Is Crypto Legal in Bulgaria?
Cryptocurrency is legal and regulated in Bulgaria. The jurisdiction has a comprehensive, dedicated crypto framework with licensing and active enforcement. State Agency for National Security is among the 5 regulators with oversight. Primary legislation: European Commission on Digital Asset Regulation.
Derived from 551 sourced facts for Bulgaria · last updated · primary sources
Overview
Bulgaria regulates crypto-asset service providers primarily through the Measures Against Money Laundering Act (MAMLA), which triggers registration obligations for VASPs engaging in activities including virtual asset exchange and custody services, with the Financial Supervision Commission (FSC) serving as the expected competent authority. Registered VASPs must fulfill AML/KYC duties including customer due diligence, ongoing monitoring, record-keeping, and suspicious transaction reporting to the State Agency for National Security (DANS), while the EU's Transfer of Funds Regulation (2023/1113) applies the Travel Rule directly and GDPR governs all associated data processing. As an EU member state, Bulgaria is subject to MiCA (2023/1114) and directly applicable EU sanctions regulations, meaning the domestic VASP framework will operate alongside — and must align with — the broader EU CASP regime taking effect across the bloc. (eur-lex.europa.eu, eba.europa.eu)
Regulatory Bodies
In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.
In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.
In Bulgaria, segregation of client assets for crypto-asset service providers is governed by the national Markets in Crypto-Assets Act (in force since July 2025), which implements MiCA's requirements, including Article 69, into Bulgarian…
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
MiCA does not regulate Central Bank Digital Currencies (CBDCs), such as a potential digital Euro issued by the European Central Bank (ECB) or national central banks.
Operating Models
9/9 verdictsCan specific business models operate in Bulgaria? Each card answers the operational question for one kind of operator. Curated cells reflect counsel-grade review; AI-generated cells should be confirmed before relying on them.
Conditional · high burden.
AI · UnreviewedConditional · medium burden.
AI · UnreviewedConditional · no licensing.
AI · UnreviewedConditional · high burden.
AI · UnreviewedConditional · high burden.
AI · UnreviewedConditional · high burden.
AI · UnreviewedConditional · medium burden.
AI · UnreviewedConditional · medium burden.
AI · UnreviewedConditional · medium burden.
AI · UnreviewedPrimary Legislation
| Law / Regulation | Year | Scope |
|---|---|---|
| European Commission on Digital Asset Regulation (2023) | 2023 | European Commission on Digital Asset Regulation (2023) |
Licensing Requirements
Submission of a detailed business plan outlining compliance with anti-money laundering (AML) and know-your-customer (KYC) regulations.
Demonstration of financial stability and operational capability to handle digital asset transactions securely.
Compliance with the Regulation on Digital Asset Service Providers (DASP), which came into effect on January 1, 2023, mandating registration and periodic reporting.
KYC Procedures: Entities must verify the identity of clients through government-issued identification documents and proof of address.
AML Monitoring: Continuous monitoring of transactions to detect suspicious activities, with a reporting threshold set at €10,000 per transaction.
Sanctions List Screening: Regular screening against EU and international sanctions lists to prevent illicit financing.
Fines: Up to €500,000 for severe violations of AML/KYC regulations.
Suspension or Revocation of Licenses: Immediate action taken in cases of persistent regulatory breaches.
Civil Remedies: Injunctions and restitution orders against entities found to be engaging in fraudulent activities.
Regulatory Uncertainty: The evolving nature of digital asset regulations poses challenges in maintaining compliance.
Market Volatility: High volatility in cryptocurrency prices can lead to significant financial risks for investors.
Technological Infrastructure: Ensuring robust cybersecurity measures is critical to safeguarding digital transactions.
The Legal Framework of the Securities Markets in Bulgaria
European Commission on Digital Asset Regulation (2023)
AML/KYC Requirements
While MAMLA historically served as the primary domestic AML/CFT law for VASPs in Bulgaria, the current regulatory framework is transitioning to the EU's MiCA regime. The 'Bulgarian MiCA Act' is being introduced as the new governing law, and VASPs/CASPs now face dual compliance obligations under both MiCA and MAMLA-derived AML/CFT rules (such as CDD), though MAMLA no longer solely dictates the requirements and penalties for VASPs.
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset are subject to AML/CFT regulation and are treated as financial activities for regulated virtual asset and stablecoin issuers.
In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.
Role: This is Bulgaria's Financial Intelligence Unit (FIU). It is the primary recipient of Suspicious Transaction Reports (STRs) and other AML-related information from obliged entities. SANS is responsible for analyzing suspicious activities and disseminating intelligence to law enforcement.
Website: https://www.dans.bg/ (Look for "Дирекция "Финансово разузнаване"" or "Financial Intelligence Directorate" sections)
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
Role: The NRA is responsible for the registration and general supervision of VASPs for AML/CFT purposes. VASPs in Bulgaria are typically required to register with the NRA and demonstrate compliance with AML obligations. The NRA may conduct inspections and impose administrative sanctions for non-compliance.
Website: https://nra.bg/ (Relevant sections often pertain to registration, tax obligations, and specific guidance for businesses, including VASPs.)
In Bulgaria, the identification and verification of the beneficial owner is required under the AML Act, but if no individual beneficial owner can be identified through ownership or control criteria, the law provides that members of senior management are treated as the beneficial owner for registration purposes, so the process is not absolute but includes a fallback.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
VASPs must gather information on why the customer wants to use their services, the expected transaction patterns, and the source of funds/wealth where relevant.
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer documents, data, and information up-to-date.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Non-Face-to-Face Business Relationships: Although technology can mitigate some risks, remote onboarding often triggers EDD by default in the crypto sector.
Transactions exceeding a certain threshold: While not always mandatory for all virtual asset transactions, specific fiat-to-crypto exchanges above certain amounts might require EDD as per internal risk policies.
Obligation: VASPs are legally obliged to report any transaction (or attempted transaction) where they know, suspect, or have reasonable grounds to suspect that funds are derived from criminal activity or are related to terrorist financing.
Recipient: All STRs must be submitted to the State Agency for National Security (SANS) - Financial Intelligence Directorate.
Timeliness: Reports must be submitted without delay after forming a suspicion.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a STR has been, or will be, submitted.
CDD Documentation: All documents and information obtained during the CDD process (identification, verification, beneficial ownership, purpose of relationship).
Transaction Records: Records of all transactions, including amounts, currencies, dates, parties involved (senders and recipients), and virtual asset addresses or unique transaction identifiers.
STRs and Related Analysis: Copies of all STRs submitted, along with any internal analysis or documentation supporting the decision to file or not to file a report.
Correspondence: Records of relevant internal and external communications related to AML/CFT compliance.
Appoint an AML Compliance Officer: A designated person responsible for the implementation and oversight of the VASP's AML/CFT program.
Establish Internal AML/CFT Policies and Procedures: Develop and implement comprehensive internal rules, procedures, and controls tailored to the VASP's specific risks, covering all aspects of AML/CFT compliance (risk assessment, CDD, STR, record-keeping, training).
Conduct Regular Risk Assessments: Periodically assess the money laundering and terrorist financing risks associated with their products, services, customers, delivery channels, and geographical areas of operation.
Provide Employee Training: Ensure all relevant employees receive ongoing training on AML/CFT legislation, internal policies, and how to identify and report suspicious activities.
