversee these measures, and have every member of your management body complete cybersecurity training every two years and organise the same training for your staff; a member who fails to do so faces a personal fine of EUR 500 to 5,000.
- Expect a fine or property sanction of up to EUR 10,000,000 or 2 percent of your undertaking's worldwide annual turnover for the preceding financial year, whichever is higher but never less than EUR 25,000, if you are an essential entity that fails these duties; the ceiling drops to EUR 7,000,000 or 1.4 percent, not less than EUR 12,500, for an important entity. This turnover-based sanction does not reach an essential entity that is itself an administrative body.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Chapter Three of the amended Cybersecurity Act (Arts. 27i, 28 and 29) makes an Article 22 or 21 failure an administrative offence carrying a fine or property sanction (imushtestvena sanktsia) imposed by the competent authority, not a criminal offence; no provision reviewed here attaches criminal liability to a risk-management or governance failure.
Penalty structure
Article 29(2), as substituted by Paragraph 36, sets an essential entity's sanction for an Article 22 or 23 failure at up to EUR 10,000,000 or up to 2 percent of the worldwide annual turnover of the undertaking to which the entity belongs, whichever is higher, but not less than EUR 25,000. Article 29(3) sets an important entity's sanction at up to EUR 7,000,000 or up to 1.4 percent of turnover, whichever is higher, but not less than EUR 12,500 (not separately structured here, since this field holds one tier; see this note). Article 29(4) separately fines a head of an administrative body, a manager, or a management-body member EUR 500 to 5,000 for a violation of Article 21. Article 29(5) exempts an essential entity that is itself an administrative body from the Article 29(2) turnover-based sanction. Article 51 of the amending Act's transitional provisions halved every fine and sanction under this chapter for a violation committed before 1 June 2026.
- Rule
- Higher of
- As of
- 15 September 2026
- Minimum
- 25,000
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The national competent authority the Council of Ministers designates per sector under Article 16(1) of the Cybersecurity Act, which also determines essential and important entities under Article 16(3), pt. 8.
Settledness
- As of
- 15 September 2026
- Open questions
- The amending Act's own text, as read in this session, states no express commencement clause for the Act as a whole (only deadlines running from its entry into force for secondary measures); independent legal commentary places entry into force on 17 February 2026, consistent with Bulgaria's general three-clear-day rule for a law that states no other term, but this was not confirmed against an express primary-text clause in this session. Does the Act carry its own express commencement date distinct from the general default rule?
- Article 3(3)'s implementing ordinance on the detail of the Article 22 risk-management measures was due within 8 months of the Act's entry into force under Section 47(2) of the transitional provisions, with the pre-existing electronic-communications security rules applying until then under Section 50. Has that ordinance been adopted, and does it narrow or particularise any of the Article 22(2) measure categories?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 22 of the Cybersecurity Act, as substituted by Paragraph 26 of the amending Act, requires every essential and important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems it uses in its core activity or in providing its services, at a level of security matched to the entity's exposure, size, and the likelihood and severity of an incident.
The measures must follow an all-hazards approach covering, at minimum, risk-analysis and information-system-security policies, incident-handling procedures, business continuity (including backup and disaster-recovery management and crisis management), supply-chain security, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of the risk-management measures themselves, basic cyber-hygiene practices and cybersecurity training, cryptography and encryption policies, and human-resources security and access control.
Article 21, as substituted by Paragraph 25 of the same amending Act, puts approval and oversight of these Article 22 measures on the entity's own management body (or, for an administrative body, its governing organ), and separately requires every management-body member of an essential or important entity to complete cybersecurity training every two years sufficient to identify risks and assess risk-management practices, and to organise the same training for the entity's staff.
Both articles transpose NIS2 Articles 20 and 21 respectively, and apply, among the sector classes the Act's annexes name, to a provider of an online marketplace, an online search engine, or a social networking services platform, which the amended annex lists among the reached digital service providers.
When LexLint raises it
operates_social_platform
Read the law
Act Amending and Supplementing the Cybersecurity Act
adopted by the 51st National Assembly on 5 February 2026, promulgated in State Gazette issue 17 of 13 February 2026 read via a State Gazette issue 17/2026 reproduction hosted by the University of Agribusiness and Rural Development (uard.bg), after the official host dv.parliament.bg could not be reached directly through crawler infrastructure in this session and lex.bg returned a Cloudflare CAPTCHA challenge