The European framework
The cyber risk management measures, the incident reporting obligations, supplier management and management responsibility are presented as the directive defines them.
NIS2 platform
Assessment, evidence, GAP analysis and corrective actions in one platform. Management sees the state. The team knows what comes next.
One connected process
What is NIS2
NIS2 is a European directive on the management of cyber risk. For the affected organisations it means ongoing work on measures, responsibilities, incidents and control.
The difficulty comes when the policies are in one folder, the evidence is in emails, the GAP analysis is in a separate file, and the tasks are tracked elsewhere.
NIS2.bg organises this work, without replacing legal or audit judgement.
Regulatory basis
The platform is not a generic checklist. Its structure follows the requirements of Directive (EU) 2022/2555 and the way they are transposed into Bulgarian law.
The cyber risk management measures, the incident reporting obligations, supplier management and management responsibility are presented as the directive defines them.
The work follows the transposition of the directive into Bulgarian cybersecurity law: applicability, obligated persons, measures and competent authorities.
The Cybersecurity ActEvery requirement becomes an understandable question for the team. This shows what is implemented, what is partial and what still needs to be checked.
Check your scopeThe platform follows the public regulatory framework. It is not an official portal of the European Union or of a state institution and does not replace legal advice.
The assessment does not end with a report. The platform connects the established state with the evidence and the subsequent work.
A look inside
Uploading a document does not automatically mean confirmation. A second person reviews the content, leaves a comment and records a decision. The history of decisions stays visible.
How evidence works
Why us
The assessment and the GAP analysis are the beginning. But a gap does not close itself, neither on paper nor technically.
Behind the platform stands a team that implements the measures in the real environment: access control, network, backups, monitoring. So the work does not stop at the report.
The same process, applied to your structure.
Management sees the overall state, and the team sees the specific tasks. Without collecting the latest version of every report.
A repeatable process for every client organisation, with separate context and clear roles between the person filling in and the reviewer.
In the assessment, this is a gap. In the platform, it gets a next step: a task to test it, an owner, a deadline and a protocol as evidence.
An illustrative scenario, not client data or a client result.
Why we do it
We work with organisations for which security is not an abstraction, but a daily matter. We have seen assessments that stay in Excel, evidence that cannot be found, and tasks without an owner.
NIS2.bg is our answer to that picture: not one more tool for reporting, but a place where the work gets carried through to the end.
About the productQuestions and answers
The full list of answers on scope, obligations, reporting and evidence is on a separate page.
All questions and answersNo. The obligations apply to entities from the sectors under Annex I and Annex II of the Cybersecurity Act, when the size threshold is also met. Scope is determined by type of activity and size, not by self-assessment.
Essential entities are those from the sectors of Annex I that exceed the upper threshold for a medium-sized enterprise. Entities from Annex I or II that do not meet these criteria are considered important. The difference also affects the maximum amount of the penalty.
No. The platform organises the work, stores the evidence and makes the process traceable. The judgement on scope, the assessment and the acceptance of a result remain decisions of the competent people in the organisation.
Each document is linked to a specific answer, finding or task. When updated, a new version is added, and the previous one remains in the history. Uploading does not mean automatic confirmation: review by a second person is a separate step with a recorded decision.
Next step
In the demonstration we will follow one gap from the assessment to the verified action - with test data close to your scenario.