Three months into NIS2 enforcement in Bulgaria: what carriers actually face
The 50% fine discount expired on 1 June 2026. Three months later, the first-wave EU fines are visible, Bulgaria's competent authorities were only being designated in August, and telecom operators are being asked for evidence, not architecture.
CEO, Sofia Connect EAD · Honorary Consul of Georgia in Bulgaria
Bulgaria's NIS2-aligned Cybersecurity Act became fully enforceable on 1 June 2026, when the transitional 50% reduction on administrative fines under §51 of the amended act expired (nis-solutions.eu). Three months later, two things are true at the same time: the statutory penalty regime is at full strength, and the operational supervisory infrastructure was still being assembled through the summer. That gap — regulatory intent ahead of regulatory capacity — is where telecom operators are actually working today.
What happened between June and September
The Bulgarian Cybersecurity Act was amended on 5 February 2026 and promulgated in State Gazette Issue No. 17 on 13 February 2026, entering into force on 17 February 2026 (CMS). The §51 transitional paragraph reduced fines by 50% for infringements committed up to 1 June 2026; after that date, the full statutory amounts apply (nis-2-templates.com).
The next milestone was the designation of sectoral competent authorities. The statutory deadline was 17 August 2026, but as of 3 August 2026 the Council of Ministers' designation decision had not been published, and the sectoral CSIRTs were therefore not yet operationally established (nis-solutions.eu). For an operator preparing an evidence pack in Q3 2026, the practical implication was that the receiving side of the supervisory conversation was still being staffed while the sending side — the obligation to report incidents, maintain risk management, and train the board — was already at full strength.
The first-wave EU fines are visible now
Bulgaria has not yet issued a public NIS2 fine, and the enforcement trackers do not list a Bulgarian action (Legiscope). Elsewhere in the EU, however, the first wave of fines is now on the record and it establishes the pattern that Bulgarian regulators will inherit (Legiscope):
| Jurisdiction | Date | Entity | Amount | Reason |
|---|---|---|---|---|
| Belgium | January 2025 | Healthcare provider | €185,000 | Missed 24-hour early warning |
| Italy | March 2025 | Cloud provider | €450,000 | No risk-management programme |
| Hungary | July 2025 | Water utility | €78,000 | Inadequate incident response |
| Lithuania | September 2025 | Energy operator | €52,000 | Missing supply-chain controls |
| France | February 2026 | DNS provider | €120,000 | Late incident notification |
Two features of this list matter for a Bulgarian telecom operator. First, none of these are anywhere near the €10m / 2% of turnover ceiling — regulators are, so far, calibrating penalties to enforcement pattern-setting rather than to headline deterrence. Second, three of the five actions punish procedural failures around incident reporting and management systems, not the underlying security incident itself. The message is that missing the 24-hour early warning or failing to maintain a demonstrable risk-management programme is being treated as a first-order breach in its own right.
Bulgaria's penalty architecture is broader than the headline figure
The €10m / 2% ceiling is the number that gets quoted, but the Bulgarian regime has several less-discussed teeth that are more likely to touch a live operator:
- Daily penalty payments of up to BGN 200,000 (approximately €102,000) per day for ongoing violations (nis-2-templates.com).
- Court-ordered suspension of licences, registrations, certifications, or authorisations for essential entities (nis-2-templates.com).
- Court-ordered prohibition of named individuals from exercising management functions in NIS2-regulated entities for up to three years (nis-2-templates.com).
- Mandatory external security audits at the entity's expense (nis-2-templates.com).
- Public disclosure of specific violations (nis-2-templates.com).
- Personal fines of €500 to €5,000 for management body members, plus procedural-breach fines in the €200,000 to €2,000,000 range for notification or registration failures (nis-2-templates.com).
For a mid-size operator, the €102k/day continuing-violation clock is more operationally dangerous than the €10m ceiling. It converts an unresolved deficiency into a burn rate. A month of inaction on a binding corrective instruction is roughly €3m; the ceiling is not what forces the timeline, the daily accrual is.
