Questions and answers

Questions prospective clients ask

General explanations, not legal advice. Whether a rule applies to your organisation depends on your facts, which we confirm in a free scoping call. Prices are “from” prices as published on this site and are confirmed in a written quote.

Information current as of September 2026. Regulatory sections are reviewed quarterly; the next review is due in December 2026.

About Dyasol

Who is Dyasol?

Dyasol Ltd is a security, regulatory-compliance and digital-trust consultancy registered in Sofia, Bulgaria, working with EU and international clients. We deliver fixed-price readiness work for DORA, NIS2, the EU AI Act, ISO/IEC 27001 and SOC 2, and we fill named officer roles that regulation requires. Our principle is evidence, not promises: every engagement ends with documents your board, auditor or regulator can actually use.

What is Dyasol not?

We are not a law firm, not a licensed statutory auditor, not a certification body, not a Big-Four consultancy, not a general IT-support or marketing agency, and not a budget penetration-testing shop. Where an engagement needs a licensed lawyer, a certification audit or a CPA attestation, we work alongside accredited partners and tell you up front who does what.

Are you independent?

Yes. We are vendor-neutral and we apply a separation principle: where we build or operate something, we will not also audit it. If you want us to both implement and assess, we say so and propose a partner for the assessment.

Who does the work and who is accountable?

Named professionals. Every deliverable names the person responsible for it; we do not hand your file to an anonymous pool. Our people and what each of them owns are listed on the People page.

Do you work in Bulgarian and English?

Yes. This website and our deliverables are available in either language: Bulgarian for local authorities and management, English for international groups and boards.

Can you work with organisations outside Bulgaria?

Yes. Our packaged work is remote by default and we serve EU and international clients. Where a national transposition or regulator differs from the Bulgarian one, we say what we have verified and what a local adviser must confirm.

The regulations and standards

Which regulations do you cover?

Binding EU law: DORA (Regulation (EU) 2022/2554); NIS2 (Directive (EU) 2022/2555 and its national transpositions, including Bulgaria’s Cybersecurity Act); the EU AI Act (Regulation (EU) 2024/1689); the GDPR (Regulation (EU) 2016/679), in particular the data-protection-officer requirement; the Cyber Resilience Act (Regulation (EU) 2024/2847), for incident and vulnerability reporting; and the Whistleblowing Directive (Directive (EU) 2019/1937). Voluntary frameworks: ISO/IEC 27001, ISO/IEC 42001, ISO 22301 and SOC 2.

What is DORA and who does it apply to?

DORA is the EU’s digital-operational-resilience regulation for the financial sector. It has applied since 17 January 2025 to banks, payment and e-money institutions, investment firms, insurers, fund managers, crypto-asset service providers and other financial entities, and it reaches their ICT suppliers through mandatory contract terms. In Bulgaria the supervisors are the Bulgarian National Bank (БНБ) and the Financial Supervision Commission (КФН); in Cyprus, CySEC. DORA requires an ICT risk-management framework approved by the management body, incident classification and reporting, resilience testing, a register of all ICT third-party arrangements, and specific contractual clauses with ICT providers.

What is NIS2 and how does it apply in Bulgaria?

NIS2 is the EU cybersecurity directive for essential and important entities. Bulgaria transposed it by amending the Cybersecurity Act (State Gazette No. 17 of 13 February 2026). The duties have applied since 17 February 2026; a transitional period with sanctions reduced by half ended on 1 June 2026, and the full regime applies now. You are in scope if you operate in one of the eighteen listed sectors and are at least a medium-sized enterprise — 50 or more staff, or turnover and balance-sheet total both above €10 million, counted with linked and partner enterprises. Administrative and judicial authorities are covered, and DNS providers, top-level-domain registries, trust-service providers, public electronic-communications providers, cloud and data-centre providers are covered regardless of size. Formal identification is administrative: the competent authorities designate entities under a methodology adopted by the Council of Ministers and notify them for entry in the national register kept by the Ministry of e-Government — but the duties do not wait for that letter. Management bodies must approve the measures, oversee them and train at least every two years. Significant incidents go to the sectoral CSIRT: early warning within 24 hours, notification within 72 hours, final report within one month. Fines reach €10 million or 2% of worldwide turnover for essential entities (statutory minimum €25,000) and €7 million or 1.4% for important ones (minimum €12,500); members of management bodies face personal fines of €500 to €5,000 and, at essential entities, a court-ordered temporary ban from management functions. The identification methodology and the updated ordinance on minimum measures were expected by October 2026; we track both.

