The NIS2 Directive has been officially transposed into Bulgarian law through the latest amendments to the Cybersecurity Act

 

The Bulgarian Parliament has officially adopted the amendments to the Cybersecurity Act, transposing the European standards for a high level of cyber resilience (Network and Information Security Directive 2 / NIS2) into national legislation.

New Requirements and Scope:

The number of sectors covered by the law has expanded from 8 to 18, including Space, Waste Water, ICT Services, Postal and Courier Services, Manufacturing of Chemicals and Food, and others. Organizations are now categorized into Essential and Important Entities, each with specific obligations.

Incident Reporting Timelines

Essential and Important entities must notify CERT.bg of any significant incident within the following timeframes:

  • Within 24 hours: Submission of an "early warning" to CERT.bg regarding a significant incident.

  • Within 72 hours: Submission of an initial incident update/assessment.

  • No later than 1 month: Submission of a final report.

Reduced Sanctions until 2026 (§ 51):

A provision has been adopted stating that for violations committed until June 1, 2026, fines and property sanctions shall be imposed at a rate reduced by 50% of the amount established by law.

Restriction of High-Risk Technologies

The Council of Ministers, upon proposal by the Cybersecurity Council, may decree requirements for Essential and Important entities to use specific ICT products, services, and procedures that are operationally and economically proven to be suitable. Entities must comply with these requirements within 3 years of the decree's adoption. A shorter timeframe may be set in cases of high risk to national security.

 

Under the NIS2 framework, affected organizations are expected to identify and address security vulnerabilities, ensure process traceability, and implement a proactive rather than purely reactive approach to cyber threats. It is mandatory to implement a comprehensive internal risk management program. This serves as your primary evidence of due diligence before regulatory authorities, ensures business continuity, and increases stakeholder trust. The Act is expected to be published in the State Gazette and enter into force accordingly.

If you wish to assess your readiness level or conduct a regular audit in accordance with the NIS 2 Directive, please contact us for a professional consultation.

 

NIS2 Compliance Audit & Self-Assessment: Sample Questionnaire

 

The following questions are structured to assist organizations in identifying gaps, assessing maturity levels, and defining areas for improvement regarding NIS2 compliance.

I. Governance and Strategy

  1. Question: Has the management body approved the cybersecurity risk management measures and does it oversee their implementation?

    • Evidence: Board meeting minutes, formal policy approval documents, management review records.

  2. Question: Do members of the management body undergo regular cybersecurity training?

    • Evidence: Training certificates, attendance records for workshops or seminars.

  3. Question: Is there a designated person (e.g., CISO) who reports directly to management on security matters?

    • Evidence: Organizational chart, job description, records of regular management briefings.

  4. Question: How is the Segregation of Duties ensured to mitigate the risk of internal abuse?

    • Evidence: Roles and Responsibilities Matrix (RACI), access control audit logs.

II. Risk Management

  1. Question: Has the entity established and documented a methodology for cybersecurity risk assessment?

    • Evidence: Documented Risk Management Framework, threat and vulnerability analysis procedures.

  2. Question: Has a Risk Treatment Plan been developed and approved based on these assessments?

    • Evidence: Current Risk Register, approved implementation plan for security controls.

  3. Question: Are independent security audits of networks and information systems conducted?

    • Evidence: Internal or external audit reports, auditor competency certificates.

  4. Question: Is an up-to-date Asset Inventory maintained for all assets within the NIS2 scope?

    • Evidence: Asset Register including hardware, software, services, and data.

III. Technical Measures and Operational Security

  1. Question: Is Multi-Factor Authentication (MFA) implemented for access to sensitive systems?

    • Evidence: System configurations, authentication logs, Access Control Policies.

  2. Question: How does the entity manage the security of data at rest and in transit using cryptography?

    • Evidence: Encryption Policy, key generation, and management records.

  3. Question: Are mechanisms for malware detection and protection (EDR/XDR) in place?

    • Evidence: Active EDR/XDR systems, antivirus logs, periodic scan records.

  4. Question: How are changes to network and information infrastructure controlled?

    • Evidence: Change Management logs, approval records from the Change Advisory Board (CAB).

  5. Question: Is Network Segmentation applied to isolate critical assets?

    • Evidence: Network diagrams, VLAN configurations, and firewall rules.

  6. Question: Are Patch Management procedures applied within reasonable timeframes?

    • Evidence: Reports from patch management tools, implementation logs, vulnerability scans.

IV. Continuity and Incident Management

  1. Question: Does the organization have a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

    • Evidence: Documented BCP/DRP plans, Business Impact Analysis (BIA) results.

  2. Question: Are recovery plans tested at regular intervals (at least annually)?

    • Evidence: Exercise/drill reports, records of Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

  3. Question: Is there an established process for submitting an "early warning" within 24 hours of a significant incident?

    • Evidence: Incident Reporting Policy, report templates, records of past notifications.

  4. Question: How are the root causes of incidents analyzed after resolution?

    • Evidence: Root Cause Analysis (RCA) reports, lessons learned lists, and corrective action plans.

V. Supply Chain and Human Resources

  1. Question: Are cybersecurity clauses and the right to audit included in contracts with direct suppliers?

    • Evidence: Signed contracts/SLAs, third-party audit records.

  2. Question: Does the organization maintain an up-to-date register of its direct suppliers and the services they provide?

    • Evidence: Supplier directory, contact persons, list of provided ICT products.

  3. Question: Are background checks conducted for employees in critical positions?

    • Evidence: Vetting procedures, professional reference verification records.

  4. Question: Is there a procedure for the immediate termination of access upon employee offboarding?

    • Evidence: Termination checklists, account deactivation logs, asset return records.

VI. Monitoring and Performance Evaluation

  1. Question: Are Key Performance Indicators (KPIs) used to measure the effectiveness of implemented security controls?

    • Evidence: Metrics dashboards, quarterly/annual security status reports.

  2. Question: Are regular Penetration Tests and vulnerability scans conducted?

    • Evidence: Pen Test reports, scan records with remediation plans for critical findings.

  3. Question: How does the organization monitor changes in the threat landscape and update its risk analysis accordingly?

    • Evidence: Records of periodic risk reviews, threat intelligence bulletins.

*Note: The questions provided are for illustrative purposes, are not exhaustive, and should not be considered a final or complete checklist. Depending on the specific context, activities, scale, and risk profile of the organization, the number and content of applicable questions may be significantly larger or further customized.