The Bulgarian coordination layer: SEGA and the sectoral gap
The State e-Government Agency (SEGA) is the central node in the Bulgarian model. It manages the entity registration portal, maintains the national risk-management catalogue, receives cross-sector incident reports, coordinates with sectoral competent authorities, and holds direct supervisory authority for public administration entities (nis-2-templates.com).
What SEGA does not do is act as the sectoral authority for electronic communications. That role sits with a separately designated telecom-sector authority — which, as noted above, had not been published by early August 2026. The three-month window between the 1 June enforcement date and the 17 August designation deadline is the period during which operators were expected to be compliant but did not yet have a named counterparty on the supervisory side. Any operator that was audited in that window would have been audited by SEGA on cross-sector obligations, without a sectoral CSIRT in the loop.
Once the sectoral authorities are formally designated, the audit menu they can trigger is already fixed in law: scheduled audits announced in advance, targeted audits triggered by specific risk indicators or complaints, and unannounced audits (nis-2-templates.com). The unannounced category is the one that changes operational posture — evidence packs must be current, not "current by end of quarter".
What the first-wave fines say about telecom exposure
The France February 2026 action against a DNS provider is the closest data point to what a Bulgarian carrier would face, and the reason is worth naming: DNS providers sit in the "digital infrastructure" NIS2 sub-sector alongside IXPs, TLD name registries, cloud, CDN, and data centres. The €120,000 fine was for late incident notification — a procedural obligation, not a security failure. The Belgian healthcare fine (€185,000) has the same structural cause: a missed 24-hour early warning.
Both are consistent with the ENISA reading that digital infrastructure has the highest enforcement activity of any NIS2 sector (Legiscope). The likely reason is auditability: notification timestamps are objective, machine-readable, and easy to check, whereas "was your risk-management programme adequate?" requires interpretation. Regulators are prosecuting the easy cases first.
For a telecom operator, that means the near-term audit exposure is not "did we prevent the incident?" but "did we tell the right people in time, in the right format, from an authorised sender?". That is a workflow question, not a security question.
What it means for the region
Bulgaria's enforcement window opened three months ahead of some SEE neighbours completing their own transposition and designation cycles. If a Bulgarian PoP is the first in a multi-country transit path to be audited under NIS2, the audit findings will propagate into supplier and customer expectations for the entire regional interconnect fabric. Cross-border carrier partnerships will increasingly include contractual representations about NIS2 status that did not exist in interconnect agreements twelve months ago.
The second implication is investment-side. The daily-accrual penalty structure and the possibility of court-ordered management bans mean that under-investment in operational evidence — as distinct from under-investment in security tooling itself — carries a direct executive-level risk. Governance artefacts (board-approved risk-appetite statements, quarterly cyber KPI packs, machine-readable training completion evidence) are the specific area where most operators are thinnest and where audits are structurally easiest to lose.
For Sofia Connect, the operational discipline is unchanged from what we wrote when the transposition landed: treat NIS2 as an evidence problem, keep the vendor-access perimeter inside the audit envelope, and make the reporting workflow rehearsed before a real incident forces it into a first-time run. The August designation slippage is a reminder that the timeline pressure is on operators, not on the state — the calendar for compliance runs from 1 June regardless of when the sectoral authority receives its first email.
Sources
- NIS2 Enforcement Tracker 2026 — Legiscope
- NIS2 Bulgaria 2026: Cybersecurity Act (ЗКС), Fines & Reporting — nis-solutions.eu
- Bulgaria NIS2 Enforcement: €10M/2% Fines in Full Force After 50% Grace Period Expired — nis-2-templates.com
- Bulgaria adopts NIS2-aligned cybersecurity law — CMS
- Bulgaria implements NIS 2 Directive: key changes to the Cybersecurity Act — Schoenherr
- NIS2 in Bulgaria — Vassilev & Partners Law Firm
Weekly analysis on regional telecom infrastructure
DWDM, submarine cables, IP transit, peering, regulation, M&A — one email per week, written for engineers and decision-makers. No marketing.
By subscribing you agree to receive emails from Sofia Connect EAD. You can unsubscribe at any time. Privacy.