Bulgaria NIS2 competent authority SEGA structure and dual CSIRT network

Bulgaria’s NIS2 Competent Authority: SEGA, the Dual CSIRT Structure, and Why Your Registration Window Is 2 Weeks

Bulgaria was the last EU member state to formally transpose the NIS2 Directive. The amendments to the Cybersecurity Act entered into force on 17 February 2026 — sixteen months after the EU deadline, and only after the European Commission referred Bulgaria to the Court of Justice for failure to notify full transposition. [1] The delay is over. The obligations apply now, with no transitional grace period.

For organisations operating in Bulgaria, the practical question is not whether they are in scope — it is who enforces compliance and how the oversight structure works. Two authorities operate in parallel: the State e-Government Agency (SEGA), which is both Bulgaria’s central competent authority and the EU-designated single point of contact; and a dual CSIRT structure that separates civilian incident handling (CERT.bg) from military cybersecurity (the Mil CIRC under the Ministry of Defence). Five provisions in the amended Cybersecurity Act go beyond the EU minimum — including a two-week window for updating registry information that is six times tighter than the three-month standard in Directive (EU) 2022/2555.

Does NIS2 Apply to Your Bulgarian Organisation?

As a general rule, NIS2 in Bulgaria applies to medium-sized and larger enterprises — at least 50 employees or €10 million in annual turnover — operating in one of eighteen sectors. Some entities fall within scope regardless of size, wherever the disruption of their services would cause significant cross-border impact or where they are publicly designated as critical. Bulgaria also extended obligations to judicial authorities and educational institutions conducting research in designated sectors — categories not explicitly required by Directive (EU) 2022/2555. [4]

The framework divides obliged entities into two tiers. Essential entities face stricter ex-ante proactive supervision; important entities face ex-post oversight triggered by incidents or complaints. The eighteen sectors covered, up from eight under NIS1, split across both tiers:

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Essential Entities (Annex I) Important Entities (Annex II)
Energy (electricity, oil, gas, hydrogen) Postal and courier services
Transport (air, rail, water, road) Waste management
Banking and financial market infrastructure Manufacture of chemicals
Health (hospitals, laboratories, R&D) Food businesses (see note below)
Drinking water and wastewater Manufacturing (medical devices, electronics, machinery, vehicles)
Digital infrastructure (IXPs, DNS, TLD registries, cloud, data centres, CDNs, trust services, telecom) Digital providers (online marketplaces, search engines, social networks)
ICT service management (B2B MSPs and MSSPs) Research organisations
Public administration
Space

Note on food sector: NIS2 Annex II covers food businesses “engaged in wholesale distribution and industrial production and processing.” Bulgaria’s Cybersecurity Act applies to all food businesses — a broader definition that includes retail food operators and smaller processors outside the EU threshold. See the food industry NIS2 guide for the full scope analysis.

SEGA: Bulgaria’s Central NIS2 Authority and EU Single Point of Contact

The State e-Government Agency — SEGA — holds two distinct roles under Bulgaria’s NIS2 framework that are easy to conflate but operate separately. First, it is designated as Bulgaria’s National Single Point of Contact (NSPOC), responsible for liaising with competent authorities in other EU member states, the European Commission, and ENISA on cross-border cybersecurity matters. [1] Second, SEGA coordinates the national register of essential and important entities and exercises enforcement authority within its supervisory remit.

NIS2 Article 8 requires each member state to establish a single point of contact that “shall serve as the liaison to facilitate cooperation” between domestic authorities and EU-level bodies. [2] Bulgaria fulfils this through SEGA, reachable at NSPOC@e-gov.bg. Direct contact: Gen. Yosif V. Gurko Street 6, Sofia 1000; telephone +359 (2) 949 20 40.

For most private-sector entities, the directly relevant competent authority is not SEGA itself but a sector-specific body designated by the Council of Ministers. The Ministry of Energy supervises energy entities; the Financial Supervision Commission oversees financial market infrastructure; the Ministry of Health has authority over healthcare; and the Ministry of Transport covers digital infrastructure and transport operators. The Ministry of Defence, Ministry of Interior, and State Agency for National Security each exercise control over entities in their respective security domains. [5]

What makes SEGA’s position distinctive is its enforcement toolkit. Under the amended Cybersecurity Act, SEGA can issue binding instructions, order mandatory security audits, require public disclosure of compliance failures, and — for essential entities — seek court orders suspending licences or prohibiting named individuals from exercising management functions. [5] Daily penalty provisions and executive disqualification orders of up to three years are also available.

