The European Commission has dropped its case against Bulgaria over the late rollout of the EU's NIS2 cybersecurity directive. The ministry of innovation and digital transformation said today it had received the notice.
Brussels opened the case, numbered 2024/0257, after Bulgaria failed to tell the Commission it had fully applied Directive (EU) 2022/2555. The Commission has now closed the case because Bulgaria has met the rules.
Before that happened, parliament passed changes to the cybersecurity law, and on March 6, 2026, Brussels was formally told the directive had been fully applied. The changes widen the range of organisations that must follow cybersecurity rules and set tougher requirements for managing risk and reporting cyber incidents.
The goal is to better protect people and businesses, and to help key services in energy, transport, health care, digital infrastructure and public administration cope better when incidents happen, the ministry says. It credits the closure of the case to work done by the ministry and other state bodies on Bulgaria's EU cybersecurity commitments.
The Commission also gave an update today on six other infringement cases against Bulgaria, saying two of them are now headed to the EU Court of Justice.
Comments (0)
No comments yet.