NIS2 Country Guide

NIS2 Lithuania: Kibernetinio saugumo įstatymas 2026

Lithuania transposed NIS2 through the Kibernetinio saugumo įstatymas (Law on Cyber Security), in force since 18 October 2024 and amended twice in 2026 - the consolidated text in force today dates from 4 July 2026. This page sets out who counts as a kibernetinio saugumo subjektai (cybersecurity entity), what the NKSC can fine you and on what scale, and the clocks that start the day you are registered in KSIS.

Lithuania In force: 18 October 2024 Consolidated text: 4 July 2026 Regulator: NKSC Last updated: 13 August 2026

Introduction: NIS2 Directive & the Lithuanian context

Lithuania already had a Law on Cyber Security before NIS2. What changed in 2024 was not the existence of the law but its reach: the Kibernetinio saugumo įstatymas was restated in full by amending act No. XIV-2902, adopted by the Seimas on 11 July 2024 and in force from 18 October 2024.

Two things about the Lithuanian regime catch organisations out, and both are on this page. First, your obligations do not begin when the law comes into force - they begin when you are registered, which means every deadline on this page is personal to your entity. Second, the headline fines everyone quotes are ceilings on ceilings: the Act sets a maximum, and then caps what share of that maximum a given breach can attract.

Currency: the Act has been amended twice since transposition - by law No. XV-894 (in force 30 June 2026) and No. XV-1076 (in force 4 July 2026). Published English-language summaries of Lithuanian NIS2 are still describing the October 2024 text.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

NIS2 implementation in Lithuania

Lithuania implemented NIS2 by restating the Kibernetinio saugumo įstatymas (Law on Cyber Security, No. XII-1428) through amending act No. XIV-2902, adopted by the Seimas on 11 July 2024, published in the Register of Legal Acts on 24 July 2024 and in force from 18 October 2024.

The detail sits in Government Resolution No. 818, substantially rewritten by Resolution No. 945 of 6 November 2024 (published 11 November, in force 12 November). That resolution approved six instruments at once, and two of them govern most of what you actually have to do: the Kibernetinio saugumo reikalavimų aprašas (Description of Cybersecurity Requirements), which sets the technical and organisational controls and the implementation deadlines, and the national cyber incident management plan, which sets the reporting routes and the deadlines for incidents that fall below the "significant" threshold.

The Act has moved twice in 2026, and no published summary reflects it. Law No. XV-894 (adopted 12 May 2026) applied from 30 June 2026, and law No. XV-1076 (adopted 25 June 2026, published 3 July) applied from 4 July 2026. XV-1076 rewrote articles 2, 11, 12, 13, 19, 23, 28, 30, 31 and 38 and annexes 2 and 3 - that is scope, the register, enforcement and the fines. Everything on this page is taken from the consolidated text in force from 4 July 2026.

Supervision is centralised. The Nacionalinis kibernetinio saugumo centras prie Krašto apsaugos ministerijos - the National Cyber Security Centre under the Ministry of National Defence, known as the NKSC - is the competent authority, the CSIRT and the single point of contact, and it is the body that imposes fines.

Status

Fully transposed and in force since 18 October 2024, ahead of most member states. The operative text today is the consolidated version of 4 July 2026.

Legal structure

Two layers. The Kibernetinio saugumo įstatymas sets scope, duties, supervisory powers and the fine ceilings. Resolution No. 818, as amended, carries the actual security requirements, the identification methodology and the implementation deadlines.

Supervisory approach

The NKSC identifies entities, enters them in the register, supervises, inspects, orders audits and imposes the fines itself - there is no separate sanctions commission and no court confirmation step.

Who is in scope

Lithuania follows the NIS2 split into essential (esminiai subjektai) and important (svarbūs subjektai) entities, known collectively as kibernetinio saugumo subjektai. The identification criteria are in Article 11, and they were amended as recently as 4 July 2026.

We print no entity count. Figures between one thousand and ten thousand circulate for Lithuania and none of them is traceable to the NKSC. We would rather state nothing than a number that gets quoted back at us.

Who is in scope?

