Services
Bulgarian Cybersecurity Act programme
You see the whole path from assessment to upkeep and who delivers each part. You do not need to commission everything in one contract — we start with what you need now.
The first conversation is free. Scope and price are confirmed in writing before work starts.
Discuss where you are on the pathWho it is for
For essential and important entities in the sectors listed in the Act’s annexes, and for administrative bodies, which are always in scope. Municipalities and public bodies, see also the dedicated page; financial entities, see DORA.
The seven steps
| Step | What you receive | Who delivers |
|---|---|---|
| Assessment against the Cybersecurity Act and its ordinance | A “requirement — status — evidence — gap — action” matrix and a prioritised plan | Dyasol, with your responsible staff |
| Building security governance | Roles and owners, policies, asset and risk registers, an annual plan, approved by management | Dyasol drafts; management approves |
| Implementing safeguards | Completed changes and records of their verification | Your IT team or contractor following our instructions — or Dyasol under a separate quotation; verification is ours |
| Continuity and recovery | Plans, a verified data restore and an exercise with a written record | Dyasol leads; your IT team performs the restore |
| Incident readiness and reporting | Contacts and escalation, significant-incident criteria, templates for СЕРИКС and a rehearsed scenario | Dyasol |
| Management and staff training | A programme, delivered sessions and documented results — including management training every two years | Dyasol |
| Keeping compliance current | Periodic reviews, current evidence, deadline reminders and task tracking | Dyasol through ongoing support |
What we review, what we create, what we implement
We review
Your existing policies, procedures, contracts, registers and configurations — and whether they are actually applied.
We create
The missing documents and records: policies, roles, asset and risk registers, an incident response and reporting plan, a continuity plan, a training programme, an annual plan. Fitted to your organisation, not a generic template.
We implement
The technical and organisational measures. Your IT team or contractor carries them out following our instructions, or we do under a separate quotation. The verification and its record are always ours.
Starting almost from scratch? Then the main work is the second step — building governance. The price depends on the number of systems, units and documents and is given in a written quotation.
Incident help — what is agreed
Who receives the alert
A named Dyasol specialist and a deputy, through the agreed channel.
When
Within the agreed service window. A critical alert receives acknowledgement and first guidance within 4 working hours; this does not mean the incident is resolved.
What Dyasol does
Helps decide whether the incident is significant under the Act and whether personal data is affected; prepares the early warning and the notification to СЕРИКС; coordinates the response, keeps management informed and maintains the records for the register and the final report.
Who contains it technically
Your IT team or contractor. Digital forensics and out-of-hours response come from a specialist whose availability and terms are confirmed in advance and written into the contract. Round-the-clock cover is not part of the standard support.
Price and start
Step 1 uses the scope of the readiness and evidence pack — from €7 900. If you are unsure whether the Act applies to you, start with the applicability assessment — from €900. Step 7 runs through ongoing support — from €1 400 per month. The other steps are quoted in writing.