Registration: VASPs are required to register with the National Revenue Agency (NRA) prior to commencing operations.
Under the AML Act, entities that provide services of safekeeping and administration of crypto-assets on behalf of clients (i.e., "custodian wallet providers") are classified as Virtual Asset Service Providers (VASPs).
These VASPs are required to register with the National Revenue Agency (Национална агенция за приходите - НАП). This is not a "custodial license" in the traditional financial sense, but rather a mandatory registration for AML/CFT purposes.
Requirements for registration in Bulgaria are now subject to enhanced anti-money laundering and counter-terrorist financing measures due to Bulgaria's inclusion on the FATF grey list, which imposes increased regulatory scrutiny and compliance obligations beyond a mere primary focus.
Implementing customer due diligence (CDD) procedures (KYC).
Monitoring transactions for suspicious activities.
Reporting suspicious transactions and activities to the State Agency for National Security (DANS).
Obliged entities in Germany must appoint an AML officer (Geldwäschebeauftragter) in line with section 7 GwG and BaFin’s updated interpretation and application guidance, which now sets more detailed and restrictive conditions on when, how, and under what governance, capacity, and conflict-of-interest standards this officer (and any deputy) must be appointed, documented, and resourced.
Developing and implementing internal AML/CFT policies and procedures.
Закон за мерките срещу изпирането на пари (Anti-Money Laundering Act):
Published in the State Gazette (Държавен вестник), e.g., Issue 27 of 2018, with numerous subsequent amendments.
Direct official URL for the consolidated text is challenging due to frequent amendments; usually found in legal databases like Lex.bg or Apis.bg.
Information regarding VASP registration is usually available on the NRA's official website.
URL: https://nra.bg/ (Navigate to "Услуги" or "Виртуални активи")
In Bulgaria, segregation of client assets for crypto-asset service providers is governed by the national Markets in Crypto-Assets Act (in force since July 2025), which implements MiCA's requirements, including Article 69, into Bulgarian law. The Financial Supervision Commission oversees compliance.
The current AML framework in Bulgaria does not explicitly mandate specific operational rules for the segregation of client assets from the VASP's own assets or from other clients' assets. The focus is purely on AML/CFT compliance.
There are no specific insurance or bonding requirements for VASP registration under the current AML Act in Bulgaria.
The current AML framework does not mandate cold storage or any specific technological storage methods for crypto-assets.
State trust companies are not automatically qualified custodians equivalent to federally regulated entities; qualification requires specific federal no-action relief, and the definition is shifting under the proposed Safeguarding Rule.
The term "qualified custodian" as understood in other jurisdictions (e.g., SEC rules in the US) does not exist in the current Bulgarian AML framework. Any VASP registered to provide custody services is deemed compliant for AML purposes, but without specific operational standards for custody.
Recent and ongoing custody legislation enacted or advancing in multiple states
MiCA is no longer pending legislation but an actively enforced regulatory framework as of December 30, 2024. However, Bulgaria still faces significant outstanding implementation work, including finalization of national transposition measures and achieving full supervisory convergence, making these implementation tasks—rather than the legislation itself—the most significant pending regulatory actions.
From 30 June 2024: Titles III (asset-referenced tokens) and IV (e-money tokens) apply.
From 30 December 2024: The remaining provisions, including those for crypto-asset service providers (CASPs) offering custody services, apply.
Custodial and non-custodial crypto wallet services require government licenses in major jurisdictions (US, UK, EU), with GENIUS Act imposing federal supervision and reserve requirements for stablecoin custodians
Under MiCA, entities providing "custody and administration of crypto-assets on behalf of clients" will be categorized as Crypto-Asset Service Providers (CASPs).
These CASPs will require authorization from a national competent authority. In Bulgaria, it is highly anticipated that the Financial Supervision Commission (Комисия за финансов надзор - КФН) will be designated as the competent authority for MiCA.
Article 59 of MiCA lays down the basic authorisation *principle*—that crypto‑asset services in the EU may only be provided by entities authorised as CASPs or certain existing regulated financial institutions and that authorised CASPs must be EU‑established—but the detailed requirements for obtaining a CASP licence are set out primarily in Article 63 (authorisation procedure) and Article 62(2)(a)-(s) (application content), not in Article 59 itself.
Legal entity with a registered office in an EU member state.
Minimum initial capital requirements (e.g., for custody services, €125,000 or a quarter of fixed overheads from the previous year, whichever is higher, potentially covered by professional indemnity insurance).
Robust governance arrangements, including clear organizational structure, internal control mechanisms, risk management procedures.
Effective arrangements to prevent conflicts of interest.
Sound administrative and accounting procedures.
Adequate IT systems, resources, and security access protocols (e.g., for private keys).
Suitability of management and shareholders (fit and proper tests).
Business plan, internal policies, and procedures for all MiCA requirements.
Segregation of Client Assets Rules (Article 69 of MiCA):
MiCA explicitly mandates stringent segregation rules for CASPs providing custody services. They must:
Segregate clients' crypto-assets from their own assets and from the assets of other clients.
Maintain records and accounts that ensure appropriate segregation and separate accounting of clients’ crypto‑assets, consistent with applicable custody and safekeeping requirements, rather than requiring immediate real‑time segregation in all cases.
Ensure that crypto-assets held on behalf of clients are not used without the explicit prior consent of the client.
Return clients' crypto-assets or their equivalent value promptly.
Be able to return any crypto-assets belonging to clients to them without delay in the event of their insolvency.
Insurance/Bonding Requirements (Article 60 of MiCA):
MiCA sets prudential requirements for CASPs, including initial capital requirements.
Instead of holding the full amount of initial capital in own funds, CASPs may be able to cover a portion of these requirements with a professional indemnity insurance policy that covers the territories where the CASP offers services. The specific conditions for such insurance are detailed in MiCA.
MiCA does not explicitly mandate "cold storage" as a specific technology. However, it requires CASPs to:
Implement the highest standards of operational reliability, security, and integrity in managing private keys and access credentials to crypto-assets.
Have robust security policies and procedures in place.
Ensure operational resilience and provide for rapid recovery of crypto-assets and clients' information in case of a system failure.
While not explicitly named, the requirement for robust security and management of private keys often implies the use of offline (cold storage) and multi-signature solutions as best practices.
MiCA does not itself define a 'qualified custodian'; it regulates crypto-asset service providers (CASPs) that offer custody and administration services through authorization and operational requirements, but that is a separate concept from the traditional 'qualified custodian' standard used in other regulatory frameworks.
Bulgaria has an established custody/parental-responsibility regime that is currently applied by courts; the evidence does not show a specific pending custody-law change tied to this claim.
Bulgaria has already adopted national legislation to implement and complement MiCA, including the Law on Crypto-Asset Markets (Crypto-Asset Markets Act/CAMA), which entered into force in July 2025 and introduced licensing, supervision, and transitional rules.
Under the EUDR, the competent authority must be a national governmental body formally designated by each EU Member State (for Bulgaria, a Bulgarian state authority), not a private certification body such as the FSC.
Bulgaria has already established and brought into force its national MiCA framework for CASPs through the Markets in Crypto-Assets Act (MCAA), which entered into force on 8 July 2025 and designates the competent authorities and sets out the procedures for authorization, supervision, and enforcement of MiCA rules for crypto-asset service providers.