Do we have to register with an authority under the Cybersecurity Act?

You do not self-register. The competent authorities identify essential and important entities under a methodology adopted by the Council of Ministers and notify them for entry in the national register kept by the Ministry of e-Government; the register is not public. Once entered, changes to your data must be notified within two weeks, and some digital providers — DNS, cloud, data-centre, managed-service and online-marketplace providers — carry their own notification duties. Two things matter in practice: the obligations and sanctions have applied since 17 February 2026 whether or not a letter has arrived, and the methodology and the updated ordinance on minimum measures were still expected by October 2026 when this page was written. We prepare the register data in advance and tell you what will be asked.

What does the EU AI Act require today?

As of September 2026: prohibited practices and the AI-literacy duty (Article 4) have applied since 2 February 2025; obligations for general-purpose AI model providers since 2 August 2025; transparency duties (Article 50 — telling people they are interacting with AI or that content is AI-generated) from 2 August 2026, with a grace period to 2 December 2026 for marking content from systems already on the market. The heavy high-risk obligations, including Article 26 deployer duties, have been deferred by the Digital Omnibus on AI: to 2 December 2027 for Annex III systems and to 2 August 2028 for AI built into regulated products. The deferral buys time; it does not remove the duties, and the rules already in force still apply.

What does the GDPR have to do with your services?

Two things. First, Article 37 makes a data protection officer mandatory for public authorities and bodies and for organisations whose core activities involve large-scale regular and systematic monitoring of individuals or large-scale processing of special-category data. We provide the DPO role as a serviced officer. Second, personal-data breaches must be notified to the supervisory authority within 72 hours where required — a duty we build into the same incident process as NIS2 and DORA reporting, so that one incident does not produce three uncoordinated notifications. We do not provide general GDPR legal advice.

What is the Cyber Resilience Act and does it affect me?

The CRA regulates products with digital elements placed on the EU market: hardware and software, from routers to SaaS-connected devices and standalone applications. Manufacturers must report actively exploited vulnerabilities and severe incidents from 11 September 2026: early warning within 24 hours, notification within 72 hours, and a final report within 14 days after a fix is available (vulnerabilities) or within one month (incidents). The full product-security obligations apply from 11 December 2027. If you only use software you are not a manufacturer under the CRA; if you build and sell it, you are. Our support is focused on the reporting duty through the incident-reporting coordinator role; we do not offer CRA conformity assessment.

What is the whistleblowing obligation?

Legal entities with 50 or more employees and public-sector entities must run a confidential internal reporting channel and follow up on reports within set deadlines. Bulgaria transposed the directive in 2023. We provide the whistleblowing-officer role; the legal design of the channel is confirmed with your legal adviser.

Are ISO 27001, ISO 42001, ISO 22301 and SOC 2 legal requirements?

No. They are voluntary frameworks that customers, tender rules or regulators increasingly ask for as proof. ISO/IEC 27001 (information security), ISO/IEC 42001 (AI management) and ISO 22301 (business continuity) are certified by independent certification bodies; SOC 2 is an attestation report that only a licensed CPA firm can issue. We prepare you for certification or attestation and act as your named officer; the certificate or report itself comes from the independent body, never from us.

If we already hold ISO 27001, are we NIS2 or DORA compliant?

Not automatically. ISO 27001 is strong evidence for many technical and organisational measures, but NIS2 and DORA add duties the standard does not test: management-body approval and training, statutory incident-reporting deadlines, supply-chain and contract requirements, registration with authorities, and in DORA’s case a third-party register and a resilience-testing programme. We map your existing certification to the legal requirements and show you the gaps rather than starting again.