  • Entities in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
  • Size is not written as a flat headcount or turnover figure. Article 11 refers across to the Law on the Development of Small and Medium-sized Business, and an essential entity is one exceeding the medium-enterprise headcount and/or both financial thresholds. Read the conjunction: it is "both financial limits", not "either".
  • Named national categories that have nothing to do with size: entities recognised as critical under the Crisis Management and Civil Protection Act; central, regional and municipal public administration bodies; managers of critical or important state information resources; and enterprises important to national security, or whose systems appear on the national-security assets list.
  • In digital infrastructure, qualified trust service providers, top-level domain registries and DNS providers are essential regardless of size (root name server operators excepted); public electronic communications providers qualify at medium-enterprise size.

Core obligations

  • Implement comprehensive cybersecurity risk-management measures aligned with NIS2 Article 21.
  • Maintain governance documentation, including board-approved cybersecurity plans and policies.
  • Ensure incident detection, response and reporting processes meet the 24h / 72h / 30-day notification ladder.
  • Manage supply-chain cybersecurity risks and document security requirements for critical suppliers.
  • Provide training and oversight at management level; directors are explicitly accountable for cybersecurity.

A revenue test most guides miss

For an Annex 2 (important-entity) activity, Article 11(4)(1) requires that the revenue from that activity exceeds 50% of the entity's total annual revenue. An organisation with a small qualifying sideline can therefore sit outside the regime on that limb.

This test was introduced by the amendment in force on 4 July 2026 and appears in no published English-language summary we could find.

The staged compliance window is real, and it is set out below - see your 12 and 24-month clocks. It runs from your registration date, not from the date the law came into force.

Registration in KSIS, and when your duties actually start

This is the provision that reorders everything else. Article 11(2): a cybersecurity entity acquires the obligations of a cybersecurity entity only from the moment it is registered in the Kibernetinio saugumo informacinė sistema - the Cybersecurity Information System, known as KSIS. Until then, the duties in Articles 14, 15 and 18 do not bite.

Who files

Both sides act. The NKSC identifies entities and enters them in the register - the statutory deadline for the first sweep was 17 April 2025. But Article 13(4) also puts a duty on the entity: an organisation meeting the Article 11 criteria submits its own data to the operator of KSIS, in the form set by the Minister of National Defence.

What the register holds

Name, legal-entity code, legal form and economic activity; head-office address; contact details; the services that meet the criteria; the states where you provide them; the networks and information systems significant to them; the Annex 1 or 2 sector and subsector - and the IP addresses you use.

If you are not established in the EU

Article 12(3) requires a designated representative, whose name, legal form, activity and address also go into the register. Special-category providers - cloud, data centre, CDN, managed services, managed security services, online marketplaces, search engines, social platforms and trust services - must additionally list the addresses of their other EU establishments.

Practical consequence: if you believe you are in scope and have not been contacted, the answer is not to wait. Registration is what starts your 12 and 24-month implementation clocks, and it is also what makes the duties enforceable against you.

Your 12 and 24-month clocks

Lithuania's implementation deadlines are relative, not calendar. They run from the day your entity was registered in KSIS, which is why no single national date applies to everyone.

What By when Source
The cybersecurity requirements generally 12 months from registration in KSIS Description of Cybersecurity Requirements, point 71
The technical requirements set out in points 26, 31, 47, 57, 60, 64 and 69 of the Description 24 months from registration in KSIS Description, point 72
Incident event and incident management arrangements 12 months from registration, extendable once by up to 12 further months by the NKSC on a reasoned request Resolution No. 818, point 3

The Act itself sets only a floor: Article 14(2) requires the Government to allow a period of not less than 12 months from registration. The 12 and 24-month figures are the Government's, in the Description of Cybersecurity Requirements - which is why they cannot be found by reading the Law on Cyber Security alone.

The extension is worth knowing about. Most summaries present 12 and 24 months as immovable. Resolution No. 818 lets the NKSC extend once, by up to a further twelve months, on a reasoned request - a route that exists for organisations that can show why they need it.

The cybersecurity manager and the security officer

Article 15 requires two appointments, not one, and it sets statutory qualification requirements for both. This is the most commonly missed obligation in the Lithuanian regime, and breaching it sits in the middle severity band - up to half the maximum fine.

Kibernetinio saugumo vadovas

The cybersecurity manager, appointed by the entity's head, directly accountable to that head, and responsible for the entity's compliance with Articles 14 and 18 - the risk-management measures and the incident reporting.

