DIAMATIX Participated in PARAi Expert Online Session on NIS2 and Amendments to the Cybersecurity Act
Date: February 26, 2026
Format: Online
Organizer: PARAi
Duration: 90-minute expert discussion
Expert Session with National and International Cybersecurity Leaders
On February 26, 2026, an expert online session dedicated to the recent amendments to the Bulgarian Cybersecurity Act transposing the NIS2 Directive was organized by Kristiyan Mihaylov on behalf of PARAi.
Originally planned as a 40-minute session, the discussion extended to 90 minutes due to strong engagement and targeted questions from business participants.
DIAMATIX participated by invitation through cybersecurity expert Plamen Mandadjiev, who presented the operational perspective on regulatory implementation.
The session also featured:
• Dr. Eyal Pinko and Vladimir Nedkov from SAIFORT
• Petar Kirkov, National Cybersecurity Coordinator of Bulgaria
Petar Kirkov brings over 20 years of experience in cybersecurity strategy, regulation, and technology governance. As National Coordinator, he has led national-level incident coordination and international cooperation efforts, contributing to major EU regulatory frameworks such as NIS2 and the Cyber Resilience Act. His work includes the development of the Bulgarian National CSIRT infrastructure, the establishment of the National SOC, and SOC capabilities for critical infrastructure.
The presence of experts at this level added both regulatory and operational depth to the discussion.
Key Discussion Topics
The session moved beyond regulatory overview into operational and strategic questions:
• How organizations determine whether they fall under the scope of the law
• How to conduct a rapid risk assessment in the absence of formal policies
• Three effective technical measures that can be implemented within 30 days
• Required documentation and evidence for regulatory inspection
• How to plan a cybersecurity budget when one did not previously exist
• Whether cybersecurity budgets should be separated from IT budgets and how governance responsibilities differ
• What should remain internal versus what can be outsourced strategically
The financial governance discussion generated significant interest. It was emphasized that cybersecurity should not be treated as a residual IT expense, but as a standalone governance responsibility linked directly to risk exposure, regulatory accountability, and business resilience.
NIS2 Is Not a Technical Checklist
During the discussion, it was emphasized that the Cybersecurity Act amendments and the transposed NIS2 Directive do not prescribe detailed technical specifications. The only explicitly referenced technical requirement is the use of multi-factor authentication.
All other obligations focus on governance, risk management, and operational processes.
It was clarified that NIS2 is not a certification scheme. There is no formal certificate confirming compliance. In the event of regulatory inspection, authorities assess actual implementation – evidence of monitoring, incident handling, risk documentation, and accountability.
Having documented policies without operational enforcement does not constitute compliance. The regulation requires functioning processes, not dormant documentation.
The DIAMATIX Perspective
At DIAMATIX, we approach NIS2 as a governance and operational maturity framework.
Regulation defines expectations. Operational resilience depends on:
• Centralized visibility and monitoring
• Structured risk assessment
• Clear roles and escalation processes
• Documented and actively enforced policies
In practice, the most significant challenge is not technology adoption, but organizational clarity and consistent execution.
Our participation focused on translating regulatory requirements into practical and implementable operational steps.
Conclusion
The extension of the session to 90 minutes reflects the seriousness of the topic and the demand for structured dialogue between regulators, cybersecurity experts, and business leaders.
Organizations that approach NIS2 strategically will build not only compliance, but operational resilience.
For a structured readiness assessment and advisory session, contact DIAMATIX.
Trusted · Innovative · Vigilant.