Who must comply, and why

Who must comply with NIS2 — the full list?

Two things put you in scope: your sector and your size, with important exceptions. NIS2 covers eighteen sectors. Eleven are high-criticality (Appendix I of the Cybersecurity Act): energy; transport; banking; financial market infrastructure; health; drinking water; wastewater; digital infrastructure; ICT service management (business-to-business); public administration; and space. Seven are other critical sectors (Appendix II): postal and courier services; waste management; the manufacture and distribution of chemicals; the production, processing and distribution of food; manufacturing (medical devices, computers and electronics, electrical equipment, machinery and motor vehicles); digital providers (online marketplaces, search engines and social networks); and research organisations. Within those sectors you are in scope if you are at least a medium-sized enterprise — 50 or more staff, or annual turnover and balance-sheet total both above €10 million, counted together with linked and partner enterprises. Large entities in a high-criticality sector are “essential entities”, the strictest tier; the rest are “important entities”. Some entities are in scope regardless of size: DNS providers, top-level-domain registries, qualified trust-service providers, public electronic-communications providers, cloud and data-centre providers, and sole providers of a service essential to society. Administrative and judicial authorities are covered as well — see the next answer.

Do municipalities and other public bodies have to comply?

Yes. Administrative bodies are essential entities by category, not by size, so all 265 Bulgarian municipalities are in scope, together with central-government administration; judicial authorities are covered too. There is no exemption for a small municipality. The mayor, as head of the administration, personally approves the security measures and oversees them, and a manager who fails to do so can be fined €500 to €5,000. One difference for public bodies: the turnover-based fine — up to €10 million or 2% of turnover — does not apply to administrative-body essential entities, which have no turnover; enforcement against them takes the form of binding instructions, warnings, public disclosure of a confirmed breach and the personal fine on the manager. This is confirmed by the two Bulgarian municipal associations. The precise scope of public-sector duties will be settled further by the identification methodology and the updated ordinance on minimum measures, expected by October 2026; we track both.

How do you fall in scope, and how do you comply?

In two steps, and the order matters. First, the duties apply by operation of law: since 17 February 2026 an entity that meets the sector-and-size test is subject to the obligations whether or not it has received any letter. Second, formal identification is administrative — the competent authorities designate essential and important entities under a methodology adopted by the Council of Ministers and enter them in the national register kept by the Ministry of e-Government, which is not public; once entered, you notify changes to your data within two weeks. Complying then means: the management body approves the cybersecurity measures, oversees them and is trained at least every two years; you implement the risk-management measures required by the Act and its ordinance — risk analysis, incident handling, business continuity and backups, supply-chain security, access control and multi-factor authentication, among others; you keep a register of the suppliers that matter, with contract terms that give you security, cooperation and audit rights; and you report significant incidents to the sectoral CSIRT — early warning within 24 hours, notification within 72 hours, final report within one month. Our Evidence Sprint produces the documentation that proves each of these operates.

Why does NIS2 apply to us — what is it for?

NIS2 is an EU directive whose purpose is to raise the common level of cybersecurity across the services that society and the economy depend on — power, water, health, transport, finance, digital infrastructure and public administration — because a failure or attack in one spreads quickly to the rest. It does this by making cybersecurity a management responsibility rather than a purely technical one, by setting minimum measures and common incident-reporting rules, and by extending duties down the supply chain. Bulgaria transposed it through the Cybersecurity Act (State Gazette No. 17 of 13 February 2026). The consequences of ignoring it are concrete: fines up to €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important ones, personal fines and a possible temporary management ban for directors, targeted audits at your own expense, and public disclosure of a breach. Beyond the law itself, your regulated customers increasingly require evidence of compliance in their contracts, so the practical reach is wider than the statutory scope.

Am I in scope?

We are a private company outside the financial sector. What applies to us?