Saugos įgaliotinis

The security officer, responsible for the compliance of a specific network and information system. Where a system has a separate operator, the manager of the system may require that operator to appoint one.

One person, several roles, or bought in

The cybersecurity manager may also perform the security officer's functions, and either role may cover several entities or several systems. Article 15(4) expressly permits buying these functions in from a supplier, provided compliance with Articles 14 and 18 is still ensured.

Article 15(5) sets who may hold the role. The person must meet the impeccable reputation standard that applies to civil servants; must not have had an administrative penalty for breaches in networks and information systems or in data protection and privacy imposed less than one year ago; and must satisfy one of four alternatives -

  • at least 2 years' experience in IT, cybersecurity or networks and information systems; or
  • a higher-education diploma confirming qualification in those fields; or
  • an internationally recognised qualification certificate; or
  • completion of training and a pass in the cybersecurity manager examination set by the head of the NKSC.
A dated point that is about to matter. Security officers already in post when the law took effect were carried over, and the qualification requirement above was disapplied to them for the first two years from entry into force. That grandfathering expires on 18 October 2026. Where the entity is a natural person, Article 15 does not apply at all.

Authorities, CSIRT and who supervises you

Lithuania is genuinely centralised - one regulator does identification, supervision, incident response and fines. But the Act names other bodies with real roles, and the vague "sectoral regulators" line that circulates for Lithuania does not survive a reading of it.

A note on names. The Act designates the regulator only by its full legal name, Nacionalinis kibernetinio saugumo centras, which appears 64 times; the acronym NKSC appears nowhere in it, though the institution uses that acronym itself. The English form "NCSC" is best avoided - it is the acronym of the United Kingdom's agency.
Role Authority Notes
Competent authority, CSIRT and Single Point of Contact Nacionalinis kibernetinio saugumo centras prie Krašto apsaugos ministerijos (NKSC) An institution under the Ministry of National Defence (Article 7(1)). Identifies entities, operates the register, receives incident reports, inspects, orders audits, applies the enforcement measures and imposes the fines.
Policy formation Ministry of National Defence (Krašto apsaugos ministerija) Forms cybersecurity policy and organises, controls and coordinates its implementation (Article 4(2)). The Ministry of Foreign Affairs participates to the extent diplomatic responses to cyber threats are concerned.
Policy implementation alongside the NKSC Lietuvos policija and the Valstybinė duomenų apsaugos inspekcija Named in Article 4(3) as implementing bodies, with their own powers under Articles 9 and 10. The NKSC must inform the data protection inspectorate within 36 hours where GDPR Article 33(3) circumstances are identified.
Trust service providers Ryšių reguliavimo tarnyba (Communications Regulatory Authority) Article 20: cooperates with the NKSC on cybersecurity audits of trust service providers, and must be informed by the NKSC within 24 hours of incident notifications received from them.

Incident reporting: 24h / 72h / one month

Article 18 sets a four-stage chain, and Lithuania adds a duty most transpositions do not: you must report incidents that do not meet the significance threshold as well.

Stage Deadline What it must contain
Early warning
ankstyvasis perspėjimas
24 hours from becoming aware Whether the incident is suspected to have been caused by unlawful or malicious acts, and whether it could have cross-border impact.
Incident notification 72 hours from becoming aware Updates the early warning, adds an initial assessment of severity and impact, and indicators of compromise where there are any.
Interim report On NKSC request, by the deadline it sets Updated status information.
Final report One month - see the note below Full description including severity and impact; the threat or root cause; mitigation measures applied; and any cross-border effect.
Progress report Where the incident is still running when the final report falls due The final report is then due one month from the day the incident was contained.
Read the trigger, not just the duration. Article 18(4)(4) runs the one-month clock from the day you submitted the notification referred to in point 1 of that paragraph - and point 1 is the 24-hour early warning, not the 72-hour notification. As drafted, the final report is due one month from first knowledge. We state it as the Act states it.

An incident is significant where it caused or could cause serious disruption to your services or financial loss, or where it affected or could affect other natural or legal persons by causing substantial material or non-material damage (Article 18(2)). The Description of Cybersecurity Requirements adds a concrete test that is easy to miss: more than one analogous incident within six months, with the same root cause and comparable financial loss, counts.

The duty that has no equivalent in most member states. Article 18(1)(2) requires you to report incidents that do not meet the significance criteria, within the deadlines and in the form set by the national cyber incident management plan. Failing to do so is an infringement in its own right - in the lowest severity band, but an infringement.