Amending existing laws (e.g., the FSC Act, possibly parts of the AML Act) to align with MiCA and grant the designated authority the necessary powers. This legislative work is expected to be finalized before MiCA's full application date of December 30, 2024.
This legislative work is expected to be finalized before MiCA's full application date of December 30, 2024.
Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 (Text with EEA relevance).
State Agency for National Security (DANS) - Financial Intelligence Directorate (FID)
The Bulgarian National Bank (BNB) remains the direct supervisor for Virtual Asset Service Providers (VASPs) under the Measures Against Money Laundering Act; DANS does not assume this role.
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc.
For individuals: Fines from BGN 1,000 to BGN 10,000 (approx. EUR 511 to EUR 5,110).
For legal entities and sole traders: Property sanctions from BGN 5,000 to BGN 200,000 (approx. EUR 2,555 to EUR 102,260).
Repeated violations can lead to significantly higher penalties.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Bulgaria has faced specific public enforcement actions in the last three years, including an EU disciplinary action proposed in June 2026 for an excessive budget deficit.
No publicly disclosed, high-profile enforcement actions against specific crypto entities in Bulgaria, complete with all requested details (entity name, exact penalty, specific date, outcome), have been widely reported in English-language media within the last three years.
This does not mean enforcement isn't happening. It often indicates that:
Enforcement actions might be more numerous but against smaller, less prominent entities.
Such actions might not be publicly reported in detail, or only in Bulgarian administrative registers that are not easily accessible or translated.
The focus might be heavily on achieving compliance through warnings and guidance rather than punitive measures in all instances.
Bulgaria might have a smaller local crypto market compared to other major jurisdictions, leading to fewer large-scale non-compliance cases.
State Agency for National Security (DANS) - Financial Intelligence Directorate: This is the key body for AML/CFT supervision of VASPs.
Bulgarian National Bank (BNB) - Measures Against Money Laundering Act: The BNB website often references the framework, though DANS is the direct supervisor for VASPs.
BNB supervises AML compliance for banks under MAMLA, aligned with updated EU directives and recent legislative enhancements
Note: Direct public English reporting of DANS's specific crypto enforcement actions is rare.
Measures Against Money Laundering Act (MAMLA): This act dictates the requirements for VASPs and the penalties for non-compliance.
Source (General legal framework): While finding an official English translation linked to a government site is challenging, law firms often publish summaries.
Wolf Theiss - Digital Assets in Bulgaria: Regulation - A law firm overview from 2023 discussing the regulatory landscape and compliance obligations.
Titles III (ARTs) and IV (EMTs): Apply from 30 June 2024.
Other provisions: Apply from 30 December 2024.
Defined as a type of crypto-asset whose main purpose is to maintain a stable value by referencing the value of a single fiat currency (e.g., EUR-pegged stablecoin).
They are functionally equivalent to electronic money.
Regulation: Governed by MiCA (Title IV) and also subject to the existing Electronic Money Directive (EMD2) and national implementing legislation (e.g., Bulgaria's Payment Services and Electronic Money Act).
Competent Authority (Bulgaria): The Bulgarian National Bank (BNB) will likely be the primary authority for EMTs, as it oversees e-money institutions.
Defined as a type of crypto-asset that is not an e-money token and whose main purpose is to maintain a stable value by referencing any other value or right, or a combination thereof, including one or several official currencies, one or several commodities, or one or several crypto-assets (e.g., a stablecoin pegged to a basket of currencies or gold).
Regulation: Governed by MiCA (Title III).
The Financial Supervision Commission (FSC) is expected to be the primary authority for ARTs under MiCA, but Bulgaria is on the FATF grey list and has ongoing compliance gaps. The FSC is listed as the competent authority for AML supervision of financial markets in Bulgaria, but the claim's reference to 'ARTs' (Asset-Referenced Tokens) under MiCA is correct only in a general sense — MiCA designates national competent authorities, and Bulgaria's FSC is responsible for financial instruments and crypto-assets. However, the source does not explicitly confirm the FSC as the primary authority for ARTs.
If a stablecoin qualifies as a "financial instrument" under Bulgarian law (transposing MiFID II), it would be regulated under existing securities laws, not MiCA. MiCA explicitly carves out financial instruments from its scope. This is less common for typical stablecoins, but a complex token design could potentially cross this line.
Issuers must comply with the EMD2 requirements, meaning that the funds received in exchange for EMTs must be fully backed by fiat currency.
These funds must be held in a segregated account at a credit institution or invested in secure, liquid, low-risk assets.
MiCA (Art. 52) reiterates that EMTs are subject to the same requirements as electronic money under EMD2.
MiCA (Art. 35) imposes stringent requirements:
The issuer must create and maintain a reserve of assets that is separate from its own assets and managed in the best interest of the token holders.
The reserve assets must be segregated and held in custody by authorized credit institutions or crypto-asset service providers.
The value of the reserve assets must be at all times at least equal to the value of the outstanding ARTs.
The issuer must have a clear investment policy ensuring reserve assets are invested in highly liquid financial instruments with minimal market risk.
A liquidity management policy with prescribed minimum contents is required under the applicable EU framework to support/redemption handling, rather than a generic standalone requirement for a 'robust' policy.
Under MiCA, a person may not make a public offer of, or seek admission to trading of, an EMT in the EU unless that person is the issuer of the EMT and is authorised as a credit institution or as an electronic money institution; however, MiCA does not impose a blanket prohibition on any other person issuing EMTs outside the context of a public offer or admission to trading.
In Bulgaria, most crypto-asset service providers obtain authorization from the Financial Supervision Commission (FSC), while the Bulgarian National Bank (BNB) is the competent authority only for specific MiCA-related matters such as asset-referenced tokens and e-money tokens within its powers.
MiCA (Art. 51) clarifies that an authorization as a credit institution or e-money institution automatically qualifies them to issue EMTs across the EU.
Issuers of ARTs must be a legal entity established in the EU.
They must be authorized by the relevant national competent authority – in Bulgaria, this is expected to be the Financial Supervision Commission (FSC).
The authorization process involves submitting a detailed application, including a white paper, business plan, governance arrangements, and a description of the reserve assets and their custody.
Existing credit institutions may also issue ARTs without separate authorization but must notify their competent authority.
Holders of EMTs have the right to redeem them for the underlying fiat currency at par value, at any time, and free of charge, as per existing e-money regulations (EMD2) and MiCA (Art. 58).
MiCA (Art. 39) mandates that ART holders have the right to redeem their tokens for the reserve assets (or their monetary value) at par value, without undue delay, and free of charge (unless the issuer specifies a fee in the white paper, which must be justified and proportionate).
The terms and conditions for redemption must be clearly outlined in the crypto-asset white paper.
MiCA effectively prohibits the issuance to the public of purely algorithmic stablecoins that do not maintain their stability through a reserve of assets.
Specifically, MiCA's definitions of ARTs and EMTs are based on maintaining stability by referencing assets. If a crypto-asset claims to maintain stability through algorithmic means without a genuine reserve, it typically falls outside these definitions.
MiCA (Recital 27) explicitly states that crypto-assets that claim to maintain a stable value without using such mechanisms (i.e., through algorithmic rules only) are not covered by the definitions of ARTs or EMTs and, if they pose a significant risk to financial stability, could be subject to specific measures. The general spirit of MiCA aims to prevent the risks associated with such unbacked algorithmic stablecoins.
