This is not legal advice. NIS2 and Bulgaria’s Cybersecurity Act amendments apply differently by sector, size and activity. Confirm scope and duties with counsel. What follows is a practical checklist for shop and SMB teams that host in Sofia (EU).
Amendments that transpose NIS2 into Bulgarian law entered into force on 17 February 2026. For store operators the question is no longer “is there a directive?” but are you or your supply chain in scope and what will your hosting contract say in an audit.
Scope: shop versus “essential / important” entity
NIS2 is not only for banks and energy. Digital infrastructure, cloud, managed services and certain mid-size operators plus critical suppliers sit in the frame. A small Sofia- or Istanbul-based shop may not automatically be an “important entity,” but payment gateways, logistics APIs, B2B portals or public-procurement suppliers often face customer questionnaires that look like NIS2 evidence requests.
Practical scan: headcount and turnover thresholds, sector lists, whether you sell managed ICT, and security riders in customer contracts. If unsure, plan for “customers will ask for proof,” not for a self-declared exemption.
What the hosting contract should say
Audits and vendor forms want written commitments, not slogans:
- Data location: where production and backups sit (EuroVDC: Sofia, EU).
- Processor role: GDPR Art. 28 / DPA — controller vs processor.
- Incident notice: how fast you are informed, and through which channel.
- Access and subprocessors: support access, subcontractors, third-country transfers.
- Backup and continuity: testable restore, not only marketing RTO numbers.
- Deletion on exit: written deletion or return when the account closes.
That is not the whole of NIS2, but it is auditable. For residency context see GDPR hosting — EU datacenter Sofia.
Concrete steps for the shop team
- List which products (web hosting, VPS, corporate email) share one account.
- Confirm nameservers — on EuroVDC typically
ns1.eurovdc.eu/ns2.eurovdc.eu. - Note whether MX points to
securemail.eurovdc.euand who can see panel access logs. - Download or request the DPA; attach a dated PDF to customer questionnaires.
- Write a three-name playbook: who opens support, who emails the customer, who approves restore.
Out of scope still needs contract language
Many shops will not sit on the formal NIS2 list. B2B buyers, insurers and marketplace onboarding still ask the same questions. Clear location, DPA and incident timing remove sales friction. Keeping Sofia web hosting and mail with one EU provider avoids four conflicting cloud answers.
Bottom line: after 17 February 2026 the Bulgarian NIS2 framework is in force. Let counsel settle your legal status; keep hosting contract, DPA, incident path and Sofia infrastructure evidence ready.
FAQ
Is this legal advice?
No. Operational guidance only. Use qualified counsel for scope and penalties.
Is every small shop automatically in scope?
No. Thresholds, sector and customer demands decide. DPA readiness still helps B2B sales.
Does Sofia hosting alone mean NIS2 compliance?
No. Location helps; processes, notice, access control and a written processor agreement are separate.
No incident timing in the contract?
Ask for written clarification. Support SLA and security-incident notice are not always the same clause.
Mail and site with different vendors?
Possible, but audits need two DPAs, two incident channels and two location statements. One EU stack simplifies questionnaires.