NIS2 timeline & key dates (Lithuania)

1 September 2023 — Draft amendments to the Law on Cyber Security published for consultation.
11 July 2024 — Amended Law on Cyber Security adopted by the Seimas (Act transposing NIS2).
18 October 2024 — Law on Cyber Security (as amended) enters into force, formally implementing NIS2.
12 November 2024 — Implementing Resolution enters into force, detailing cybersecurity requirements, reporting and designation rules.
17 April 2025 — Statutory deadline for the NKSC to identify entities in the Annex 1 and 2 sectors and enter them in the Cybersecurity Information System (XIV-2902, transitional article).
30 June 2026 — Amending law No. XV-894 applies.
4 July 2026 — Amending law No. XV-1076 applies, rewriting scope, the register, enforcement and the fines. This is the text in force today.
18 October 2026 — The two-year carry-over for security officers already in post ends; from this date the Article 15(5) qualification requirements apply to all of them.
1 January 2027 — A further consolidated version of Resolution No. 818 is already scheduled; the current version is stated to run only to 31 December 2026.
1 January 2029 — Deadline for the Ministry of National Defence to complete the statutory ex post evaluation of the Act's impact on cybersecurity entities.
Rolling, per entity — 12 months from your registration in KSIS for the requirements generally, 24 months for the seven listed technical requirements.

Sector-specific notes for Lithuania

  • Energy: the scope covers a broad set of energy operators, including electricity, gas, LNG, hydrogen and district heating operators, with strong monitoring and reporting to energy regulators.
  • Digital infrastructure: data centres, cloud providers, electronic communications networks and DNS/TLD operators are treated as highly critical, often essential regardless of size.
  • Healthcare: the number of covered healthcare providers has increased substantially, with expectations around incident drills and alignment with standards such as ISO/IEC 27001.
  • Manufacturing & industry: many manufacturing companies become important entities, particularly where they support critical supply chains or national strategic sectors.
  • Public sector: central, regional and municipal public administration bodies are named directly in Article 11(3) as essential-entity criteria. Note that public bodies are not exempt from fines in Lithuania - they are fined on a separate scale, set out under penalties.
  • Trust services: qualified trust service providers are essential regardless of size, and are the one group with a second regulator in the loop - the Ryšių reguliavimo tarnyba, which the NKSC must inform within 24 hours of any incident notification they file.

Penalties and fines

Article 30 sets four maximums, not two - and then Article 30(3) caps what proportion of that maximum any given breach can attract. Quoting "up to 10 million euro" describes the worst case for one class of breach by one class of entity.

Entity Maximum fine
Essential entity EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial period, whichever is higher
Important entity EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher
Budgetary institution that is an essential entity Up to 1% of its current-year budget and other gross annual income received in the previous year, but not more than EUR 60,000
Budgetary institution that is an important entity Up to 0.5% on the same base, capped at EUR 30,000

Lithuania fines public bodies. It does not exempt them, as Spain, France and Finland do - it applies a different base and a hard low cap.

The severity bands, and why they change the number

Article 30(3) allows only a share of the maximum above, according to how Article 29 classifies the breach:

Severity Share of the maximum Effective cap, essential entity Which duties
Dangerous
pavojingas
up to 100% EUR 10,000,000 Article 14(1) risk-management measures; Article 18(1)(1) - the 24-hour early warning
Medium
vidutinio pavojingumo
up to 50% EUR 5,000,000 Article 14(6) and 14(8); Article 15(1)-(3), the responsible persons; obstructing an inspection; Article 17 duties where breached by a top-level domain registry
Low
nedidelio pavojingumo
up to 10% EUR 1,000,000 Article 14(3) and 14(7); Article 18(1)(2) - the 72-hour notification; Article 19(4); Article 17 duties where breached by a domain name registration service
Missing the 24-hour early warning is ten times more serious than missing the 72-hour notification. The first sits in the dangerous band at up to EUR 10 million; the second sits in the low band at up to EUR 1 million. That is the opposite of how most incident-response plans prioritise, and it is the single most useful thing on this page for anyone writing one.