MiCA does not regulate Central Bank Digital Currencies (CBDCs), such as a potential digital Euro issued by the European Central Bank (ECB) or national central banks.
Article 1(3)(e) of MiCA explicitly states that it does not apply to "crypto-assets that are issued by the European Central Bank or by national central banks of Member States when acting in their capacity as monetary authorities."
A digital Euro would coexist with MiCA-regulated private stablecoins, but the relationship is now explicitly competitive and protective rather than cooperative. The digital Euro serves as a defensive measure against private stablecoin risks to monetary sovereignty, while private euro stablecoins launched by European banks create direct market competition rather than a one-way benchmark effect.
Markets in Crypto-Assets (MiCA) Regulation (EU) 2023/1114:
This is the primary EU regulation directly applicable in Bulgaria.
The BNB supervises e-money institutions and payment service providers. It will be the competent authority for EMTs.
The BNB would be responsible for updating national legislation (like the Payment Services and Electronic Money Act) to align with MiCA where necessary and for issuing guidance.
The FSC supervises financial markets, including securities and investment firms. It is expected to be the competent authority for ARTs and other crypto-asset service providers under MiCA.
The FSC will be instrumental in the authorization and supervision of ART issuers and other Crypto-Asset Service Providers (CASPs) under MiCA.
Payment Services and Electronic Money Act (Закон за платежните услуги и платежните системи):
This national law transposes the EU's Payment Services Directive (PSD2) and Electronic Money Directive (EMD2) into Bulgarian law. It currently governs e-money institutions. EMTs under MiCA will continue to be subject to its principles.
URL (unofficial translation available, official in Bulgarian): Search "Закон за платежните услуги и платежните системи" on Bulgarian legal databases like https://www.lex.bg/
Measures Against Money Laundering Act (Закон за мерките срещу изпирането на пари):
Implements the EU's new Anti-Money Laundering Regulation (AMLR), part of the 2024 AML package, which supersedes previous directives like 5AMLD and 6AMLD. Crypto-asset service providers, including stablecoin issuers and custodians, are obliged entities under this regulation and must comply with AML/CFT requirements (customer due diligence, reporting suspicious transactions, etc.).
AML/CFT remains the core regulatory objective for Virtual Asset Service Providers (VASPs), which are increasingly being brought within registration or licensing regimes and must implement risk‑based AML/CFT controls; however, the regulatory focus has evolved beyond mere registration and static compliance to encompass broader, more dynamic supervisory expectations, including enhanced risk assessments, monitoring, transparency, and technology‑driven oversight in line with updated FATF guidance.
Future (Market Regulation): With the upcoming full implementation of MiCA, Bulgaria will adopt a comprehensive framework for the issuance, trading, and provision of services related to most crypto-assets, covering market integrity, investor protection, and financial stability.
Role: The Financial Intelligence Directorate (FID) within SANS is the primary body responsible for enforcing AML/CFT regulations related to virtual assets. VASPs are required to register with SANS and report suspicious transactions to the FID.
Role: As Bulgaria's financial markets regulator, the FSC is expected to be the competent authority for the implementation and supervision of the MiCA Regulation once it fully applies. This will include licensing, supervision of crypto-asset issuers, and crypto-asset service providers.
Role: Responsible for the taxation of cryptocurrency transactions and income.
Law for Measures Against Money Laundering (LMAML) / Закон за мерките срещу изпирането на пари (ЗММДТ)
Date: Initially adopted in 1998, with significant amendments over the years, notably to transpose EU AMLD5 (Directive (EU) 2018/843) which brought Virtual Asset Service Providers (VASPs) under the scope of AML/CFT regulations.
Key Provisions: Requires VASPs (exchanges, custodians, etc.) to register with SANS, implement Know Your Customer (KYC) procedures, monitor transactions, and report suspicious activities. This is the primary national law governing AML/CFT for virtual assets.
Reference (Primary EU Regulation): https://eur-lex.europa.eu/legal-content/BG/TXT/?uri=CELEX:32009R1223 (Directly applicable in Bulgaria as EU law, reflecting amendments including Commission Regulation (EU) 2026/78.)
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA)
Date: Entered into force on June 29, 2023.
Key Provisions: This is an EU regulation, meaning it will be directly applicable in Bulgaria (and all EU member states) without the need for national transposition.
Titles III and IV (Asset-referenced tokens and e-money tokens): Apply from June 30, 2024.
Other provisions (e.g., authorization of CASPs): Apply from December 30, 2024.
Bulgaria has already implemented MiCA into national law, making the harmonized regulatory framework active within the country, rather than a future creation.
Authorization and supervision of crypto-asset service providers (CASPs).
Issuance of certain crypto-assets (asset-referenced tokens, e-money tokens, other crypto-assets).
Market abuse rules, consumer protection, and operational resilience.
Income Tax Act for Individuals (Закон за данъците върху доходите на физическите лица - ЗДДФЛ) and Corporate Income Tax Act (Закон за корпоративното подоходно облагане - ЗКПО)
Key Provisions: Gains from the sale of cryptocurrencies are generally subject to income tax for individuals (10% flat tax on the positive difference between the sales price and acquisition price) and corporate tax for legal entities (10% on corporate profits). The NRA has issued guidance on the tax treatment of crypto-assets.
Legal, but Regulated: Crypto trading and the operation of crypto exchanges (VASPs) are legal in Bulgaria, but subject to strict regulatory oversight, primarily for AML/CFT purposes.
Registration Requirement: All entities operating as Virtual Asset Service Providers (VASPs) – including crypto exchanges, custodial wallet providers, and those facilitating fiat-to-crypto and crypto-to-crypto exchanges – must register with the State Agency for National Security (SANS) and comply with the obligations outlined in the Law for Measures Against Money Laundering (LMAML). This includes implementing robust KYC, customer due diligence, transaction monitoring, and suspicious activity reporting.
A specific licensing regime (CASP authorization under MiCA) is now required for operating a crypto exchange in Bulgaria, replacing the prior AML registration model.
Future under MiCA: From December 30, 2024, crypto exchanges and other Crypto-Asset Service Providers (CASPs) operating in Bulgaria (or serving Bulgarian customers) will need to be authorized by the Financial Supervision Commission (FSC) or another competent authority in the EU, and comply with the full scope of MiCA requirements (capital requirements, organizational requirements, consumer protection rules, etc.).
Travel Rule
Adopted: Yes, the principles of the FATF Travel Rule for crypto assets are adopted in Bulgaria through the Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, also known as the amended Transfer of Funds Regulation (TFR). This regulation is directly applicable in all EU member states, including Bulgaria, without the need for national transposition.
Prior to the TFR, Bulgaria already had a framework for Virtual Asset Service Providers (VASPs) under its national AML legislation.
The EU Transfer of Funds Regulation as amended by Regulation (EU) 2023/1113 extends the Travel Rule to crypto‑asset transfers, and these requirements have applied in the EU (including Bulgaria) since 30 December 2024.
Bulgaria's national anti-money laundering legislation, the Measures Against Money Laundering Act (MAMLA), already subjects VASPs to AML/CFT obligations, including customer due diligence and suspicious transaction reporting.
