Questions and answers

Frequently asked questions about NIS2 and the Cybersecurity Act

Short and specific answers to the questions we get most often - about scope, obligations, reporting and evidence.

Which organisations are obligated under the Cybersecurity Act?

Entities of the types under Annex I and Annex II that meet the criteria for a medium-sized enterprise or exceed the upper threshold for a medium-sized enterprise, as well as entities included on special grounds - for example providers of electronic communications networks or services, public authorities and organisations providing administrative services electronically.

Since when are the obligations in force?

The Act was promulgated in State Gazette No. 17 of 13 February 2026. For infringements committed up to 1 June 2026, fines and pecuniary penalties are imposed at an amount reduced by 50 percent.

What is reported and to whom?

Essential and important entities notify the sector CSIRT of every significant incident using the specified template. Where appropriate, the recipients of the affected services are also notified. Notification does not create increased liability for the notifying entity.

What exactly is required of management?

The management bodies approve the cyber risk management measures and monitor their implementation. Members of the management bodies undergo training every two years. For a breach of these obligations, the Act provides for a personal fine of 500 to 5 000 euro.

What penalties are provided for?

For an essential entity - up to 10 000 000 euro or up to 2% of total worldwide annual turnover, but not less than 25 000 euro. For an important entity - up to 7 000 000 euro or up to 1.4%, but not less than 12 500 euro. The higher value applies.

Who determines whether an organisation is an essential or an important entity?

The national competent authorities determine the essential and important entities according to a methodology adopted by the Council of Ministers. Therefore, the judgement of the organisation is the beginning of the process, not its final decision.

Do we need to notify in case of a change in the data?

Yes. Changes in the data provided are notified to the relevant national competent authority within two weeks of their occurrence (Art. 4(3)).

What evidence is expected during a check?

Documents that support a specific answer or action: policies, procedures, test protocols, reports. It is key that the evidence is linked to the requirement it supports, and that it is clear when and by whom it was reviewed.

Is the platform suitable for consultants and MSPs?

Yes. Each client organisation has an independent context, and roles separate who fills in, who manages and who reviews. The same process is applied repeatedly, without rebuilding the structure from scratch for each client.

Can the platform be used for frameworks other than NIS2?

The current content of the platform is built around NIS2 and the Bulgarian Cybersecurity Act. The architecture is built so that the content is versioned and separated from the logic, but other frameworks are not part of the current release and should not be assumed to be available.

Is anything stored in a database from the contact form?

No. Inquiries are sent by email and are not recorded in a database. The site does not use analytics tools, advertising pixels or marketing cookies.

Next step

Still have an unanswered question?

In the demonstration we will look at your specific case: scope, assessment and what the evidence looks like during a review.

Request a demo