CERT.bg and Bulgaria’s Dual CSIRT Structure

Bulgaria operates two Computer Security Incident Response Teams under NIS2, and directing incident notifications to the wrong one is a compliance failure. Understanding which CSIRT covers your organisation is a first-day obligation.

CERT.bg, operating at govcert.bg, is the national civilian CSIRT designated under NIS2 Article 10, housed within SEGA. [3][6] It covers essential and important entities across the civilian sectors — from energy and banking through digital infrastructure, manufacturing, and food businesses. Significant incident notifications go to CERT.bg at cert@govcert.bg. The notification timeline follows the standard three-stage NIS2 requirement: [1]

  • Within 24 hours of becoming aware of a significant incident: early warning to CERT.bg
  • Within 72 hours: initial notification with a preliminary impact and severity assessment
  • Within one month: final incident report including root cause analysis and a full description of the incident

NIS2 Article 10 permits member states to designate CSIRTs that “operate within competent authorities” and to establish additional sector-specific teams where needed. [3] Bulgaria exercises this provision for its defence domain. The Mil CIRC (Military Computer Incident Response Capability), operating under the Ministry of Defence, handles incidents for defence-related entities and military networks. [6] Entities operating within Bulgaria’s defence supply chain — including contractors and military-adjacent public bodies — direct incident notifications to Mil CIRC rather than CERT.bg.

For most in-scope private-sector entities, Mil CIRC is irrelevant. The civilian CERT.bg at govcert.bg is the contact point for significant incident notifications. Both CSIRTs participate in the EU CSIRTs Network, ensuring that large-scale or cross-border incidents escalate through the standard EU coordination path via ENISA and the CyCLONe network. See the full NIS2 incident reporting requirements for the complete notification framework.

The National Register: Administrative Designation, Not Self-Registration

Bulgaria’s registration model differs from several other EU member states in one key way: there is no uniform self-registration procedure that automatically triggers when an entity concludes it falls within scope. Bulgaria uses administrative designation instead. [7]

The process unfolds in two stages. The Council of Ministers must first adopt a methodology for identifying essential and important entities — this methodology is due within six months of the law entering into force, by approximately August 2026. After the methodology is adopted, competent authorities have five months to identify and formally designate entities in their respective sectors. [4] Formal designation decisions are therefore expected from late 2026.

The resulting national register is non-public, managed by the Minister of e-Government. [7] Entities are not named publicly through the register itself, though competent authorities retain the power to require public disclosure as an enforcement measure in specific cases.

The absence of a formal self-registration trigger does not remove the compliance obligation. Under the amended Cybersecurity Act, if your organisation meets the statutory criteria — sector, size, and type — the security obligations apply from 17 February 2026, regardless of whether formal designation has occurred. [7] Bulgarian legal practitioners recommend conducting an internal scoping analysis now and implementing required security measures without waiting for formal notification. The entity registration guidance provides a structured self-assessment approach.

Once designated, changes to information held in the national register must be reported within two weeks. Directive (EU) 2022/2555 provides a three-month standard update window — Bulgaria’s accelerated timeline is one of five ways the national law exceeds the EU minimum. [4]

5 Ways Bulgaria’s Law Goes Beyond the EU Baseline

Most member-state transpositions implement the NIS2 minimum with limited national additions. Bulgaria’s amended Cybersecurity Act includes five provisions that exceed or depart from the EU baseline, each with direct compliance implications. [4]

1. All Food Businesses — Not Just Wholesale and Industrial Producers

NIS2 Annex II covers food businesses “engaged in wholesale distribution and industrial production and processing” — a definition that excludes retail food operators and smaller processors. Bulgaria’s Cybersecurity Act applies to all food businesses, removing the wholesale/industrial filter entirely. A food retailer or regional processor that would fall outside NIS2’s scope under the EU baseline may be in scope under Bulgarian law. If you operate anywhere in Bulgaria’s food supply chain, apply the national definition, not the EU one.

2. Change Management Added to the Required Security Measures

NIS2 Article 21(2) specifies ten categories of mandatory security measures — from risk analysis and incident handling through supply chain security, access control, and cryptography. Bulgaria’s Cybersecurity Act adds change management and associated notification obligations to this list. In-scope entities must document and control changes to their network and information systems under a formal change management process — a requirement with no direct equivalent in Article 21(2)’s ten EU baseline categories. [4]

3. Governance Training Fixed at Every Two Years

NIS2 Article 20(2) mandates that management body members undergo cybersecurity training, but does not specify a minimum frequency — organisations calibrate the schedule to their risk profile. Bulgaria’s Cybersecurity Act removes that flexibility. Training for management bodies is a mandatory minimum of every two years. [4] For compliance officers and company secretaries, this means governance training must appear in the board’s annual calendar as a fixed recurring obligation, not a discretionary risk-based decision.

