Compliance — NIS2, ZKS, DORA, ISO 27001 — Protectiva
Compliance

Four frameworks, kept apart on purpose.

NIS2, the Bulgarian Cybersecurity Act, DORA and ISO/IEC 27001 share ground, but each has its own scope, its own controls and its own reporting clock. Getting the mapping right is what turns paperwork into evidence.

EU Directive 2022/2555

NIS2 lifts the minimum for everyone in the chain

The directive covers essential and important entities in energy, water, transport, health, digital infrastructure, waste, public administration and manufacturing — and, in practice, the suppliers they depend on. The management body has to approve the risk measures and can be held liable if it does not.

In scope if you are A medium or large organisation in a listed sector · a public administration body · a supplier whose outage would disrupt either
Get a written scoping opinion
What we deliver
Risk management measures (Art. 21)Each of the ten measure areas reviewed, rated and evidenced.
Incident handling & reportingHow incidents are classified, who escalates, and a rehearsal of it.
Supply-chain securityAssessment criteria for suppliers and the clauses to put in contracts.
Continuity & crisis managementBackup, recovery and crisis roles, all of them tested.
Management-body trainingThe briefing the directive assumes leadership has already had.
Bulgarian Cybersecurity Act

ZKS turns the directive into a Bulgarian duty

The Act and the rules beneath it say who must appoint a responsible officer, what the information security policy has to contain, how incidents are graded and how fast the national CERT has to hear about it. Municipalities and administrative bodies are firmly in scope, and inspections ask for documents rather than intentions.

Typical findings we fix No asset register · a policy never formally approved · no officer appointed · logs not kept · backups never tested · no reporting route
Request a ZKS review
What we deliver
Compliance programme & policy setWritten so your management body can approve it as it stands.
Support for the appointed officerWe work beside the person you appoint, or take the role externally.
Reporting workflow to the national CERTTemplates, the contact path, and a drill run against the clock.
Technical specifications for ZOPProcurement documents that hold up when they are challenged.
Staff awareness programmeShort, mandatory and recorded, with attendance you can evidence.
EU Regulation 2022/2554

DORA puts ICT resilience under financial supervision

Banks, insurers, payment and investment firms — along with their critical ICT providers — need a documented ICT risk framework, a register of third-party arrangements, incident classification against regulatory thresholds, and a resilience testing programme.

Also relevant if You supply software or services to a financial entity: their contractual obligations now pass down to you
Review DORA readiness
What we deliver
ICT risk management frameworkGovernance, roles and the reporting line up to the board.
Third-party ICT registerWho provides what, how critical it is, and how you would leave.
Incident classificationThresholds tied to the duties you owe the supervisor.
Resilience testing programmeScope and scenarios, TLPT preparation included.
Contractual gap reviewProvider agreements checked against the clauses now required.
ISO/IEC 27001:2022

One certificate that answers most questionnaires

An ISMS gives you a single management system feeding NIS2, ZKS and customer due diligence at once. We build it to pass certification and to be workable for the people who have to live with it.

Also implemented ISO 9001 quality · ISO/IEC 20000-1 service management · GDPR records of processing
Plan certification
What we deliver
Defining the ISMS boundaryA scope you can defend and a risk method people will actually use.
Selecting from Annex ANinety-three controls triaged down to the ones that apply to you.
Audit before the auditorOur lead auditors find it first, while it is still cheap to fix.
Papers for the management reviewInputs, minutes and actions in the form the standard expects.
Cross-framework mappingOne control satisfying three regimes, so evidence is reused instead of rewritten.
The reporting clock

Detection to final report

Awareness starts the clock, not the completion of your analysis. This is the sequence we rehearse with your people.

T + 0 Detection & containment Triage, isolation of what is affected, and evidence preserved before anything gets rebuilt.
24 h Early warning First notice to the national CERT: what happened, the suspected cause, any cross-border effect.
72 h Incident notification Your assessment, the severity, indicators of compromise and what you have already done.
1 month Final report Root cause, the full impact, the mitigations, and what goes back into the risk register.
Self-assessment

Six things an inspector will ask to see

Tick only what you could put in front of someone today, in writing, with no preparation. Whatever stays unticked is a finding in waiting.

{{ score }} of six you could evidence today
Let us close the gaps