For municipalities and public bodies
Cybersecurity for municipalities and public bodies
Administrative bodies are covered by the Bulgarian Cybersecurity Act regardless of size — without waiting to be designated. We help you establish what is required of you, build what is missing and keep it current, together with your IT staff or contractor.
The first conversation is free. Scope and price are confirmed in writing before work starts.
Discuss your organisationWhat the Act requires of a public administration
- Administrative bodies are covered by the Act (Art. 4(1)) and are essential entities regardless of size (Art. 4a(1)(4)). Every municipality is covered through its mayor as an executive body. The judiciary and organisations that provide administrative services electronically are also covered (Art. 4(7)–(9)).
- The national competent authority for administrative bodies is the Ministry of Innovation and Digital Transformation (Art. 16(2)).
- The head of the body approves the risk-management measures and oversees their implementation (Art. 21(1)).
- Management completes cybersecurity training every two years and organises training for staff (Art. 21(2) and (3)).
- For a breach of Art. 21 the head of the body can be fined personally — EUR 500 to 5 000 (Art. 29(4)).
- A significant incident is reported to СЕРИКС: an early warning within 24 hours and a notification within 72 hours of establishing it (Art. 23(5)).
- Minimum measures are set by an ordinance under Art. 3 of the Act. As of 30 September 2026 the 2019 ordinance is in force; the statutory deadline for the new one falls around mid-October 2026. We check what applies at the time of the engagement.
General information, not a legal opinion. Separate legal support can be agreed for a specific legal question. Regulatory reference
The systems that are usually in scope
For example: records-management and electronic document flow; local taxes and fees; portal and electronic administrative services; accounting and payroll; the organisation’s email and domain; video surveillance and building access; systems maintained by an external IT contractor.
Many municipalities have no IT department of their own and rely on an external contractor. The responsibility stays with management — so we also set out what the contractor must do and how it is verified.
The whole path — and who delivers each part
| Step | What you receive | Who delivers |
|---|---|---|
| Assessment against the Cybersecurity Act and its ordinance | A “requirement — status — evidence — gap — action” matrix and a prioritised plan | Dyasol, with your responsible staff |
| Building security governance | Roles and owners, policies, asset and risk registers, an annual plan, approved by management | Dyasol drafts; management approves |
| Implementing safeguards | Completed changes and records of their verification | Your IT team or contractor following our instructions — or Dyasol under a separate quotation; verification is ours |
| Continuity and recovery | Plans, a verified data restore and an exercise with a written record | Dyasol leads; your IT team performs the restore |
| Incident readiness and reporting | Contacts and escalation, significant-incident criteria, templates for СЕРИКС and a rehearsed scenario | Dyasol |
| Management and staff training | A programme, delivered sessions and documented results — including management training every two years | Dyasol |
| Keeping compliance current | Periodic reviews, current evidence, deadline reminders and task tracking | Dyasol through ongoing support |
You do not need to commission everything at once. Detail on each step: Bulgarian Cybersecurity Act programme.
Example: part of the matrix for one municipality
Fictional data — an illustration of the format, not a client case.
| Requirement | Status | Evidence | Gap | Action |
|---|---|---|---|---|
| Management approves the measures (Art. 21(1)) | Policy exists, no decision | Draft policy from 2025 | No mayor’s act | Approval order; annual review |
| Management training (Art. 21(2)) | Not held | — | No record | Session by quarter end; attendance list and test |
| Backups of the records-management system | Done by the contractor | Support contract | Restore never tested | Restore test with a written record |
| Reporting a significant incident (Art. 23(5)) | No procedure | — | No contacts or criteria | Procedure, СЕРИКС templates, exercise |
| External IT contractor access | Shared admin account | — | No named access or review | Named accounts, multi-factor sign-in, six-monthly review |
Related obligations we help with
Cybersecurity is not the only thing the law asks of a public administration. These areas connect with it and can be commissioned separately or together.