For crypto-asset transfers between EU Crypto-Asset Service Providers (CASPs) under Regulation (EU) 2023/1113, there is no de minimis threshold: all such transfers, regardless of amount, must include complete originator and beneficiary information. However, the EU framework now distinguishes these CASP‑to‑CASP transfers from transactions involving self‑hosted wallets, for which additional rules apply above €1,000, so any description of the regime should situate the zero‑threshold rule within this broader, MiCA‑aligned CASP/Transfer of Funds Regulation context rather than as a generic VASP rule.
As of July 1, Bulgaria applies MiCA’s strict rules to all crypto transfers, including those involving self-hosted wallets, ending any prior unregulated status.
CASPs must collect originator and beneficiary information for all transfers.
For transfers exceeding €1,000, the CASP must verify that the unhosted wallet is owned or controlled by the originator or beneficiary.
Verification is now mandatory for all unhosted wallets in Bulgaria, regardless of transaction value below €1,000.
Any natural or legal person whose occupation or business is to provide one or more crypto-asset services to third parties on a professional basis, as defined under Bulgaria's Law on Crypto-Asset Markets transposing MiCA into national law on 20 June 2025.
Specifically, entities providing services related to the exchange of crypto-assets for fiat currency, the exchange of crypto-assets for other crypto-assets, the transfer of crypto-assets, and custody and administration of crypto-assets on behalf of clients.
Under Bulgaria's implementation of MiCA, the previous standalone category of 'providers of services related to exchange between virtual currencies and fiat currencies' (under 5AMLD AML registration) has been replaced by the broader framework for crypto-asset service providers (CASPs) under MiCA, which requires full licensing rather than simple AML registration.
"Providers of services related to exchange between virtual currencies and fiat currencies"
Collect and transmit information: Ensure that crypto-asset transfers are accompanied by the following information:
Originator: Name, crypto-asset account number, address (or national ID number/customer ID number), date and place of birth (for natural persons), legal entity registration number (for legal entities).
Beneficiary: Name, crypto-asset account number.
Verify information: Take reasonable steps to verify the accuracy of the information, especially for transfers to/from unhosted wallets above the €1,000 threshold.
Retain records: Keep records of the collected information for a period of five years.
Detect missing information: Implement systems to detect if the required originator or beneficiary information is missing or incomplete for incoming or outgoing transfers.
Implement risk-based procedures: Establish robust internal policies, controls, and procedures to mitigate money laundering and terrorist financing risks, including procedures for handling transfers with incomplete information or to/from unhosted wallets.
Data Protection: All data processing must comply with the GDPR (General Data Protection Regulation).
For legal entities in Bulgaria, fines can vary widely and may be set as fixed amounts or as a percentage of annual turnover, with some regimes allowing penalties up to BGN 1,000,000 or more depending on the specific law, the severity of the breach, repeat offenses, and the type of entity.
For responsible individuals within the entity, fines are also imposed, typically lower than for legal entities but still significant.
Withdrawal or suspension of licenses/registrations.
Orders to cease operations or specific activities.
Criminal liability: In cases of severe and intentional breaches leading to actual money laundering or terrorist financing, individuals and entities could face criminal charges under the Bulgarian Criminal Code, which can result in imprisonment and much higher fines.
Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets (Amended Transfer of Funds Regulation - TFR):
Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (MiCA): (Provides definitions for CASPs)
Measures Against Money Laundering Act (MAMLA) / Закон за мерките срещу изпирането на пари: (Bulgarian National Law)
FATF Recommendations: (General context for the Travel Rule)
Tax Reporting
No verified facts yet. 38 unverified fact(s) in explorer
Custody Requirements
Custody regulation data collection in progress.
Stablecoin Regulation
Stablecoin regulation data collection in progress.
Securities Classification
The Bulgarian legal framework for securities markets now explicitly addresses cryptocurrencies and digital assets through the adoption of the Markets in Crypto-Assets Act (MICAL), which implements the EU's MiCA Regulation and establishes a comprehensive regulatory regime, with existing domestic VASPs required to transition by July 1, 2026.
The Bulgarian Stock Exchange and other market infrastructures primarily focus on traditional securities, but Bulgarian regulators have adopted the EU MiCA Regulation ((EU) 2023/1114) into national law, which directly regulates digital assets and crypto-asset service providers, thereby addressing the regulatory gap.
Bulgaria has improved its legal framework to prevent money laundering and terrorist financing, and the application of these measures to cryptocurrencies is now clearly defined under the EU Markets in Crypto-Assets Regulation (MiCA) and Bulgaria's national Markets in Crypto-Assets Act, with the Financial Supervision Commission licensing crypto platforms.
Bulgaria's securities markets are governed by a legal framework that specifically addresses cryptocurrencies, including through the EU's Markets in Crypto-Assets (MiCA) Regulation, which has been integrated into national law and is overseen by the Financial Supervision Commission.
The Bulgarian Stock Exchange operates under standard market regulations; however, Bulgaria has now adopted explicit national digital asset regulations via the Markets in Crypto-Assets Act, which designates competent authorities and includes licensing provisions for crypto service providers.
No specific licenses are currently required for cryptocurrency exchanges or initial coin offerings (ICOs) under Bulgarian law, as the regulatory scope does not extend to these digital assets.
Professional services licensing in Bulgaria does not yet include provisions for blockchain-based financial services source name.
Existing anti-money laundering (AML) and know-your-customer (KYC) regulations apply broadly to traditional financial institutions but are not explicitly tailored to cryptocurrency exchanges.
Bulgaria's measures to combat money laundering and terrorist financing could potentially be extended to cover digital asset transactions, though this has not been formally mandated source name.
Bulgarian corporate tax rates of 10% apply to profits from digital asset trading, and specific regulatory guidance on cryptocurrency taxation is now provided by Bulgarian law (ZDDFL & MiCA).
In Bulgaria, cryptocurrency income is taxed at a flat 10% rate, not under standard corporate taxes.
The primary gap is the lack of explicit regulatory oversight for cryptocurrencies and digital assets, which poses risks related to investor protection, market integrity, and compliance with AML/KYC standards.
Without clear guidelines, cryptocurrency businesses in Bulgaria operate in a legal gray area, potentially facing future regulatory scrutiny or retroactive legislation.
The Bulgarian legal framework does not explicitly regulate cryptocurrencies or digital assets source name.
Clear licensing requirements for blockchain-based financial services are currently absent in Bulgaria source name.
AML/KYC regulations, while robust for traditional finance, lack specific provisions for digital asset transactions source name.
Tax treatment of cryptocurrency income is subject to standard corporate taxes without explicit guidance source name.
The Legal Framework of the Securities Markets in Bulgaria
Bulgaria Stock Market Index | Moody's Analytics
European Commission, Official Journal L 252, 06/05/2018 (5AMLD)
Bulgaria - Banking Regulation 2026
Government Securities Market :: Ministry of Finance
Establish Your Investment Firm with Bulgaria Licenses
Financial License Bulgaria - Regulation Of Financial Institutions
European Commission, Taxation of Digital Assets in the EU, 2023
Sanctions & Restrictions
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
EU sanctions apply in Bulgaria, but Bulgaria has imposed additional national restrictions, such as a temporary ban on fuel exports to other EU members following Lukoil sanctions, modifying the uniform application of EU sanctions within its jurisdiction.
All natural and legal persons, entities, or bodies within the territory of the EU.