How a fine is actually imposed

  • The fine is imposed by the head of the NKSC or a person they authorise - no court confirmation, no separate sanctions commission.
  • The default is a written procedure with no hearing. An oral hearing happens on the entity's request or the NKSC's own initiative, with at least 10 working days' notice.
  • The hearing is public by default, closed only to protect state, official, professional or commercial secrets or personal data. It is held in Lithuanian, with a guaranteed right to an interpreter, and the audio recording serves as the minutes.
  • Decision within 20 working days; a copy is sent within 3 working days.
  • No fine is imposed where one has already been imposed for the same breach under Article 58(2)(i) of the GDPR.
  • Appeal lies to the administrative courts. The fine must be paid within 3 months of service, or of the court judgment upholding it.
  • A breach counts as repeated where the same breach is committed within 12 months of an enforcement decision taking effect.
We do not state a statutory minimum fine, because Lithuania has none. Eleven countries on this project set a floor in their transposition; Lithuania sets ceilings and proportionality criteria only.

What the NKSC can do to you

Article 28 gives the NKSC eleven enforcement measures, and a fine can be combined with any of them. Two reach further than most readers expect.

  • Warnings that the entity is in breach.
  • Binding instructions to essential entities on the measures needed to prevent or contain an incident, with deadlines for implementing them and for reporting back.
  • Orders to stop conduct that breaches the Act and not to repeat it.
  • Orders to bring risk-management measures into line with Article 14(1), or to comply with the Article 18 reporting duty, in a specified way and within a specified period.
  • Orders to inform your own customers of a significant cyber threat, its nature, and what they can do about it.
  • Orders to implement the recommendations of a cybersecurity audit within a reasonable period.
  • Appointment of a monitoring officer (stebėsenos pareigūnas) with defined tasks, for a defined period, to supervise an essential entity's compliance with Articles 14 and 18.
  • An order to make aspects of the breach public, in a specified manner.
  • A fine under Articles 30 and 31, combinable with any of the above.
  • Initiation of a temporary suspension of the right to carry on part or all of an essential entity's activity, or to provide services (Article 32). The suspension is ordered by a district court, for no more than 4 months, extendable by up to 2 months at a time.
  • Initiation of the temporary removal of an essential entity's chief executive (Article 33), for no more than 6 months, extendable by up to a further 3. Decisions taken by a suspended chief executive are void.
A carve-out worth noting. The power to remove a chief executive does not reach the heads of public administration bodies appointed by the Seimas, the Government or the President of the Republic. And under Article 28(2), applying any measure neither discharges the underlying duty nor releases managers and staff from civil, administrative or criminal liability.

In setting a measure the NKSC must weigh the circumstances, the severity band, the duration of the breach, any breaches in the previous 2 years, the material and non-material damage caused, the steps taken to prevent or reduce it, adherence to approved codes of conduct or certification schemes, cooperation with the NKSC, and the scale of the breach.

The three-year cybersecurity audit

Article 14(8) requires every cybersecurity entity to carry out a cybersecurity audit at least once every three years, to a methodology the NKSC approves. Omitting it is a medium severity breach - up to half the maximum fine.

Who may audit

Independent information systems security compliance auditors, audit firms or other bodies certified by internationally recognised organisations. The methodology is the NKSC's, not the auditor's.

The regulator can commission one too

Under Article 7(3) the NKSC may engage an independent auditor, audit firm or other body - meeting its own independence, impartiality and reputation requirements - to carry out an audit, and can then order you to implement the recommendations.

And scanning, every six months

Separately from the audit cycle, the Description of Cybersecurity Requirements requires regular vulnerability assessment and a full vulnerability scan of the network and information system at least every six months.

How Lithuania differs from the Directive

Six things in the Lithuanian regime are not obvious from reading NIS2, and each of them changes what a compliance programme has to do.

