Practical tool

Compliance checklist under NIS2 and the Cybersecurity Act

Directive (EU) 2022/2555, known as NIS2, is transposed in Bulgaria by the Cybersecurity Act. Here the requirements are collected in one place - with the article stated for every item - so that what is covered and what remains can be seen.

Working list

The requirements, item by item

Mark what is in place and see what remains. The list works entirely in your browser: we do not send, store or analyse the marks.

The list is a working tool, not an assessment of compliance. Whether an entity is essential or important is determined by the competent authorities under a methodology adopted by the Council of Ministers.

Nothing is marked yet.
Governance

The management body approves the measures and is responsible for their implementation.

Risk-management measures

The measures the Act lists. A measure without a document and without a review remains a statement.

Incident reporting

The deadlines run from the moment the incident is established, and the final report runs from the submission of the notification.

Data and register

The register is kept by the Minister of Electronic Governance and is not public (Art. 6(1) and (5)).

Supply chain and corrective measures

Responsibility does not end with your own systems.

The marks are kept only while the page is open. They are not stored, sent or analysed.

01

What the checklist contains

The list is not a general security checklist. It is built from the requirements the Act states, and every item carries the article it comes from: governance and training under Art. 21, the measures under Art. 22, incident reporting under Art. 23, the data under Art. 6, certified products under Art. 24, and the supply chain under Art. 22(3) and Art. 26.

That is also the practical benefit: a check does not ask whether a policy exists, but which requirement it covers and what evidences it. An item with a recorded article can be traced; an item without one turns into a dispute about scope.

02

How to use it

Mark only what can be supported by a document. If a measure is adopted but there is no record of when it was adopted and by whom it was reviewed, the mark is premature - this is the most common difference between working compliance and prepared documents.

Everything unmarked is a gap. A gap becomes a task with an owner and a deadline, and the result is reviewed by a second person. The platform supports exactly that sequence: requirement, answer, evidence, finding, task, review.

  • A mark without evidence does not count as done.
  • A gap is given an owner and a deadline rather than being left as a note.
  • Review by a second person is a separate step with a recorded decision.
  • The list is reviewed again when the scope or the systems change.
03

What is required of management

The management bodies approve the cyber risk management measures and monitor their implementation (Art. 21(1)). Approval is not a formality: it is also the basis on which the measures are defended in a check.

Members of the management bodies complete training every two years (Art. 21(2)), and training is offered and organised for employees as well (Art. 21(3)). For a breach of the obligations under Art. 21, the Act provides for a personal fine of 500 to 5 000 euro.

04

The measures under Art. 22(2) (12)

The Act lists the measures that entities must apply. They are appropriate and proportionate to the risk rather than identical for everyone: the degree of exposure to risk, the size of the entity and the likelihood of incidents are taken into account.

Where a gap is identified, corrective measures are taken to address it (Art. 22(4)). The supply chain is assessed separately - with the vulnerabilities of direct suppliers and service providers and with the results of coordinated risk assessments (Art. 22(3) and Art. 26).

  • 1. Policies on risk analysis and on the security of information systems.
  • 2. Incident handling.
  • 3. Business continuity, backup management and disaster recovery, and crisis management.
  • 4. Supply chain security, including the security aspects of the links with direct suppliers and service providers.
  • 5. Security in the acquisition of systems, in development and in maintenance, including vulnerability handling and disclosure.
  • 6. Policies and procedures to assess the effectiveness of the risk-management measures.
  • 7. Basic cyber hygiene practices and cybersecurity training.
  • 8. Policies and procedures on the use of cryptography and, where appropriate, encryption.
  • 9. Human resources security, access control policies and asset management.
  • 10. Multi-factor authentication and secured communications.
  • 11. Change management of information assets.
  • 12. Cyber risk management and reporting obligations for entities of a type listed in Annex I or II and for entities identified as critical under Directive (EU) 2022/2557.
05

The deadlines for an incident under Art. 23

A significant incident is notified in steps. The deadlines run from the moment the incident is established, and the deadline for the final report runs from the submission of the notification, not from the incident itself.

In practice this means that readiness to report is prepared before the incident: who establishes it, who assesses whether it is significant, who submits the notification and with what data. The 24-hour deadline leaves no time to invent a process at the moment of the incident.

  • within 24 hours: Early warning. The sector CSIRT is notified. Where applicable, the notification states whether the incident is suspected to be caused by unlawful or malicious action and whether it could have a cross-border impact.
  • within 72 hours: Incident notification. The information from the early warning is updated and an initial assessment of the incident is given: severity, impact and technical information, where available. For trust service providers this deadline is 24 hours.
  • at the request of the CSIRT: Intermediate report. Updated information about the incident is submitted when the CSIRT requests it.
  • within 1 month: Final report. The deadline runs from the submission of the notification in the previous step. The report describes the incident, its scope and impact, the likely cause or type of threat, the mitigation measures applied and the cross-border impact, where there is one.
  • if the incident is not handled: Intermediate and further final report. If the incident is not handled by the expiry of the deadline for the final report, an intermediate report is submitted, and the final report is submitted within one month of the handling of the incident.
06

Data and the register under Art. 6

The Minister of Electronic Governance keeps a register of the entities under Art. 4 and Art. 4a. It is not public, and the data in it must be current: the name, address and contact details, IP ranges, sector and type of entity, as well as the Member States in which the entity provides services, where applicable.

Changes to the data provided are notified to the relevant national competent authority within two weeks of the date of the change (Art. 6(3)).

  • The name of the entity.
  • Address and current contact details, including an email address and a telephone number.
  • IP ranges.
  • Sector, subsector and type of entity under Annex I or II, where applicable.
  • The Member States in which the entity provides services covered by the Act, where applicable.
07

What follows the checklist

A completed list shows where the uncovered areas are, but it does not create the evidence. The next step is for every requirement to get an answer, a document and a review, and for the gaps to become tasks with an owner and a deadline.

This is where the platform and the team behind it complement each other: the platform organises the process and keeps the evidence, while the technical side of the measures - access, backups, monitoring, networks - is implemented by the team when the organisation has no capacity of its own.

Reference basis: the Cybersecurity Act, State Gazette No. 17 of 13 February 2026. The full description of the obligations is on the Cybersecurity Act page, and the amounts of the penalties on the Penalties page.

Next step

Turn the marks into a proven result.

In the demonstration we will take one requirement from the list, connect the evidence to it, and follow the gap through to the verified action.

Request a demo