Services

Bulgarian Cybersecurity Act programme

You see the whole path from assessment to upkeep and who delivers each part. You do not need to commission everything in one contract — we start with what you need now.

The first conversation is free. Scope and price are confirmed in writing before work starts.

Discuss where you are on the path

Who it is for

For essential and important entities in the sectors listed in the Act’s annexes, and for administrative bodies, which are always in scope. Municipalities and public bodies, see also the dedicated page; financial entities, see DORA.

The seven steps

StepWhat you receiveWho delivers
Assessment against the Cybersecurity Act and its ordinanceA “requirement — status — evidence — gap — action” matrix and a prioritised planDyasol, with your responsible staff
Building security governanceRoles and owners, policies, asset and risk registers, an annual plan, approved by managementDyasol drafts; management approves
Implementing safeguardsCompleted changes and records of their verificationYour IT team or contractor following our instructions — or Dyasol under a separate quotation; verification is ours
Continuity and recoveryPlans, a verified data restore and an exercise with a written recordDyasol leads; your IT team performs the restore
Incident readiness and reportingContacts and escalation, significant-incident criteria, templates for СЕРИКС and a rehearsed scenarioDyasol
Management and staff trainingA programme, delivered sessions and documented results — including management training every two yearsDyasol
Keeping compliance currentPeriodic reviews, current evidence, deadline reminders and task trackingDyasol through ongoing support

What we review, what we create, what we implement

We review

Your existing policies, procedures, contracts, registers and configurations — and whether they are actually applied.

We create

The missing documents and records: policies, roles, asset and risk registers, an incident response and reporting plan, a continuity plan, a training programme, an annual plan. Fitted to your organisation, not a generic template.

We implement

The technical and organisational measures. Your IT team or contractor carries them out following our instructions, or we do under a separate quotation. The verification and its record are always ours.

Starting almost from scratch? Then the main work is the second step — building governance. The price depends on the number of systems, units and documents and is given in a written quotation.

Incident help — what is agreed

Who receives the alert

A named Dyasol specialist and a deputy, through the agreed channel.

When

Within the agreed service window. A critical alert receives acknowledgement and first guidance within 4 working hours; this does not mean the incident is resolved.

What Dyasol does

Helps decide whether the incident is significant under the Act and whether personal data is affected; prepares the early warning and the notification to СЕРИКС; coordinates the response, keeps management informed and maintains the records for the register and the final report.

Who contains it technically

Your IT team or contractor. Digital forensics and out-of-hours response come from a specialist whose availability and terms are confirmed in advance and written into the contract. Round-the-clock cover is not part of the standard support.

Price and start

Step 1 uses the scope of the readiness and evidence pack — from €7 900. If you are unsure whether the Act applies to you, start with the applicability assessment — from €900. Step 7 runs through ongoing support — from €1 400 per month. The other steps are quoted in writing.

General scope and acceptance terms

Discuss where you are on the path