NIS2, the Bulgarian Cybersecurity Act, DORA and ISO/IEC 27001 share ground, but each has its own scope, its own controls and its own reporting clock. Getting the mapping right is what turns paperwork into evidence.
The directive covers essential and important entities in energy, water, transport, health, digital infrastructure, waste, public administration and manufacturing — and, in practice, the suppliers they depend on. The management body has to approve the risk measures and can be held liable if it does not.
The Act and the rules beneath it say who must appoint a responsible officer, what the information security policy has to contain, how incidents are graded and how fast the national CERT has to hear about it. Municipalities and administrative bodies are firmly in scope, and inspections ask for documents rather than intentions.
Banks, insurers, payment and investment firms — along with their critical ICT providers — need a documented ICT risk framework, a register of third-party arrangements, incident classification against regulatory thresholds, and a resilience testing programme.
An ISMS gives you a single management system feeding NIS2, ZKS and customer due diligence at once. We build it to pass certification and to be workable for the people who have to live with it.
Awareness starts the clock, not the completion of your analysis. This is the sequence we rehearse with your people.
Tick only what you could put in front of someone today, in writing, with no preparation. Whatever stays unticked is a finding in waiting.