By 18 October 2024, every EU Member State was expected to transpose the NIS2 Directive into national law. For Bulgarian manufacturers, importers, distributors, retailers, and digital service providers, that date is more than a cybersecurity milestone: it is part of a broader compliance wave that also includes digital product passports, packaging reform, extended producer responsibility, and new product data obligations.
The practical effect is clear. A Bulgarian electronics importer may soon need cybersecurity controls under NIS2, packaging reporting under Extended Producer Responsibility rules, future Digital Product Passport data for batteries or electronics, and redesigned packaging processes under the EU Packaging and Packaging Waste Regulation. These are not separate legal checklists anymore. They are increasingly connected business transformation requirements.
This article summarizes the key points businesses should know about Bulgarian legislation on DPP, DPR, EPR, PPWR, NIS2, and related EU rules, with a focus on Regulatory Compliance in the EU and operational readiness.
Why Bulgarian Companies Should Treat Compliance as a Transformation Program
European product, packaging, sustainability, and cybersecurity legislation is moving from document-based compliance to data-based compliance. Authorities, customers, business partners, and digital platforms increasingly expect verifiable information, not only signed declarations.
For Bulgarian businesses, this means compliance must involve legal, IT, procurement, product, logistics, finance, and sustainability teams. A manufacturer that cannot trace recycled content, packaging material, supplier certifications, cybersecurity incidents, or product lifecycle data may face delays in market access, penalties, contract losses, or operational disruption.
The most important shift is that compliance data must become structured, reusable, and auditable. This is where DPP, DPR, EPR, PPWR, and NIS2 intersect.

DPP: Digital Product Passports and the New Product Data Economy
The Digital Product Passport, commonly referred to as DPP, is one of the central tools of the EU’s sustainable product policy. It is introduced through the Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, which entered into force in July 2024.
The DPP is intended to provide digital information about a product’s composition, performance, repairability, durability, environmental footprint, recycled content, and compliance characteristics. The information will be accessible through a data carrier, such as a QR code or similar technology, depending on product-specific rules.
What DPP Means for Bulgarian Businesses
Bulgarian manufacturers, importers, and distributors should not wait until product-specific delegated acts are adopted. The DPP will be introduced by product category, and the first sectors are expected to include batteries, textiles, electronics, construction products, furniture, chemicals, and intermediate products such as iron, steel, and aluminum.
For example, a Bulgarian company placing industrial batteries or textile products on the EU market may need to collect supplier-level data on materials, hazardous substances, recycled content, carbon footprint, spare parts, and end-of-life handling. This information must be accurate, machine-readable, and maintained over time.
At present, Bulgarian legislation on DPP is primarily driven by directly applicable EU regulations rather than a standalone Bulgarian DPP act. However, national authorities will play a role in market surveillance, enforcement, and penalties once product-specific requirements apply.
Business Preparation Checklist for DPP
Companies should map product data sources, identify missing supplier information, review ERP and product lifecycle management systems, and prepare data governance procedures. Procurement contracts should be updated to require suppliers to provide DPP-ready technical, environmental, and compliance data.
Businesses should also monitor the European Commission’s Ecodesign workplan and product-specific delegated acts. The key issue is not whether DPP will apply, but when it will apply to each product category.
DPR: Understanding the Role of Data, Product, and Due Diligence Requirements
The acronym DPR is used differently across sectors. In compliance projects, it may refer to digital product-related requirements, data processing requirements, or due diligence and reporting obligations. In the context of Bulgarian legislation on DPP, DPR, EPR, PPWR, NIS2, businesses should treat DPR as the broader set of digital reporting and product responsibility requirements that support EU market compliance.
These requirements include keeping technical documentation, making conformity information available, reporting environmental data, maintaining supply chain traceability, and ensuring that digital compliance information is reliable. For many businesses, DPR is the operational bridge between traditional product compliance and newer digital systems such as DPP.
Why DPR Matters in Practice
A Bulgarian machinery producer may already maintain CE conformity documentation. Under emerging EU rules, that company may also need to connect technical files with repair information, software update records, spare part availability, environmental performance, and cybersecurity documentation. These data points may be requested by market surveillance authorities or business customers.
The business risk is fragmentation. If sustainability data sits in one spreadsheet, supplier certificates in email folders, packaging reports in accounting software, and cybersecurity evidence in IT systems, the company will struggle to respond to audits and customer requests.
EPR in Bulgaria: Extended Producer Responsibility for Products and Packaging
Extended Producer Responsibility, or EPR, is already well established in Bulgaria. It requires producers, importers, and certain traders to take responsibility for the collection, recovery, recycling, and reporting of specific product and waste streams placed on the market.
