NIS2 Directive
What is the NIS2 Directive?
The NIS2 Directive is EU legislation that requires medium and large organisations in 18 sectors to manage their cybersecurity risks and report significant incidents. Bulgaria transposed it through amendments to its Cybersecurity Act, in force since February 2026. Management must approve the measures and can be held personally liable, and covered organisations must also look after the security of their suppliers, which is how the directive reaches smaller firms.
Example
A food manufacturer with 80 employees is in scope as an important entity: industrial food production is one of the directive’s sectors, and the company is past the small-enterprise threshold. If it becomes aware of a significant incident at 10:00 on a Monday, the early warning is due to the sectoral incident response team by 10:00 on Tuesday, the incident notification by 10:00 on Thursday (72 hours), and the final report within a month of that notification.
The same company sends a contract annex to each of its suppliers: the accounting software vendor, the hosting company, the agency that runs its online shop. The annex asks for two-factor login, notice of any incident within 24 hours, tested backups and a right to audit. The agency is a small enterprise and is not in scope itself, but without those measures it risks losing the client.
Why it matters for a business
Most small firms are not directly covered. Scope starts at medium size (as a rule, 50 employees, or annual turnover and balance sheet both above €10 million) in the sectors the law lists: energy, transport, health, digital infrastructure, food, postal and courier services, waste management, certain kinds of manufacturing and more. A few providers, such as top-level domain registries and DNS service providers, are covered whatever their size.
The indirect reach is wider. Anyone who sells software, hosting or site maintenance to a covered company should expect security questionnaires and new contract clauses. Fines for important entities go up to €7 million or 1.4% of worldwide annual turnover, and for essential entities up to €10 million or 2%, whichever is higher.
What to ask
- Are we in a listed sector, and above the threshold once linked and partner companies are counted?
- Who in management approves the measures, and have they completed the training the law requires?
- If we are a supplier, which measures does our client expect, and can we show evidence for each?
- Who detects an incident, and who sends the early warning within 24 hours?
Whether a company is in scope is a question for a lawyer or the competent authority, not a web agency. Our website security test covers its part of the measures (vulnerabilities in the site, the shop and access to them) and ends in a report you can show a client or an auditor as evidence.