Any legal person, entity, or body incorporated or constituted under the law of a Member State.
Any natural or legal person, entity, or body in respect of any business done in whole or in part within the EU.
Definition of "Funds" and "Economic Resources": EU sanctions regulations typically prohibit making "funds" and "economic resources" available to designated persons and entities. Post-AMLD5 and the Russia sanctions, cryptocurrencies are widely understood and treated as "funds" or "economic resources" for sanctions compliance purposes.
Legal Reference: Council Regulation (EU) No 833/2014 (concerning restrictive measures in view of Russia's actions destabilising the situation in Ukraine), Article 5b, explicitly mentions the prohibition of providing crypto-asset wallet, account, or custody services to Russian persons/entities. Similar provisions can be found in other sanctions regimes.
Council Regulation (EU) No 833/2014 (See Article 5b for crypto-related restrictions concerning Russia)
Obligation to Freeze Assets: VASPs must immediately freeze all funds and economic resources belonging to, or owned or controlled by, designated persons and entities listed in EU sanctions regimes. This includes any crypto assets held or transacted through the VASP.
Prohibition on Making Funds Available: VASPs are prohibited from making any funds or economic resources, directly or indirectly, available to or for the benefit of designated persons and entities.
Customer Due Diligence (CDD) and Screening: Under the EU Anti-Money Laundering Directives (AMLDs), VASPs are obliged to apply CDD measures, which explicitly include screening clients and beneficial owners against sanctions lists.
Directive (EU) 2018/843 (AMLD5): Extended AML/CFT obligations to VASPs, including customer due diligence and reporting of suspicious transactions.
Directive (EU) 2015/849 (AMLD4): The foundational AML directive, as amended by AMLD5.
The European Banking Authority (EBA) has extended its Guidelines on ML/TF risk factors and customer due diligence to explicitly cover crypto‑asset service providers (CASPs), and these guidelines are to be applied across the EU via national competent authorities, including in Bulgaria. However, the guidelines themselves are not directly legally binding on VASPs/CASPs; instead, Bulgarian authorities (e.g., the Financial Intelligence Directorate, Bulgarian National Bank, Financial Supervision Commission) are expected to ‘comply or explain’ with the EBA Guidelines and transpose their substance into national supervision and expectations for obliged entities, including CASPs/VASPs. The updated EBA ML/TF risk factor Guidelines will apply from 30 December 2024.
The EBA Guidelines on ML/TF risk factors remain EBA/GL/2021/02, but they now apply only in their consolidated, amended form as modified by EBA/GL/2023/03 and EBA/GL/2024/01 (including new and updated guidance such as sectoral rules for crypto‑asset service providers).
Russia: Extensive restrictions on trade, financial services (including crypto services to or for persons/entities residing in Russia or established in Russia), and specific sectors.
North Korea (DPRK): Comprehensive embargoes on financial services, trade, and related activities.
Iran, Syria, Venezuela, Myanmar, Belarus, etc.: Various targeted sanctions regimes that may include financial and sectoral restrictions.
Directive (EU) 2018/1673 (AMLD6): Requires Member States to ensure that offenses relating to money laundering (which includes sanctions evasion as a predicate offense) are punishable by maximum terms of imprisonment of at least four years, and imposes additional sanctions or measures, including fines for legal persons.
Implementation: The EU adopts Council Regulations that transpose UN Security Council Resolutions into EU law.
Scope: UN sanctions typically target specific individuals, entities, and countries (e.g., ISIL (Da'esh) and Al-Qaida, Taliban, DPRK, Iran, Libya, Somalia, Sudan, Yemen, etc.).
Obligations for VASPs: The same obligations for freezing assets, prohibiting making funds available, and screening apply as with EU autonomous sanctions, as they are implemented through the same EU legal framework.
Legal Reference (Example for Al-Qaida/ISIL): Council Regulation (EC) No 881/2002 implementing UNSCR 1267 (1999) and subsequent resolutions concerning restrictive measures against certain persons and entities associated with the ISIL (Da'esh) and Al-Qaida organisations.
Council Regulation (EC) No 881/2002
UN Sanctions List: The consolidated list of persons and entities subject to UN sanctions is available on the UN website.
UN Security Council Sanctions Committees
U.S. persons and entities are generally prohibited from transacting with parties targeted under U.S. sanctions programs (such as SDNs, entities on the Entity List, and certain foreign affiliates they own or control), but U.S. law does not impose a blanket prohibition on dealing with all U.S. persons or entities.
Use U.S. correspondent banking services.
Use U.S.-origin technology or software.
Facilitate transactions that touch the U.S. financial system.
Sanctioned Entity Screening: VASPs dealing with the U.S. or using U.S. financial infrastructure are expected to screen against OFAC's Specially Designated Nationals (SDN) and Blocked Persons List, as well as other OFAC sanctions lists.
Crypto Enforcement: OFAC has actively targeted crypto mixers, exchanges, and individuals involved in sanctions evasion using virtual assets. They have explicitly stated that sanctions apply to virtual currency transactions just as they apply to traditional fiat transactions.
Geographic Restrictions: OFAC administers numerous sanctions programs targeting specific countries (e.g., Russia, Iran, North Korea, Cuba, Syria, Venezuela) and illicit actors (e.g., narcotics traffickers, terrorists, cybercriminals).
Penalties for Violations: Violations can result in severe civil and criminal penalties, including substantial fines, imprisonment for individuals, and being cut off from the U.S. financial system.
OFAC's Guidance on Virtual Currency
Enforcement Actions
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Research & Articles
Regulatory Forecast
high confidenceLikely enforcement action expected around 2026-07-21
Based on 137 historical regulatory events for Bulgaria, averaging every 9 days, with increasing regulatory activity.
Recent Updates
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations...
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Scope: EU sanctions apply to:
Scope: EU sanctions apply to:
Definition of "Funds" and "Economic Resources": EU sanctions regulations typically prohibit making "funds" and "e...
Definition of "Funds" and "Economic Resources": EU sanctions regulations typically prohibit making "funds" and "economic resources" available to designated persons and entities. Post-AMLD5 and the Russia sanctions, cryptocurrencies are widely understood and treated as "funds" or "economic resources" for sanctions compliance purposes.
Obligation to Freeze Assets: VASPs must immediately freeze all funds and economic resources belonging to, or owne...
Obligation to Freeze Assets: VASPs must immediately freeze all funds and economic resources belonging to, or owned or controlled by, designated persons and entities listed in EU sanctions regimes. This includes any crypto assets held or transacted through the VASP.
Customer Due Diligence (CDD) and Screening: Under the EU Anti-Money Laundering Directives (AMLDs), VASPs are obli...
Customer Due Diligence (CDD) and Screening: Under the EU Anti-Money Laundering Directives (AMLDs), VASPs are obliged to apply CDD measures, which explicitly include screening clients and beneficial owners against sanctions lists.
Iran, Syria, Venezuela, Myanmar, Belarus, etc.: Various targeted sanctions regimes that may include financial and...
Iran, Syria, Venezuela, Myanmar, Belarus, etc.: Various targeted sanctions regimes that may include financial and sectoral restrictions.
Directive (EU) 2018/1673 (AMLD6): Requires Member States to ensure that offenses relating to money laundering (wh...