Bulgarian EPR obligations are mainly governed through the Waste Management Act and related ordinances, including rules on packaging waste, electrical and electronic equipment, batteries and accumulators, end-of-life vehicles, oils, and tires. Companies may comply individually or by participating in licensed collective recovery organizations.
Packaging EPR Obligations
Businesses placing packaged goods on the Bulgarian market must assess whether they qualify as obligated persons under packaging waste rules. This often includes manufacturers, importers, online sellers, and private-label distributors.
Typical obligations include registration or participation in a recovery organization, payment of product fees or recovery organization fees, reporting quantities and packaging materials, achieving recovery and recycling targets, and maintaining documentation for inspections.
For example, a Bulgarian company importing cosmetics from another EU country and selling them under its own brand may be responsible for reporting the cardboard boxes, plastic containers, glass jars, and transport packaging placed on the Bulgarian market.
WEEE, Batteries, and Other EPR Streams
Electrical and electronic equipment, batteries, and accumulators are especially important because they are closely linked to the future DPP framework. The EU Batteries Regulation, Regulation (EU) 2023/1542, already introduces digital battery passport requirements for certain batteries from 2027.
Bulgarian companies placing batteries, electronics, or equipment containing batteries on the market should align EPR reporting with product data systems. This will help avoid duplicate work when digital passport, carbon footprint, and recycled content requirements become mandatory.
PPWR: Packaging and Packaging Waste Regulation
The Packaging and Packaging Waste Regulation, known as PPWR, is one of the most significant upcoming changes for manufacturers and retailers in Europe. Unlike a directive, a regulation is directly applicable across the EU, reducing national differences but increasing the need for harmonized compliance systems.
The PPWR replaces the existing Packaging and Packaging Waste Directive framework and introduces stricter rules on packaging minimization, recyclability, recycled content, reuse, labeling, and restrictions on certain packaging formats.
What PPWR Changes for Bulgarian Companies
Bulgarian manufacturers, importers, food businesses, e-commerce operators, logistics providers, and retailers should review packaging design and procurement now. Packaging that is lawful today may become restricted or economically inefficient under PPWR requirements.
Key areas include packaging weight and volume minimization, recyclability performance grades, recycled content targets for plastic packaging, reuse and refill obligations in certain sectors, and harmonized labeling rules. E-commerce packaging will also be affected by empty space and packaging minimization requirements.
For example, an online retailer shipping small consumer products in oversized boxes with excess void fill may need to redesign packaging processes, renegotiate supplier contracts, and update warehouse packing algorithms.
PPWR and Bulgarian EPR Systems
PPWR will interact with Bulgaria’s existing EPR framework. Companies should expect packaging fees and producer obligations to become more closely linked to recyclability, recycled content, and environmental performance. This is often described as eco-modulation of EPR fees.
Businesses should review packaging material data at SKU level. If a company only tracks packaging by total annual tonnage, it may not have enough information to calculate future compliance costs or prove conformity.
NIS2 in Bulgaria: Cybersecurity Becomes a Board-Level Compliance Issue
The NIS2 Directive, Directive (EU) 2022/2555, expands cybersecurity obligations across essential and important entities. It applies to sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research.
In Bulgaria, NIS2 transposition requires amendments to the national cybersecurity framework, including the Cybersecurity Act and related secondary legislation. Businesses should monitor publications from the Council of Ministers, the Ministry of e-Government, the State e-Government Agency, and the Bulgarian national cybersecurity authorities for the final national implementation rules.
Who May Be Covered
NIS2 applies based on sector, size, and criticality. Medium-sized and large entities in covered sectors are generally more likely to be in scope. However, some entities may be included regardless of size if they provide critical services or meet specific criteria.
Manufacturing is particularly important. NIS2 covers certain manufacturing activities, including medical devices, computer, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles, trailers, semi-trailers, and other transport equipment.
A Bulgarian manufacturer supplying components for the automotive or medical device sector should assess whether it falls directly under NIS2 or indirectly through customer contractual requirements.
Core NIS2 Obligations
NIS2 requires covered entities to implement cybersecurity risk management measures. These include incident handling, business continuity, supply chain security, vulnerability management, access control, encryption where appropriate, secure network and information systems, and basic cyber hygiene and training.
The directive also introduces incident reporting obligations. Significant incidents must be reported through staged notifications, including an early warning, incident notification, and final report within the required timeframes.
Management bodies can be held responsible for approving cybersecurity measures and overseeing implementation. This makes NIS2 a governance issue, not only an IT issue.
Upcoming Deadlines in Relation to Legislative Changes for Manufacturers
Upcoming deadlines in relation to Legislative changes for Manufacturers should be tracked at both EU and Bulgarian levels. The exact dates vary by product category and national implementation measures, but several milestones are already clear.
