A11-K · Announcements · Founder · 22 August 2026
NIS2 / Bulgarian Cybersecurity Act
Inbound self-assessment — educational only. Not legal advice. Not an official audit. No register scrape. No cold email. No personal data collected by this page.
Public context
- Amendments to the Cybersecurity Act (NIS2 transposition) entered into force in February 2026.
- Reduced-fine grace period ended 1 June 2026.
- Essential and important entities; broader sector list than the prior regime.
- Management-body accountability and multi-stage incident reporting exist in the statute.
- Entity fines can reach high statutory caps (fixed euro amounts or a percentage of worldwide turnover).
Confirm always against the current State Gazette text and competent authority guidance.
1 · Entity profile (fill privately)
- Legal name / ЕИК — keep offline
- Sector(s) of activity
- Size band (employees / turnover) — medium+ often in scope for listed sectors
- Sole provider of a critical service? (may be in scope regardless of size)
2 · Possible scope indicators
- Operate in a sector under the Act’s annexes (energy, transport, health, digital infrastructure, ICT management, food, waste, chemicals, postal, certain manufacturing, digital services, research, and others)
- Qualify as a medium-sized or larger enterprise under applicable thresholds
- Provide systemically important services
3 · Governance & risk
- Documented cybersecurity risk-management policy
- Board / management oversight of cyber risk
- Supply-chain / third-party risk addressed
- Business continuity / disaster recovery plan exists and is tested
4 · Incident handling
- Process to detect and classify significant incidents
- Ability to notify the relevant CSIRT / authority within required windows (e.g. early warning ~24h where applicable)
- Defined contact points and escalation paths
5 · Technical / organisational basics
- Access control and least privilege
- Patch and vulnerability management
- Backups tested
- Logging and monitoring appropriate to the environment
- Staff awareness / training
6 · Internal outcome
Choose one for your internal file only:
- Likely out of scope
- Possibly in scope — seek qualified counsel
- In scope — formal compliance programme needed
Next internal action and any external counsel / MSP contact stay on your side. This page does not store answers.
What this is not
- Not a government certificate or official auditor statement
- Not permission to scrape commercial registers or harvest manager emails
- Not a template for unsolicited liability-pressure outreach
© 2026 Angel L. Krastev / A11-K · Educational inbound surface only.