Conditional on sector and size: NIS2 applies if you are medium-sized or larger (broadly, 50 or more staff, or annual turnover and balance-sheet total both above €10 million) in one of the listed sectors — energy, transport, health, water, digital infrastructure, ICT service management, postal services, waste, chemicals, food, manufacturing of certain products, and digital providers; some entities are covered regardless of size. Even outside scope, you may inherit NIS2 or DORA requirements through customer contracts. Conditional on activity: a DPO if your core business involves large-scale monitoring or sensitive data; a whistleblowing channel at 50 or more employees; AI Act deployer duties, on the deferred timetable, for AI used in listed high-risk ways such as screening job candidates or deciding on promotion, termination or task allocation, plus transparency and literacy duties that apply now; CRA duties if you manufacture or sell software or connected products. Not legally required but often demanded by customers: ISO 27001 or SOC 2.

We are a financial entity. What applies to us?

Established: DORA, since 17 January 2025, supervised in Bulgaria by БНБ or КФН — a management-body-approved ICT risk framework, incident classification and reporting to the regulator’s deadlines, a testing programme, a complete register of ICT third-party arrangements, DORA-compliant clauses with every ICT provider, and a designated control function for ICT risk (Article 6). For financial entities DORA’s ICT-risk and incident-reporting rules replace the corresponding NIS2 requirements, though group companies outside the financial perimeter may fall under NIS2 in their own right. Also established: a DPO where the GDPR criteria are met, which they usually are for retail financial services; a whistleblowing channel at 50 or more staff. Conditional: AI Act high-risk duties for creditworthiness scoring and for risk assessment and pricing in life and health insurance, on the deferred timetable; transparency duties for customer-facing AI already.

We provide ICT services to financial entities. Are we regulated by DORA?

Indirectly, in most cases. DORA obliges your financial-sector customers to put specific clauses into your contract: service levels, security requirements, incident cooperation, audit and access rights, subcontracting conditions, exit and termination rights. Expect due-diligence questionnaires and register-data requests. Only ICT providers designated as critical by the European Supervisory Authorities are directly supervised under DORA, and that is a small number of large providers. Separately, you may be in NIS2 scope in your own right as a managed-service, cloud or data-centre provider if you meet the size threshold.

We are a software or SaaS vendor. What applies to us?

Conditional: the CRA, if your product is placed on the EU market, with reporting duties from 11 September 2026 and product obligations from 11 December 2027; NIS2, if you are a medium-sized or larger provider of managed services, cloud or other listed digital services; AI Act provider duties, if your product includes AI. Commercial reality: your enterprise and financial-sector customers will require evidence, DORA contract clauses, security questionnaires and increasingly ISO 27001 or SOC 2. Our Corporate Digital Trust Audit and questionnaire support are built for that pressure.

We are a small company. Are we really affected?

Possibly. Size thresholds keep most small companies out of NIS2 and out of the whistleblowing duty, but not out of the GDPR, the AI Act’s transparency and literacy duties, the CRA if you sell software, or the contract terms your regulated customers impose. Being small is a reason to scope carefully, not a reason to assume nothing applies.

What the duties mean in practice

What does “management accountability” mean under NIS2 and DORA?

The board or managing director must approve the cybersecurity or ICT-risk framework, oversee its implementation and be trained. Under Bulgaria’s Cybersecurity Act, members of the management body personally approve the measures, oversee them and undergo training at least every two years; a manager who does not can be fined €500 to €5,000 personally, and at essential entities the competent authority can ask a court for a temporary ban from management functions. Targeted security audits are carried out at the audited entity’s expense, and a confirmed breach can be made public. Under DORA the management body carries ultimate responsibility for ICT risk. Delegating the work does not delegate the accountability.

What are the incident-reporting deadlines?