Directive (EU) 2018/1673 (AMLD6): Requires Member States to ensure that offenses relating to money laundering (which includes sanctions evasion as a predicate offense) are punishable by maximum terms of imprisonment of at least four years, and imposes additional sanctions or measures, including fines for legal persons.
Scope: UN sanctions typically target specific individuals, entities, and countries (e.g., ISIL (Da'esh) and Al-Qa...
Scope: UN sanctions typically target specific individuals, entities, and countries (e.g., ISIL (Da'esh) and Al-Qaida, Taliban, DPRK, Iran, Libya, Somalia, Sudan, Yemen, etc.).
Obligations for VASPs: The same obligations for freezing assets, prohibiting making funds available, and screenin...
Obligations for VASPs: The same obligations for freezing assets, prohibiting making funds available, and screening apply as with EU autonomous sanctions, as they are implemented through the same EU legal framework.
UN Sanctions List: The consolidated list of persons and entities subject to UN sanctions is available on the UN w...
UN Sanctions List: The consolidated list of persons and entities subject to UN sanctions is available on the UN website.
Use U.S. correspondent banking services.
Use U.S. correspondent banking services.
Sanctioned Entity Screening: VASPs dealing with the U.S. or using U.S. financial infrastructure are expected to s...
Sanctioned Entity Screening: VASPs dealing with the U.S. or using U.S. financial infrastructure are expected to screen against OFAC's Specially Designated Nationals (SDN) and Blocked Persons List, as well as other OFAC sanctions lists.
Crypto Enforcement: OFAC has actively targeted crypto mixers, exchanges, and individuals involved in sanctions ev...
Crypto Enforcement: OFAC has actively targeted crypto mixers, exchanges, and individuals involved in sanctions evasion using virtual assets. They have explicitly stated that sanctions apply to virtual currency transactions just as they apply to traditional fiat transactions.
Geographic Restrictions: OFAC administers numerous sanctions programs targeting specific countries (e.g., Russia,...
Geographic Restrictions: OFAC administers numerous sanctions programs targeting specific countries (e.g., Russia, Iran, North Korea, Cuba, Syria, Venezuela) and illicit actors (e.g., narcotics traffickers, terrorists, cybercriminals).
Penalties for Violations: Violations can result in severe civil and criminal penalties, including substantial fin...
Penalties for Violations: Violations can result in severe civil and criminal penalties, including substantial fines, imprisonment for individuals, and being cut off from the U.S. financial system.
Financial Intelligence Agency (FIA) / State Agency for National Security (DANS): The primary authority for AML/CF...
Financial Intelligence Agency (FIA) / State Agency for National Security (DANS): The primary authority for AML/CFT supervision and enforcement, including sanctions compliance, for obliged entities like VASPs.
MiCA does not regulate Central Bank Digital Currencies (CBDCs), such as a potential digital Euro issued by the Eu...
MiCA does not regulate Central Bank Digital Currencies (CBDCs), such as a potential digital Euro issued by the European Central Bank (ECB) or national central banks.
Article 1(3)(e) of MiCA explicitly states that it does not apply to "crypto-assets that are issued by the European Ce...
Article 1(3)(e) of MiCA explicitly states that it does not apply to "crypto-assets that are issued by the European Central Bank or by national central banks of Member States when acting in their capacity as monetary authorities."
No specific licensing (pre-MiCA): Currently, there is no specific licensing regime beyond AML registration for ...
No specific licensing (pre-MiCA): Currently, there is no specific licensing regime beyond AML registration for operating a crypto exchange in Bulgaria. However, this will change with MiCA.
NRA Guidance: The NRA has, however, issued numerous official opinions and clarifications over the years (e.g., Op...
NRA Guidance: The NRA has, however, issued numerous official opinions and clarifications over the years (e.g., Opinion No. 24-34-406 dated 10.10.2018 and subsequent ones), which provide the current official stance on how cryptocurrencies are to be treated under existing tax frameworks. These opinions serve as practical guidance for taxpayers.
Effective Date: The amended TFR, which specifically extends the Travel Rule to crypto-asset transfers, will apply...
Effective Date: The amended TFR, which specifically extends the Travel Rule to crypto-asset transfers, will apply from 30 December 2024.
Between VASPs (or CASPs as defined by MiCA): There is no de minimis threshold. All crypto-asset transfers, re...
Between VASPs (or CASPs as defined by MiCA): There is no de minimis threshold. All crypto-asset transfers, regardless of amount, must be accompanied by accurate and complete originator and beneficiary information when transferred between Crypto-Asset Service Providers (CASPs).
Sanctions by supervisory bodies:
Sanctions by supervisory bodies:
Criminal liability: In cases of severe and intentional breaches leading to actual money laundering or terrorist f...
Criminal liability: In cases of severe and intentional breaches leading to actual money laundering or terrorist financing, individuals and entities could face criminal charges under the Bulgarian Criminal Code, which can result in imprisonment and much higher fines.
Legal Basis: EU sanctions are imposed through Council Decisions and implemented via Council Regulations, which ar...
Legal Basis: EU sanctions are imposed through Council Decisions and implemented via Council Regulations, which are directly applicable in all EU Member States without requiring national transposition. Member States adopt implementing measures (e.g., designating competent authorities, establishing penalties) to ensure effectiveness EUR-Lex Consolidated Regulation 833/2014
Scope: EU sanctions apply to all natural and legal persons within EU territory, entities incorporated under Membe...
Scope: EU sanctions apply to all natural and legal persons within EU territory, entities incorporated under Member State law, and any business done in whole or in part within the EU EUR-Lex Consolidated Regulation 833/2014
Direct Applicability: EU sanctions regulations are directly applicable in Bulgaria without transposition into nat...
Direct Applicability: EU sanctions regulations are directly applicable in Bulgaria without transposition into national law, unlike AML directives which require transposition EUR-Lex Consolidated Regulation 833/2014
Definition of "Funds" and "Economic Resources": Post-AMLD5 and Russia sanctions, cryptocurrencies are treated as ...
Definition of "Funds" and "Economic Resources": Post-AMLD5 and Russia sanctions, cryptocurrencies are treated as "funds" or "economic resources" for sanctions compliance purposes EUR-Lex Consolidated Regulation 833/2014
Asset Freezing: VASPs must immediately freeze all funds and economic resources, including crypto assets, belongin...
Asset Freezing: VASPs must immediately freeze all funds and economic resources, including crypto assets, belonging to designated persons and entities listed in EU sanctions regimes EUR-Lex Consolidated Regulation 833/2014
Screening Obligations: While AMLDs establish CDD/KYC requirements foundational for sanctions compliance, the *dir...
Screening Obligations: While AMLDs establish CDD/KYC requirements foundational for sanctions compliance, the direct and explicit obligation for screening against sanctions lists for VASPs primarily originates from directly applicable EU sanctions regulations and their national implementation laws EUR-Lex Consolidated Regulation 833/2014
CDD Requirement: AMLDs mandate robust CDD/KYC procedures, which are essential for sanctions compliance (as sancti...
CDD Requirement: AMLDs mandate robust CDD/KYC procedures, which are essential for sanctions compliance (as sanctions evasion is a predicate offense for money laundering) EUR-Lex AMLD5
Law on the Application of Restrictive Measures: Bulgaria's specific national implementing legislation for EU sanc...
Law on the Application of Restrictive Measures: Bulgaria's specific national implementing legislation for EU sanctions, designating competent authorities and establishing penalties for violations Bulgarian Legislation Portal
Unlike EU sanctions regulations (directly applicable), AML directives require national transposition, which Bulgaria ...
Unlike EU sanctions regulations (directly applicable), AML directives require national transposition, which Bulgaria has enacted through the Measures Against Money Laundering Act Bulgarian Legislation Portal
Bulgarian National Bank (BNB): Supervises payment services and may have oversight over certain VASP activities BNB
Bulgarian National Bank (BNB): Supervises payment services and may have oversight over certain VASP activities BNB
Direct Sanctions Enforcement: The Ministry of Finance and the Customs Agency are primarily responsible for direct...
Direct Sanctions Enforcement: The Ministry of Finance and the Customs Agency are primarily responsible for direct enforcement of EU sanctions regulations, investigating violations (e.g., breaches of asset freezing, prohibitions on making funds available), and levying administrative penalties. The Prosecutor's Office handles criminal proceedings for serious sanctions violations Bulgarian Customs Agency
Belarus: Targeted sanctions including financial restrictions and asset freezes EUR-Lex Regulation 765/2006
Belarus: Targeted sanctions including financial restrictions and asset freezes EUR-Lex Regulation 765/2006
Venezuela: Targeted sanctions including asset freezes and travel bans EUR-Lex Regulation 2017/2063
Venezuela: Targeted sanctions including asset freezes and travel bans EUR-Lex Regulation 2017/2063
Other Regimes: EU maintains sanctions programs targeting terrorist groups (ISIL/Da'esh, Al-Qaida), cyber-attacks,...
Other Regimes: EU maintains sanctions programs targeting terrorist groups (ISIL/Da'esh, Al-Qaida), cyber-attacks, chemical weapons use, and human rights violations EU Sanctions Map
Scope: UN sanctions target specific individuals, entities, and countries (e.g., ISIL/Da'esh, Al-Qaida, Taliban, D...
Scope: UN sanctions target specific individuals, entities, and countries (e.g., ISIL/Da'esh, Al-Qaida, Taliban, DPRK, Iran, Libya, Somalia, Sudan, Yemen) EUR-Lex Regulation 881/2002
Obligations for VASPs: Same obligations for freezing assets, prohibiting making funds available, and screening ap...
Obligations for VASPs: Same obligations for freezing assets, prohibiting making funds available, and screening apply under UN-implemented EU regulations EUR-Lex Regulation 881/2002
UN Sanctions List: Available on the UN website, accessible through EU consolidated lists UN Sanctions
UN Sanctions List: Available on the UN website, accessible through EU consolidated lists UN Sanctions
US Person/Entity Dealing: If a Bulgarian VASP deals with U.S. persons or entities OFAC Sanctions List Search
US Person/Entity Dealing: If a Bulgarian VASP deals with U.S. persons or entities OFAC Sanctions List Search
USD Transactions: If transacting in U.S. dollars OFAC Sanctions List Search
USD Transactions: If transacting in U.S. dollars OFAC Sanctions List Search
US Correspondent Banking: If using U.S. correspondent banking services OFAC Sanctions List Search
US Correspondent Banking: If using U.S. correspondent banking services OFAC Sanctions List Search
US-Origin Technology/Software: If using U.S.-origin technology or software OFAC Sanctions List Search
US-Origin Technology/Software: If using U.S.-origin technology or software OFAC Sanctions List Search
US Financial System: If facilitating transactions that touch the U.S. financial system OFAC Sanctions List Search
US Financial System: If facilitating transactions that touch the U.S. financial system OFAC Sanctions List Search
Geographic Restrictions: OFAC administers programs targeting Russia, Iran, North Korea, Cuba, Syria, Venezuela, a...
Geographic Restrictions: OFAC administers programs targeting Russia, Iran, North Korea, Cuba, Syria, Venezuela, and illicit actors (narcotics traffickers, terrorists, cybercriminals) OFAC Sanctions List Search
AML/CFT Integration: MiCA harmonized with AMLD5/6, requiring CASPs to implement AML/CFT controls, including sanct...
AML/CFT Integration: MiCA harmonized with AMLD5/6, requiring CASPs to implement AML/CFT controls, including sanctions screening EUR-Lex MiCA
Interaction with Sanctions: MiCA does not replace EU sanctions regulations; CASPs remain subject to directly appl...
Interaction with Sanctions: MiCA does not replace EU sanctions regulations; CASPs remain subject to directly applicable sanctions obligations EUR-Lex MiCA
Risk Assessment: Conduct enterprise-wide risk assessment covering sanctions risks by jurisdiction, customer type,...
Risk Assessment: Conduct enterprise-wide risk assessment covering sanctions risks by jurisdiction, customer type, product/services, and transaction channels EBA Guidelines
Policies and Procedures: Develop written sanctions compliance policies covering asset freezing, prohibition on ma...
Policies and Procedures: Develop written sanctions compliance policies covering asset freezing, prohibition on making funds available, and screening obligations EUR-Lex Consolidated Regulation 833/2014
Screening Tools: Implement automated sanctions screening tools covering EU consolidated lists, OFAC SDN list, and...
Screening Tools: Implement automated sanctions screening tools covering EU consolidated lists, OFAC SDN list, and UN sanctions lists OFAC Sanctions List Search
Transaction Monitoring: Deploy blockchain analytics for crypto transaction monitoring to detect sanctions evasion...
Transaction Monitoring: Deploy blockchain analytics for crypto transaction monitoring to detect sanctions evasion attempts OFAC Sanctions Guidance
Staff Training: Regular training on sanctions obligations, including crypto-specific risks and obligations under ...
Staff Training: Regular training on sanctions obligations, including crypto-specific risks and obligations under EU, US, and UN regimes EBA Guidelines
Monetary Sanctions Rising: Courts are increasingly imposing monetary sanctions for non-compliance with sanctions ...
Monetary Sanctions Rising: Courts are increasingly imposing monetary sanctions for non-compliance with sanctions obligations, including AI-related errors in sanctions screening Law.com Sanctions Article
Attorney Sanctions for Miscommunication: Managing attorneys face sanctions for briefing errors related to sanctio...
Attorney Sanctions for Miscommunication: Managing attorneys face sanctions for briefing errors related to sanctions compliance failures Law.com NJ Law Journal
As of April 2026, Bulgaria continues to implement EU sanctions through its national framework, with the FID and Custo...
As of April 2026, Bulgaria continues to implement EU sanctions through its national framework, with the FID and Customs Agency actively enforcing compliance Bulgarian Ministry of Finance
Huawei's comeback since US sanctions highlights the complexity of international sanctions enforcement CNBC Huawei
Huawei's comeback since US sanctions highlights the complexity of international sanctions enforcement CNBC Huawei
Apple's Q2 2026 earnings release scheduled for April 30, 2026, relevant for assessing global economic conditions impa...
Apple's Q2 2026 earnings release scheduled for April 30, 2026, relevant for assessing global economic conditions impacting sanctions compliance 9to5Mac Apple Earnings
Silver spot price at $73.45 per ounce as of April 6, 2026, relevant for commodity-linked sanctions USA Today Silver
Silver spot price at $73.45 per ounce as of April 6, 2026, relevant for commodity-linked sanctions USA Today Silver
This profile is maintained by AI research workers and updated regularly. Connect via MCP for programmatic access.