| Area | Basis | What you receive | Who is responsible | Boundary |
|---|---|---|---|---|
| Personal data and the data protection officer | GDPR and the Bulgarian Personal Data Protection Act. Public authorities must as a rule have a data protection officer (GDPR Art. 37(1)(a)); courts acting in their judicial capacity are excepted. | An external data protection officer or support for your internal one; a review of processing, access, retention periods and processor contracts; impact assessments where risk is high — for example video surveillance or biometrics; one process for personal-data breaches and cyber incidents; training. | The team’s legal specialist and the security lead | An external data protection officer is independent and does not also hold roles that decide the purposes and means of processing. An impact assessment is required where risk is high, not for every system. We take on the role for many municipalities at once — each with a designated responsible person. |
| E-government | The Bulgarian E-Government Act and its ordinances — electronic administrative services, electronic documents and information systems. | Assessment and acceptance of electronic services and information systems: a review of services, identification, signing and document flow; architecture, integrations and interoperability; technical requirements for new systems; an acceptance plan and checks for delivered software. | Development, architecture and DevOps specialists, led by the security lead | We do not replace the supervisory bodies. Legal questions are settled with the legal specialist. |
| Internal control and IT risk | The Public Sector Financial Management and Control Act requires risk management and effective internal control. | IT and cyber risks in the organisation’s risk register; segregation of duties; control of privileged access, changes and suppliers; measures against payment fraud through changed bank details; evidence for internal auditors. | The security lead | We do not perform full financial control or statutory internal audit — our role is the specialist IT-risk work. |
| Artificial intelligence | The EU AI Act also applies to public bodies that use or provide AI systems. | An inventory of the tools and systems in use; roles, risk and applicable obligations; rules for data, approval and human oversight; AI literacy; supplier assessment; preparation for a fundamental rights impact assessment where use is high-risk. | The security lead, the legal specialist and the human-factors specialist | Obligations for high-risk systems apply from 2 December 2027 (Annex III) and from 2 August 2028 (regulated products, Annex I). |
| Whistleblowing channels | The Bulgarian Whistleblower Protection Act. | Internal rules, training for the responsible staff, a secure technical environment, restricted access and confidentiality checks. | The team’s legal specialist and the security lead | Public bodies may not outsource the receipt, registration or examination of reports. We help you build and run the internal process. |
| Open data and access to information | The Access to Public Information Act and the re-use rules, including high-value datasets. | A data inventory and classification, preparation for publication, anonymisation, a re-identification risk review, API security. | Data and security specialists, with the legal specialist on legal questions | Decisions on access and restrictions are the organisation’s and are prepared with the legal specialist. |
More on artificial intelligence: AI use and governance review. The people behind the roles are introduced on the team page.
Procurement
We help prepare the technical specification: activities and stages, deliverables, acceptance, on-site visits, what is expected from your IT team or contractor and how sensitive information is handled. First steps are usually below the threshold for award without a procedure under Art. 20(4) of the Public Procurement Act. Details about Dyasol as a contractor are in the supplier information.
Price
The first-step assessment uses the scope of the readiness and evidence pack — from €7 900 for one organisation of up to 100 employees. A larger administration and building what is missing are quoted in writing after the free conversation. Ongoing support starts at €1 400 per month.
Annual programme for a municipality — €24 700
- An assessment under the Cybersecurity Act and the ordinance, in the scope of the readiness and evidence pack (€7 900).
- Twelve months of ongoing support (€1 400 per month): annual plan, registers, preparation of management decisions, readiness to report to СЕРИКС (the national CSIRT) and training.
- A named lead and a named deputy for contact.
The included monthly capacity is 8 expert hours. Priorities, training and timelines are planned within that capacity; additional hours and technical implementation are agreed separately.
One contract for the whole year, accepted in stages. The programme is not split into smaller orders.
Boundaries
- We are not a certification body and do not replace supervision.
- Technical containment of an incident and round-the-clock response are not part of the standard support — they are agreed separately.
- For large critical-infrastructure operators we take on a defined, agreed part of the programme.
- Classified information and system accreditation are not a standard service — we take them on only after checking the required clearances and available specialists.