NIS2 (Bulgarian Cybersecurity Act): to the sectoral CSIRT — early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours, final report within one month. DORA: an initial notification, an intermediate report and a final report to your financial supervisor within the deadlines set in the DORA reporting standards, running from classification of the incident as major. CRA (manufacturers): early warning within 24 hours, notification within 72 hours, final report within 14 days of a fix or within one month. GDPR: breach notification within 72 hours where required. A single incident can trigger more than one of these; the process has to be designed once and run from one playbook.

What is required for suppliers and third parties?

A register of the suppliers that matter, a risk assessment of each, contract clauses that give you security requirements, incident cooperation, audit rights and exit terms, and evidence that you actually monitor them. DORA is prescriptive about the register and contract content (Articles 28 to 30); NIS2 requires supply-chain security measures proportionate to risk.

Which officer roles are actually required by law?

Required in specific cases: a data protection officer (GDPR Article 37); an independent ICT-risk control function (DORA Article 6); a whistleblowing officer or channel operator (Directive 2019/1937). Under Bulgaria’s Cybersecurity Act, covered entities must organise and staff their cybersecurity function; whether a specific named officer is mandatory for your entity type is confirmed against the Act and its ordinance. Required by standard, not law, if you pursue certification: information-security responsibilities under ISO/IEC 27001, AI-governance responsibilities under ISO/IEC 42001, continuity responsibilities under ISO 22301. Useful but not named in law: third-party risk manager, business-continuity manager, incident-reporting coordinator. We tell you which is which so you do not pay for a title you do not need.

What counts as evidence?

A policy is a statement of intent. Evidence is proof that the control operates: an approved and dated document, a training record with attendees, a supplier register with review dates, an incident log with timestamps, test results, board minutes showing approval. Regulators and auditors ask for the second kind. Our Evidence Sprint produces it.

Which service fits which need

Where should we start?

For most organisations, with the Corporate Digital Trust Audit. It is low-risk, fast and shows concrete problems: how your domain looks to email systems, blacklists, fraud filters, search and AI engines, whether your brand or executives are being impersonated, and what is exposed on the internet. It gives you a prioritised list and a realistic picture before you commit to a larger programme.

What is the DORA / NIS2 Evidence Sprint and what do we receive?

A three-to-five-week engagement covering one legal entity and one regulation (DORA or NIS2). You receive a gap assessment with a prioritised roadmap, a review of your supplier and ICT contracts against the regulation’s requirements, and a board- and auditor-ready presentation, plus an executive fraud briefing. The base scope covers up to 100 employees, 15 supplier or ICT contracts and 25 existing policies; larger organisations or two regulations at once are quoted separately. The evidence pack documents where you stand and what you have; it does not certify compliance and no regulator pre-approves it.

What is the DORA readiness assessment and how is it different from the Evidence Sprint?

The DORA assessment is the focused option for a single financial entity with one supervisory relationship and up to 20 ICT arrangements: gap assessment and roadmap, supplier-contract review and board presentation, in three to six weeks. The Evidence Sprint is broader, covers NIS2 as well, and produces the full evidence pack and fraud briefing. If you only need to know where you stand with DORA, start with the assessment; implementation support is quoted separately.

What does the AI Governance & Shadow-AI Sprint do?

In three to four weeks we find the AI tools your staff already use, inventory up to five AI systems, write an acceptable-use policy with risk documentation, and set up transparency basics aligned with ISO/IEC 42001. Systems that may fall into the AI Act’s high-risk categories get a separate assessment. This is the fastest route to meeting the AI-literacy and transparency duties that already apply and to being ready for the high-risk obligations when they land.

What are the human-factors options?

Psychologist-facilitated options attached to the sprints: an executive fraud-decision workshop with the Evidence Sprint, and a human-factors annex — voluntary staff interviews on why unsanctioned AI tools are used — with the AI Sprint. They report themes only, never individual scores, and the technical content is owned by our security lead. Details and prices are on the Human factors page.

How does a serviced officer role work?

