For municipalities and public bodies

Cybersecurity for municipalities and public bodies

Administrative bodies are covered by the Bulgarian Cybersecurity Act regardless of size — without waiting to be designated. We help you establish what is required of you, build what is missing and keep it current, together with your IT staff or contractor.

The first conversation is free. Scope and price are confirmed in writing before work starts.

Discuss your organisation

What the Act requires of a public administration

  • Administrative bodies are covered by the Act (Art. 4(1)) and are essential entities regardless of size (Art. 4a(1)(4)). Every municipality is covered through its mayor as an executive body. The judiciary and organisations that provide administrative services electronically are also covered (Art. 4(7)–(9)).
  • The national competent authority for administrative bodies is the Ministry of Innovation and Digital Transformation (Art. 16(2)).
  • The head of the body approves the risk-management measures and oversees their implementation (Art. 21(1)).
  • Management completes cybersecurity training every two years and organises training for staff (Art. 21(2) and (3)).
  • For a breach of Art. 21 the head of the body can be fined personally — EUR 500 to 5 000 (Art. 29(4)).
  • A significant incident is reported to СЕРИКС: an early warning within 24 hours and a notification within 72 hours of establishing it (Art. 23(5)).
  • Minimum measures are set by an ordinance under Art. 3 of the Act. As of 30 September 2026 the 2019 ordinance is in force; the statutory deadline for the new one falls around mid-October 2026. We check what applies at the time of the engagement.

General information, not a legal opinion. Separate legal support can be agreed for a specific legal question. Regulatory reference

The systems that are usually in scope

For example: records-management and electronic document flow; local taxes and fees; portal and electronic administrative services; accounting and payroll; the organisation’s email and domain; video surveillance and building access; systems maintained by an external IT contractor.

Many municipalities have no IT department of their own and rely on an external contractor. The responsibility stays with management — so we also set out what the contractor must do and how it is verified.

The whole path — and who delivers each part

StepWhat you receiveWho delivers
Assessment against the Cybersecurity Act and its ordinanceA “requirement — status — evidence — gap — action” matrix and a prioritised planDyasol, with your responsible staff
Building security governanceRoles and owners, policies, asset and risk registers, an annual plan, approved by managementDyasol drafts; management approves
Implementing safeguardsCompleted changes and records of their verificationYour IT team or contractor following our instructions — or Dyasol under a separate quotation; verification is ours
Continuity and recoveryPlans, a verified data restore and an exercise with a written recordDyasol leads; your IT team performs the restore
Incident readiness and reportingContacts and escalation, significant-incident criteria, templates for СЕРИКС and a rehearsed scenarioDyasol
Management and staff trainingA programme, delivered sessions and documented results — including management training every two yearsDyasol
Keeping compliance currentPeriodic reviews, current evidence, deadline reminders and task trackingDyasol through ongoing support

You do not need to commission everything at once. Detail on each step: Bulgarian Cybersecurity Act programme.

Example: part of the matrix for one municipality

Fictional data — an illustration of the format, not a client case.

RequirementStatusEvidenceGapAction
Management approves the measures (Art. 21(1))Policy exists, no decisionDraft policy from 2025No mayor’s actApproval order; annual review
Management training (Art. 21(2))Not held—No recordSession by quarter end; attendance list and test
Backups of the records-management systemDone by the contractorSupport contractRestore never testedRestore test with a written record
Reporting a significant incident (Art. 23(5))No procedure—No contacts or criteriaProcedure, СЕРИКС templates, exercise
External IT contractor accessShared admin account—No named access or reviewNamed accounts, multi-factor sign-in, six-monthly review

Related obligations we help with

Cybersecurity is not the only thing the law asks of a public administration. These areas connect with it and can be commissioned separately or together.

AreaBasisWhat you receiveWho is responsibleBoundary
Personal data and the data protection officerGDPR and the Bulgarian Personal Data Protection Act. Public authorities must as a rule have a data protection officer (GDPR Art. 37(1)(a)); courts acting in their judicial capacity are excepted.An external data protection officer or support for your internal one; a review of processing, access, retention periods and processor contracts; impact assessments where risk is high — for example video surveillance or biometrics; one process for personal-data breaches and cyber incidents; training.The team’s legal specialist and the security leadAn external data protection officer is independent and does not also hold roles that decide the purposes and means of processing. An impact assessment is required where risk is high, not for every system. We take on the role for many municipalities at once — each with a designated responsible person.
E-governmentThe Bulgarian E-Government Act and its ordinances — electronic administrative services, electronic documents and information systems.Assessment and acceptance of electronic services and information systems: a review of services, identification, signing and document flow; architecture, integrations and interoperability; technical requirements for new systems; an acceptance plan and checks for delivered software.Development, architecture and DevOps specialists, led by the security leadWe do not replace the supervisory bodies. Legal questions are settled with the legal specialist.
Internal control and IT riskThe Public Sector Financial Management and Control Act requires risk management and effective internal control.IT and cyber risks in the organisation’s risk register; segregation of duties; control of privileged access, changes and suppliers; measures against payment fraud through changed bank details; evidence for internal auditors.The security leadWe do not perform full financial control or statutory internal audit — our role is the specialist IT-risk work.
Artificial intelligenceThe EU AI Act also applies to public bodies that use or provide AI systems.An inventory of the tools and systems in use; roles, risk and applicable obligations; rules for data, approval and human oversight; AI literacy; supplier assessment; preparation for a fundamental rights impact assessment where use is high-risk.The security lead, the legal specialist and the human-factors specialistObligations for high-risk systems apply from 2 December 2027 (Annex III) and from 2 August 2028 (regulated products, Annex I).
Whistleblowing channelsThe Bulgarian Whistleblower Protection Act.Internal rules, training for the responsible staff, a secure technical environment, restricted access and confidentiality checks.The team’s legal specialist and the security leadPublic bodies may not outsource the receipt, registration or examination of reports. We help you build and run the internal process.
Open data and access to informationThe Access to Public Information Act and the re-use rules, including high-value datasets.A data inventory and classification, preparation for publication, anonymisation, a re-identification risk review, API security.Data and security specialists, with the legal specialist on legal questionsDecisions on access and restrictions are the organisation’s and are prepared with the legal specialist.

More on artificial intelligence: AI use and governance review. The people behind the roles are introduced on the team page.

Procurement

We help prepare the technical specification: activities and stages, deliverables, acceptance, on-site visits, what is expected from your IT team or contractor and how sensitive information is handled. First steps are usually below the threshold for award without a procedure under Art. 20(4) of the Public Procurement Act. Details about Dyasol as a contractor are in the supplier information.

Price

The first-step assessment uses the scope of the readiness and evidence pack — from €7 900 for one organisation of up to 100 employees. A larger administration and building what is missing are quoted in writing after the free conversation. Ongoing support starts at €1 400 per month.

Annual programme for a municipality — €24 700

  • An assessment under the Cybersecurity Act and the ordinance, in the scope of the readiness and evidence pack (€7 900).
  • Twelve months of ongoing support (€1 400 per month): annual plan, registers, preparation of management decisions, readiness to report to СЕРИКС (the national CSIRT) and training.
  • A named lead and a named deputy for contact.

The included monthly capacity is 8 expert hours. Priorities, training and timelines are planned within that capacity; additional hours and technical implementation are agreed separately.

One contract for the whole year, accepted in stages. The programme is not split into smaller orders.

Boundaries

  • We are not a certification body and do not replace supervision.
  • Technical containment of an incident and round-the-clock response are not part of the standard support — they are agreed separately.
  • For large critical-infrastructure operators we take on a defined, agreed part of the programme.
  • Classified information and system accreditation are not a standard service — we take them on only after checking the required clearances and available specialists.

Discuss your organisation