Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

DORA compliance in Bulgaria: who is in scope and what is owed

How DORA applies to companies operating in or serving Bulgaria — scope tests, the obligations that follow, and the primary sources to verify each one against.

The Digital Operational Resilience Act (DORA) applies to financial entities established in Bulgaria and selling financial services into the Bulgarian market, setting harmonized requirements for information and communication technology (ICT) risk management. Supervised at the European level by the European Securities and Markets Authority (ESMA), the European Banking Authority (EBA), and the European Insurance and Occupational Pensions Authority (EIOPA), regulated entities must establish robust operational resilience frameworks. This reference details the scope, obligations, and supervisory structure applicable in Bulgaria under Regulation (EU) 2022/2554.

Extraterritorial Scope and Market Reach in Bulgaria

DORA applies directly to a broad spectrum of financial entities operating within Bulgaria, ranging from credit institutions and investment firms to payment institutions and crypto-asset service providers. Entities established within Bulgaria must evaluate their operational structures to determine whether their activities fall under the purview of European supervisory authorities. When organizations operate across borders or provide services into Bulgaria from other jurisdictions, the territorial reach is determined by the specific licensing and authorization criteria defined in European financial services law. For entities designing internal controls, understanding the foundational requirements found in the Digital Operational Resilience Act is a necessary first step.

Financial entities cannot exempt themselves by outsourcing core operational functions, as third-party arrangements remain subject to strict regulatory scrutiny. The regulation captures traditional banking institutions alongside modern fintech firms, insurance undertakings, and specialized data reporting service providers. Entities must assess their operational dependencies carefully, mapping out every service provider that supports critical or important functions. Compliance teams should consult the primary legal texts and verify jurisdictional applicability with qualified local counsel to account for specific nuances under Bulgarian law.

Supervisory oversight for entities in Bulgaria is coordinated through the relevant European Supervisory Authorities, namely ESMA, EBA, and EIOPA, in cooperation with national competent authorities. These bodies monitor adherence to digital resilience mandates, conduct reviews, and enforce corrective measures where vulnerabilities are identified. Organizations must maintain transparent records of their operational structures and ICT dependencies to satisfy supervisory inquiries. Reviewing available guidance via ESMA — Digital Operational Resilience Act (DORA) and EIOPA — Digital Operational Resilience Act (DORA) helps clarify expectations set by European regulators.

ICT Risk Management Framework Requirements for Bulgarian Entities

Regulated entities in Bulgaria must put in place a comprehensive ict-risk-management-framework capable of addressing digital threats effectively. This framework must identify, classify, and continuously monitor all ICT risk areas, ensuring that digital assets, hardware, and software are adequately protected against unauthorized access, system failure, or disruption. Management bodies bear ultimate responsibility for implementing and overseeing these strategies, requiring regular reporting on risk exposures and mitigation measures. The framework must be documented, tested, and updated periodically to reflect changes in the threat landscape.

To structure compliance efforts, entities frequently utilize specialized risk assessment tools and operational platforms. Integrating a structured risk-engine into compliance workflows assists teams in evaluating vulnerabilities across complex digital architectures. Organizations can explore various assessment methodologies and operational approaches by reviewing details found at jurisdictions and methodology to ensure alignment with pan-European supervisory expectations. Documentation must be exhaustive, detailing fallback procedures, business continuity policies, and disaster recovery plans designed to maintain critical operations during severe incidents.

The framework mandates rigorous protection and prevention strategies, including access control, network security segregation, and encryption standards. Bulgarian financial entities must establish continuous monitoring mechanisms to detect anomalies in real time, preventing minor technical glitches from escalating into systemic failures. Governance structures must assign clear roles and responsibilities for ICT risk management to designated personnel, ensuring accountability at the highest executive levels. Regular audits of the risk management framework are required to validate its efficacy and confirm adherence to the overarching standards laid down in Regulation (EU) 2022/2554 (DORA) — full text.

Incident Reporting Obligations and Major Incident Classification

A core pillar of DORA is the establishment of a streamlined and harmonized process for managing and reporting ICT-related incidents. Financial entities in Bulgaria must record all ICT-related incidents, monitor their root causes, and classify them according to criteria such as the number of clients affected, duration, data loss, and geographical spread. When an event crosses specific severity thresholds, it qualifies as a major-ict-related-incident and triggers mandatory initial notification, intermediate reports, and a final detailed report to the relevant supervisory authorities.

Compliance teams must implement robust internal ticketing and monitoring systems to capture incident metrics instantaneously. Organizations can evaluate their operational preparedness by utilizing dedicated tools like calculators to measure incident impact against regulatory thresholds. Consulting resources available at faq and about provides further clarity on reporting timelines and operational workflows required under the legislation. The reporting mechanism is designed to provide regulators with early warnings of systemic stress across the financial sector.

The reporting lifecycle begins with an initial notification submitted as soon as possible after classification, followed by a status report providing intermediate updates, and concludes with a comprehensive root-cause analysis report once the incident is fully resolved. Entities must maintain a comprehensive log of all ICT incidents, regardless of severity, to feed into their continuous risk assessment cycle. This historical data enables organizations to refine their defenses and prevents recurrence of similar operational failures. Supervisory authorities review these incident reports closely to monitor market-wide stability and identify emerging cyber threats.

Digital Operational Resilience Testing and Advanced Vulnerability Assessments

Financial entities established in Bulgaria are required to test their ICT systems regularly to verify operational resilience and uncover hidden vulnerabilities. This testing program must include a wide variety of assessments, such as vulnerability scans, open-source analyses, network security evaluations, physical security reviews, and source code reviews where applicable. The scope of testing must cover all critical or important ICT systems supporting the financial entity's business functions. Conducting digital-operational-resilience-testing helps organizations validate that their protective measures function as intended under simulated stress conditions.

For major financial entities meeting specific systemic criteria, more intensive testing is mandated in the form of threat-led-penetration-testing. This advanced testing methodology simulates real-world cyber attacks orchestrated by highly skilled threat actors, testing the entity's detection, response, and recovery capabilities. Entities must ensure that testers possess the requisite certifications and independence to deliver unbiased evaluations. Findings from these penetration tests must be documented and addressed through concrete remediation plans approved by the management body.

The results of all operational resilience tests must be reported to competent authorities upon request, alongside corrective action plans detailing how identified vulnerabilities will be mitigated. Testing schedules must be adaptive, responding to emerging cyber threats and significant modifications to ICT systems. Organizations can examine broader regulatory intelligence and research updates via blog and learn to stay informed on testing expectations. Proper execution of these testing protocols ensures that Bulgarian financial entities maintain a high level of preparedness against sophisticated digital disruptions.

Management of ICT Third-Party Risk and the Register of Information

Managing risks stemming from third-party ICT suppliers is a critical compliance obligation under DORA. Financial entities in Bulgaria must maintain a comprehensive register-of-information detailing all contractual arrangements with every ict-third-party-service-provider. This register must capture all outsourcing agreements supporting ICT services, providing regulators with transparent oversight of supply chain dependencies. Entities must conduct thorough due diligence before onboarding any provider, ensuring that contractual terms include mandatory audit rights, access rights, performance standards, and robust exit strategies.

Where services are procured from a designated critical-ict-third-party-provider, specialized oversight mechanisms apply at the European supervisory level. Financial entities must monitor the performance of their vendors continuously, establishing key performance indicators and service level agreements that align with internal resilience tolerances. Compliance teams can leverage specialized research tools and methodologies available at data-sources and trust to verify supplier credentials and maintain accurate records. The register must be made available to competent authorities upon request and updated regularly.

The regulatory framework requires contractual arrangements to address data protection, confidentiality, and operational resilience explicitly. If a third-party provider fails to meet agreed service levels or poses an unmitigated operational risk, the financial entity must enforce contractual exit clauses and transition services to an alternative provider without compromising business continuity. Supervision of critical ICT providers by ESMA, EBA, and EIOPA helps safeguard the broader financial ecosystem from single points of failure. Maintaining a meticulous register and rigorous vendor oversight protects Bulgarian entities from unexpected supply chain disruptions.

Evaluating Operational Readiness and Engaging with Supervisory Expectations

Preparing for DORA supervision in Bulgaria requires a structured approach to internal governance, policy documentation, and technical implementation. Organizations must conduct gap analyses against the requirements set out in Regulation (EU) 2022/2554 (DORA) — full text to identify areas requiring remediation. Management bodies must actively participate in resilience planning, allocating sufficient budgetary and human resources to achieve operational readiness. Engaging with official publications from ESMA — Digital Operational Resilience Act (DORA) helps teams understand supervisory priorities and expectations across EU member states.

Firms seeking to streamline their operational readiness programs can utilize structured digital tools and diagnostic platforms. Reviewing offerings at agents and practice-revenue provides insight into how legal operations teams manage regulatory workflows efficiently. Exploring complementary regulatory frameworks such as mica-readiness and mica-deadlines ensures that firms operating across multiple digital finance domains maintain harmonized compliance postures. Organizations must also review the disclaimer to understand the scope and limitations of regulatory research software.

Continuous engagement with regulatory updates is essential for maintaining alignment with evolving technical standards and regulatory guidelines. Financial entities should establish cross-functional compliance committees comprising legal, risk, IT, and operational personnel to oversee the execution of resilience programs. Documenting all remediation efforts and maintaining audit-ready evidence ensures that entities in Bulgaria can demonstrate compliance effectively during supervisory inspections conducted by national authorities and European supervisors.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does DORA apply to non-financial technology vendors operating in Bulgaria?

DORA applies directly to financial entities. However, ICT third-party service providers supplying technology services to those financial entities are indirectly affected through contractual requirements and, if designated as critical, fall under direct oversight by European supervisory authorities.

Which authorities supervise DORA compliance in Bulgaria?

Supervision is shared between national competent authorities in Bulgaria and the European Supervisory Authorities, which include ESMA, EBA, and EIOPA, depending on the specific financial sector and activity of the regulated entity.

What is the purpose of the register of information under DORA?

The register of information provides a comprehensive inventory of all contractual arrangements with ICT third-party service providers, enabling financial entities and regulators to monitor supply chain dependencies and manage ICT risk effectively.

Are all Bulgarian financial entities required to perform threat-led penetration testing?

Threat-led penetration testing is specifically required for financial entities that meet certain thresholds and criteria indicating significant systemic importance, as determined by regulatory standards and supervisory guidance.

Where can compliance teams find the official legal text of the regulation?

The primary legal text is published in the Official Journal of the European Union as Regulation (EU) 2022/2554, accessible via official European Union portals and referenced across regulatory compliance platforms.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact