Law / Bulgaria

Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS)

Закон за киберсигурност (ЗКС) чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 7 months, effective 17 February 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds you where you are an essential or important entity designated under the Cybersecurity Act's sector annexes, which name a provider of an online marketplace, an online search engine, or a social networking services platform among the digital service providers it reaches expressly; the wider sector classes it also reaches are not separately raised here, for the reason given on this jurisdiction's companion risk-management-and-governance row.
  • Notify СЕРИКС of every significant incident on this clock: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours (24 hours if you are a trust service provider), an interim report on request, and a final report no later than one month after the incident notification (or, if unresolved by then, an interim report followed by a final report within one month of resolution).
  • State in your early warning, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it could have a cross-border effect; update that assessment with an initial severity and impact evaluation in your 72-hour notification; and cover in your final report the incident's scope and impact, its likely cause, your mitigation measures, and any cross-border effect.
  • Where appropriate and without undue delay, notify the recipients of your service of a significant incident likely to adversely affect them and of any measures they can take, and of a significant cyber threat and its nature.
  • Expect СЕРИКС to acknowledge your early warning within 24 hours except where objectively impossible, and to provide initial information and, on request, guidance or further technical support.
  • Same penalty tier as the risk-management duty above: up to EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity (not less than EUR 25,000), up to EUR 7,000,000 or 1.4 percent for an important entity (not less than EUR 12,500); this turnover-based sanction does not reach an essential entity that is itself an administrative body.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Chapter Three of the amended Cybersecurity Act (Arts. 27i, 28 and 29) makes an Article 23 reporting failure an administrative offence carrying a fine or property sanction imposed by the competent authority, not a criminal offence; no provision reviewed here attaches criminal liability to a reporting failure.

Penalty structure

Article 29(2), as substituted by Paragraph 36, sets an essential entity's sanction for an Article 22 or 23 failure at up to EUR 10,000,000 or up to 2 percent of the worldwide annual turnover of the undertaking to which the entity belongs, whichever is higher, but not less than EUR 25,000; this is the same penalty provision that governs the companion risk-management row. Article 29(3) sets an important entity's sanction at up to EUR 7,000,000 or up to 1.4 percent of turnover, whichever is higher, but not less than EUR 12,500. Article 29(5) exempts an essential entity that is itself an administrative body from the Article 29(2) turnover-based sanction. Article 51 of the amending Act's transitional provisions halved every fine and sanction under this chapter for a violation committed before 1 June 2026.

Rule
Higher of
As of
15 September 2026
Minimum
25,000
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The national competent authority the Council of Ministers designates per sector under Article 16(1) of the Cybersecurity Act, with СЕРИКС (the sectoral Computer Security Incident Response Team under Art. 18(1)) receiving and acknowledging the notification.

Settledness

As of
15 September 2026
Open questions
  • The amending Act's own text, as read in this session, states no express commencement clause for the Act as a whole; independent legal commentary places entry into force on 17 February 2026, consistent with Bulgaria's general three-clear-day rule, but this was not confirmed against an express primary-text clause in this session. Does the Act carry its own express commencement date distinct from the general default rule?
  • СЕРИКС is organised per sector under Article 18, and the amending Act requires each national competent authority to notify the European Commission of its sectoral СЕРИКС's identifying details. Is there a single national point of contact an entity spanning several sectors reports to, or must a multi-sector entity notify each sectoral СЕРИКС separately?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 23 of the Cybersecurity Act, as substituted by Paragraph 27 of the amending Act, requires every essential and important entity to notify СЕРИКС of every significant incident. СЕРИКС is the sectoral Computer Security Incident Response Team the Act defines at Art. 18(1). The notification runs on a graduated clock.

An early warning is due within 24 hours of becoming aware of the incident, stating where applicable whether the incident is suspected to result from unlawful or malicious acts and whether it could have a cross-border effect. An incident notification is due within 72 hours, updating that assessment with an initial severity and impact evaluation, or within 24 hours instead of 72 where the notifying entity is a trust service provider. An interim report is due on СЕРИКС's request.

A final report is due no later than one month after the incident notification, covering the incident's scope and impact, the likely threat type or cause, the mitigation measures applied and ongoing, and any cross-border effect. Where the entity has not resolved the incident by the one-month mark, it files an interim report instead and a final report within one month of resolving it.

Where appropriate and without undue delay, the entity must also notify the recipients of its service of a significant incident likely to adversely affect them and of any measures or safeguards they can take, and of a significant cyber threat and its nature; notification to recipients may be delayed, with the competent authority's consent, where it would jeopardise the incident's investigation. СЕРИКС must acknowledge the early warning within 24 hours, except where objectively impossible, and, on request, provide operational guidance or further technical support.

This article transposes NIS2 Article 23, and applies, among the sector classes the Act's annexes name, to a provider of an online marketplace, an online search engine, or a social networking services platform.

When LexLint raises it

  • operates_social_platform

Read the law

Act Amending and Supplementing the Cybersecurity Act
adopted by the 51st National Assembly on 5 February 2026, promulgated in State Gazette issue 17 of 13 February 2026 read via a State Gazette issue 17/2026 reproduction hosted by the University of Agribusiness and Rural Development (uard.bg), after the official host dv.parliament.bg could not be reached directly through crawler infrastructure in this session and lex.bg returned a Cloudflare CAPTCHA challenge

Back to the example  ·  Lint your app