Key EU and Bulgarian Compliance Milestones
18 October 2024: Deadline for EU Member States to transpose NIS2 into national law. Bulgarian businesses should verify the status of national transposition and prepare even if final national rules are still being adopted or updated.
2025 onward: Companies should expect continued implementation work under NIS2, cybersecurity registration or identification procedures where applicable, and increasing customer due diligence in supply chains.
2025-2026: The European Commission is expected to continue developing product-specific rules under the Ecodesign for Sustainable Products Regulation, including requirements that will activate DPP obligations by product group.
2027: Digital battery passport requirements under the EU Batteries Regulation are expected to apply to certain battery categories. This is one of the earliest concrete DPP-style requirements and is highly relevant for automotive, energy storage, electronics, and industrial equipment businesses.
PPWR implementation period: Once formally applicable, PPWR obligations will phase in over several years. Businesses should monitor entry-into-force dates, application dates, and specific transition periods for recyclability, recycled content, reuse, and labeling requirements.
Ongoing: Bulgarian EPR reporting and fee obligations continue under national waste legislation. Businesses should maintain accurate annual and periodic reporting for packaging, WEEE, batteries, and other regulated streams.
How to Build an Integrated Compliance Roadmap
Companies should avoid managing DPP, DPR, EPR, PPWR, and NIS2 as isolated legal projects. A more effective approach is to create one integrated compliance roadmap covering products, packaging, data, suppliers, cybersecurity, and reporting.

Step 1: Identify Scope
List all products, product groups, packaging types, business activities, digital services, and sectors in which the company operates. Map them against DPP, PPWR, EPR, NIS2, product safety, Ecodesign, batteries, WEEE, and packaging obligations.
Step 2: Build a Compliance Data Model
Define what data must be collected for each product and packaging unit. This may include material composition, weight, recycled content, supplier certificates, technical documentation, repair information, hazardous substances, carbon footprint, packaging format, and cybersecurity classification.
Step 3: Review Supplier Contracts
Many obligations depend on supplier data. Contracts should require suppliers to provide accurate compliance information, notify changes, support audits, and deliver data in structured formats suitable for DPP and regulatory reporting.
Step 4: Align IT and Cybersecurity
DPP and PPWR require reliable data. NIS2 requires secure systems and supply chains. Companies should connect compliance transformation with cybersecurity risk management, access controls, audit trails, and business continuity planning.
Step 5: Prepare for Enforcement and Customer Audits
Regulators are not the only source of pressure. Large customers, marketplaces, investors, insurers, and banks increasingly request proof of Regulatory Compliance in the EU. Companies should maintain evidence files and internal controls that can support both official inspections and commercial due diligence.
Internal Links for Further Reading
For a broader business transformation perspective, see our related resources on EU regulatory compliance roadmaps, Digital Product Passport readiness, packaging compliance and EPR strategy, and NIS2 cybersecurity governance.
Practical Takeaways for Bulgarian Businesses
Bulgarian companies should start with a gap assessment. The most exposed businesses are manufacturers, importers, distributors, e-commerce sellers, packaging-intensive companies, electronics and battery businesses, industrial suppliers, and entities in NIS2-covered sectors.
The immediate priority is to determine which obligations already apply under Bulgarian EPR and cybersecurity rules, which EU regulations are directly applicable, and which future DPP and PPWR requirements will affect products and packaging.
The second priority is data. Businesses that can collect, verify, secure, and reuse compliance data will be better positioned for audits, tenders, customer onboarding, and cross-border growth.
The third priority is governance. Compliance with DPP, EPR, PPWR, and NIS2 requires executive ownership, budget, technology, supplier engagement, and ongoing monitoring of EU and Bulgarian legal developments.
Sources and Official References
Regulation (EU) 2024/1781 on Ecodesign for Sustainable Products — legal basis for the EU Digital Product Passport framework.
Directive (EU) 2022/2555, NIS2 Directive — EU cybersecurity obligations for essential and important entities.
Regulation (EU) 2023/1542 concerning batteries and waste batteries — includes battery passport, carbon footprint, recycled content, and due diligence requirements.
European Commission: Packaging waste — policy updates on PPWR and packaging waste rules.
European Commission: Ecodesign for Sustainable Products Regulation — official information on ESPR and Digital Product Passports.
European Commission: NIS2 Directive — official overview of NIS2 scope, objectives, and implementation.
Bulgarian Ministry of Environment and Water — national authority for environmental and waste management policy, including EPR-related rules.
Ministry of e-Government of the Republic of Bulgaria — relevant Bulgarian authority for e-government and cybersecurity policy developments.
Bulgarian Waste Management Act — national legal framework for waste management and producer responsibility obligations.
Bulgarian Cybersecurity Act — national cybersecurity framework relevant to NIS2 transposition and implementation.