4. Two-Week Window for Registry Updates

Once designated, changes to information held in the national register must be reported within two weeks — compared to the three-month standard in Directive (EU) 2022/2555. [4] This applies to changes in entity classification, contact information, sector designation, and other registered data. Building a process to identify and report these changes promptly — rather than batching them for quarterly review — is the practical compliance implication for operations and legal teams.

5. Government Authority to Restrict Specific Technologies

Bulgaria’s Cybersecurity Act grants the Council of Ministers authority to prohibit or restrict essential and important entities from using specific ICT products, services, or processes where these are assessed as posing national security risks. [4][5] The default compliance window for implementing such restrictions is three years; for situations involving significant national security risk, this shortens to under one year. The NIS2 Directive is technology-neutral — this provision has no direct equivalent in the EU baseline. Organisations reliant on specific vendor platforms or technology stacks should treat this as a regulatory risk to monitor, particularly in sectors with high geopolitical sensitivity such as energy, telecoms, and digital infrastructure.

Enforcement Powers and Penalties

SEGA and Bulgaria’s sectoral competent authorities operate a graduated enforcement toolkit, applied independently of any financial penalty: [5]

  • Binding instructions — legally enforceable directions requiring specific remediation steps
  • Mandatory security audits — ordered at the entity’s expense
  • Public disclosure — requirement to announce a compliance failure publicly
  • Court orders (essential entities only) — temporary suspension of licences, registrations, or certifications; prohibition of named individuals from exercising management functions

Financial penalties align with NIS2’s EU-level thresholds. Bulgaria introduced explicit national minimum amounts by entity type — a stricter approach than jurisdictions that rely on the EU ceiling alone. Violations committed before 1 June 2026 are subject to fines reduced by 50%, though the security obligations themselves apply in full from 17 February 2026: [5]

Entity type Maximum fine Management liability (per individual)
Essential entity €10,000,000 or 2% of global annual turnover (whichever is higher) €500–€5,000
Important entity €7,000,000 or 1.4% of global annual turnover (whichever is higher) €500–€5,000

For management teams, the personal liability dimension warrants separate attention. NIS2 holds management bodies directly accountable for implementing the required measures. Bulgaria’s law enforces this through both personal fines and — for essential entities — the court-ordered management prohibition. The NIS2 penalties and enforcement framework explains how management accountability operates across the EU.

Frequently Asked Questions

Which authority handles NIS2 enforcement for banks and financial entities in Bulgaria?

The Financial Supervision Commission (FSC) is the designated competent authority for financial market infrastructure in Bulgaria. [1] For banking entities also subject to DORA (Digital Operational Resilience Act), the two regimes operate with a lex specialis relationship: where DORA covers the same obligations as NIS2 for financial entities, DORA’s requirements apply as the more specific instrument. CERT.bg remains the incident notification point of contact for significant cybersecurity incidents regardless of which sectoral authority supervises compliance.

Is there a fixed deadline by which Bulgarian entities must register?

Bulgaria uses administrative designation rather than self-registration, so entities do not register by a fixed deadline. The Council of Ministers must adopt the designation methodology by approximately August 2026, after which competent authorities have five months to designate entities — with formal designations expected from late 2026. [4] Security obligations under the amended Cybersecurity Act apply from 17 February 2026 regardless of formal designation. Begin your scoping assessment and implement required security measures now, not after receiving a formal designation notice.

Does the two-week registry update rule apply immediately after designation?

Yes — the two-week update obligation applies continuously from the moment of formal designation. [4] Since designation decisions are expected from late 2026, the practical impact will be felt then. The rule is ongoing: any subsequent change to registered information — entity classification, sector assignment, contact details — must be reported within two weeks of the change occurring, not batched for periodic review.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive Implementation in Bulgaria — European Commission Digital Strategy
  2. NIS2 Directive Article 8 — Competent Authorities and Single Point of Contact — NIS-2-Directive.com
  3. NIS2 Directive Article 10 — Requirements for CSIRTs — NIS-2-Directive.com
  4. Bulgaria’s Long Road to NIS2 Is Over — Kinstellar
  5. Bulgaria Adopts NIS2-Aligned Cybersecurity Law — CMS Law
  6. Bulgaria — National Cyber Security Index — NCSI
  7. What Next for Cyber Security in Bulgaria? — Popov, Arnaudov & Partners
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: