NIS2 platform

Manage NIS2 as a process, not as a folder of files.

Assessment, evidence, GAP analysis and corrective actions in one platform. Management sees the state. The team knows what comes next.

  • A practical questionnaire, not an abstract list
  • Evidence stays next to the answers
  • Every gap gets an owner and a deadline

One connected process

  1. 01
    ScopeYou determine which activities and services you are assessing, with review by an owner.
  2. 02
    AssessmentA practical questionnaire with explanations, filled in by the people who know.
  3. 03
    EvidenceDocuments stay next to the answers, not in a separate folder.
  4. 04
    GAP analysisGaps become visible and get a priority.
  5. 05
    ActionsFindings and tasks with an owner, a deadline and a status.
  6. 06
    VerificationA second person confirms the result. The decision stays on record.

What is NIS2

NIS2 is not a single document that gets submitted once.

NIS2 is a European directive on the management of cyber risk. For the affected organisations it means ongoing work on measures, responsibilities, incidents and control.

The difficulty comes when the policies are in one folder, the evidence is in emails, the GAP analysis is in a separate file, and the tasks are tracked elsewhere.

NIS2.bg organises this work, without replacing legal or audit judgement.

Regulatory basis

Built around the directive and Bulgarian law.

The platform is not a generic checklist. Its structure follows the requirements of Directive (EU) 2022/2555 and the way they are transposed into Bulgarian law.

Directive (EU) 2022/2555

The European framework

The cyber risk management measures, the incident reporting obligations, supplier management and management responsibility are presented as the directive defines them.

Bulgarian law

The national application

The work follows the transposition of the directive into Bulgarian cybersecurity law: applicability, obligated persons, measures and competent authorities.

The Cybersecurity Act
Practical check

From the text to the work

Every requirement becomes an understandable question for the team. This shows what is implemented, what is partial and what still needs to be checked.

Check your scope

The platform follows the public regulatory framework. It is not an official portal of the European Union or of a state institution and does not replace legal advice.

A look inside

The check ends with a decision.

Uploading a document does not automatically mean confirmation. A second person reviews the content, leaves a comment and records a decision. The history of decisions stays visible.

How evidence works
Evidence review form with a comment and a Verified or Reject decision
Detail from a demonstration environment, without client data.

Why us

The software shows what is missing. We help fix it.

The assessment and the GAP analysis are the beginning. But a gap does not close itself, neither on paper nor technically.

Behind the platform stands a team that implements the measures in the real environment: access control, network, backups, monitoring. So the work does not stop at the report.

Proxmox Certified Specialist VMware Certified Professional Microsoft Certified Professional MikroTik Certified Network Associate ESET Certified Partner
What we cover and how we work
On paper

Process and evidence

  • Policies, procedures and responsibilities
  • Scope, assessment and GAP analysis
  • Evidence and decision history
Technical

Measures in the real environment

  • Access and multi-factor protection
  • Network, firewall and remote access
  • Backups and continuity

Backups exist. A verified restore does not.

In the assessment, this is a gap. In the platform, it gets a next step: a task to test it, an owner, a deadline and a protocol as evidence.

An illustrative scenario, not client data or a client result.

  1. EstablishedNo documented restore test
  2. AssignedA task with an owner and a deadline
  3. VerifiedThe protocol is linked to the task and confirmed

Why we do it

Because we have seen what the work looks like without it.

We work with organisations for which security is not an abstraction, but a daily matter. We have seen assessments that stay in Excel, evidence that cannot be found, and tasks without an owner.

NIS2.bg is our answer to that picture: not one more tool for reporting, but a place where the work gets carried through to the end.

About the product

Questions and answers

A short version of the most common questions.

The full list of answers on scope, obligations, reporting and evidence is on a separate page.

All questions and answers
Is NIS2 mandatory for every organisation?

No. The obligations apply to entities from the sectors under Annex I and Annex II of the Cybersecurity Act, when the size threshold is also met. Scope is determined by type of activity and size, not by self-assessment.

What is the difference between an essential and an important entity?

Essential entities are those from the sectors of Annex I that exceed the upper threshold for a medium-sized enterprise. Entities from Annex I or II that do not meet these criteria are considered important. The difference also affects the maximum amount of the penalty.

Does the platform replace a consultant or an auditor?

No. The platform organises the work, stores the evidence and makes the process traceable. The judgement on scope, the assessment and the acceptance of a result remain decisions of the competent people in the organisation.

What happens to the evidence we upload?

Each document is linked to a specific answer, finding or task. When updated, a new version is added, and the previous one remains in the history. Uploading does not mean automatic confirmation: review by a second person is a separate step with a recorded decision.

Next step

Show us how you work today.

In the demonstration we will follow one gap from the assessment to the verified action - with test data close to your scenario.

Request a demo