You appoint a named Dyasol professional to a role your regulation or standard requires: DPO, ICT-risk control-function owner, NIS2 cybersecurity officer, information-security officer, AI-governance officer, third-party risk manager, business-continuity manager, incident-reporting coordinator or whistleblowing officer. Tiers give you one, two or four working days per month; unused time rolls over for one month up to half the allowance; extra days are at the published day rate. Response commitment is four hours for critical issues during business hours and one business day otherwise. There is no 24/7 cover; for out-of-hours incident response we bring in partners. Notice period is 30 days, with no annual lock-in.

If we appoint your officer, is compliance now your responsibility?

No. Legal accountability stays with your management body; that is what the regulations say and we will not pretend otherwise. The officer gives you competence, independence and continuity, and documents what was decided and by whom. Where a role requires independence from operations — the DPO, or the DORA control function — we keep it separate from any implementation work we do for you.

When do we need a full-time hire instead of a serviced role?

When the role’s workload consistently exceeds four days a month, when your regulator expects a resident officer, or when the role has line-management duties. We will tell you when you have reached that point; many clients use the serviced role to bridge recruitment or to cover an absence.

Can you help with customer security questionnaires and due diligence?

Yes. Completing questionnaires, preparing evidence for customer audits and reviewing DORA contract clauses proposed by your financial-sector customers are standard parts of our work for vendors.

Do you do penetration testing and incident response?

We scope and coordinate penetration tests through accredited partners and retest fixes after remediation. We provide incident-management support and reporting coordination during business hours; we are not a 24/7 incident-response provider.

Commercial and practical

How does fixed pricing work?

Packaged work has a fixed scope and a fixed price; there is no hourly billing on it. Each package states what is included — entities, contracts, policies, hosts, AI systems — and what an addition costs. After a free scoping call we send a written quote within 24 to 48 hours. Prices on this website are “from” prices for the base scope; the quote is the price.

When do we pay?

After you approve the deliverable. Retainers for officer roles are billed monthly.

What do you need from us?

A named counterpart, access to existing policies, contracts and system inventories, time from the people who run the controls, and read-only access to the systems in scope where the engagement requires it. Anything touching a live system is snapshotted, staged, signed off and reversible.

Is the work on site or remote?

Remote by default. On-site days are agreed in the quote where they add value — board sessions or workshops, for example.

How do you protect our information?

Engagement data is handled under a written confidentiality agreement and, where personal data is involved, a data-processing agreement. Findings are shared only with the people you designate. Subcontractors, where used, are named in the quote.

Can we share your reports with our regulator, auditor or customers?

Yes. They are written for that purpose. The board presentation is designed for supervisory and audit audiences; the technical findings are for your teams and, at your discretion, your customers’ due-diligence reviewers.

Are your services suitable for public procurement?

Fixed scope and fixed price make our packages easy to specify and compare in a procurement file. We are not a certification body or statutory auditor, so tenders that require an accredited audit or attestation should specify that component separately; we can support the preparation.

What happens after the engagement?

Optional: a retainer for monitoring, advisory or an officer role, cancellable on 30 days’ notice. Nothing obliges you to continue.

Common misunderstandings

“Our cloud provider is DORA and NIS2 compliant, so we are.”

No. Your provider’s certifications help you evidence part of your supply-chain controls, but the obligations to govern, report, contract and test are yours. A regulator will ask you, not your provider.

“The AI Act was postponed, so nothing applies to us yet.”

Only the high-risk obligations were deferred (to December 2027 and August 2028). Prohibited practices, AI literacy, general-purpose model duties and transparency requirements already apply.

“We are not a bank, so DORA does not concern us.”

If you sell ICT services to a bank, insurer or investment firm, DORA arrives in your contract.

“We have written the policies, so we are compliant.”

Policies are the start. Regulators and auditors look for evidence that the controls run: records, logs, training, tests, approvals.

“Compliance can be outsourced.”

Work can be outsourced. Accountability cannot. Management approves, management trains, management answers.

How to proceed

Book a free 15-minute scoping call through the contact form. Tell us your entity type, sector, headcount, regulators and where your customers are. We come back with what applies to you, what does not, what is unresolved in law, and a written fixed-price quote.