  • Your duties start on registration, not on the law. Article 11(2). Every deadline is personal to your entity, which is why no single national compliance date exists.
  • The fine ceiling is banded by severity. Article 30(3) caps a low-severity breach at 10% of the headline maximum. The headline number applies to two duties only.
  • Public bodies are fined, on their own scale. Up to 1% or 0.5% of budget, capped at EUR 60,000 and EUR 30,000. Not exempt, and not on the commercial scale either.
  • Sub-threshold incidents are reportable. Article 18(1)(2) reaches incidents that do not meet the significance test, on the timetable in the national incident management plan.
  • Two named roles, with a statutory qualification test. A kibernetinio saugumo vadovas and a saugos įgaliotinis, each subject to Article 15(5) - including, as one route to qualifying, a cybersecurity manager examination set by the head of the NKSC. Most transpositions name one role, or none.
  • The regulator can switch services off for 48 hours. Article 7(2)(6) lets the NKSC order public electronic communications providers, online marketplaces, search engines, cloud providers and hosting providers to restrict provision for up to 48 hours to stop an incident's impact.
What we deliberately do not state. We print no count of entities in the register and no predicted enforcement figures. Lithuania publishes neither in a form we can source to the NKSC, and a number that cannot be traced to the regulator is worse than no number at all.

How to prepare for NIS2 in Lithuania

  1. Check if you are likely in scope: review your sector, size and role against NIS2 Annex I & II and national criteria; use the NCSC self-check tools where available.
  2. Establish your registration status in KSIS, and do it first: it determines whether you have any obligations at all and when your clocks started. If you meet the Article 11 criteria and are not registered, Article 13(4) puts the duty to submit your data on you.
  3. Run a gap assessment: compare your current controls against NIS2 Article 21 and Lithuanian cybersecurity requirements (governance, technical measures, documentation, reporting).
  4. Appoint your kibernetinio saugumo vadovas and saugos įgaliotinis: check the Article 15(5) qualification test for each, and remember the carry-over for incumbent security officers ends on 18 October 2026. The functions can be bought in from a supplier if you cannot staff them.
  5. Plan against your own registration date: 12 months for the requirements generally, 24 for the seven listed technical requirements - and apply early if you need the one-off extension.
  6. Build the reporting chain into your incident plan, weighted correctly: the 24-hour early warning is a dangerous-band duty and the 72-hour notification is a low-band one, so the first alert must never be the step that slips. Include the duty to report sub-threshold incidents, and the interim and final reports.
  7. Review supply-chain risk: map critical suppliers and update contracts with explicit cybersecurity, audit and incident-notification clauses.
  8. Align with recognised frameworks: leverage ISO/IEC 27001, NIST CSF or similar frameworks to structure your ISMS and evidence NIS2 compliance.
  9. Engage the board: ensure that management formally approves the cybersecurity programme and receives regular updates and training on NIS2 obligations.

Official links & resources

FAQ: NIS2 in Lithuania

Has Lithuania fully transposed NIS2?
Yes, and early. The Kibernetinio saugumo įstatymas has been in force since 18 October 2024, with Government Resolution No. 945 of 6 November 2024 supplying the detail. The Act has since been amended twice, most recently with effect from 4 July 2026.
How will we know if we are in scope?
The NKSC identifies entities and enters them in KSIS, and its statutory deadline for the first sweep was 17 April 2025. But do not treat silence as an answer: Article 13(4) requires an entity meeting the Article 11 criteria to submit its own data, and under Article 11(2) your obligations begin only once you are registered.
How long do we have to comply once registered?
12 months from registration in KSIS for the cybersecurity requirements generally, and 24 months for the technical requirements listed in points 26, 31, 47, 57, 60, 64 and 69 of the Description of Cybersecurity Requirements. The NKSC can extend the incident-management deadline once, by up to a further 12 months, on a reasoned request.
Who is the NIS2 competent authority in Lithuania?
The Nacionalinis kibernetinio saugumo centras prie Krašto apsaugos ministerijos - the NKSC, an institution under the Ministry of National Defence. It is the competent authority, the CSIRT and the single point of contact, and it imposes the fines itself.
Is ISO 27001 certification mandatory?
No. What is mandatory is a cybersecurity audit at least once every three years under Article 14(8), carried out to the NKSC's methodology by auditors certified by internationally recognised organisations. ISO/IEC 27001 is a common way to structure the underlying controls, but the Act requires the audit, not the certificate.
What is the maximum fine, really?
It depends on the breach, not just the entity. Article 30(2) sets the maximum at EUR 10,000,000 or 2% of worldwide turnover for essential entities and EUR 7,000,000 or 1.4% for important ones - but Article 30(3) then allows only 100%, 50% or 10% of that maximum depending on whether Article 29 classifies the breach as dangerous, medium or low severity. A late 72-hour notification is a low-severity breach, capped at 10% of the maximum.
Do we have to report incidents that are not significant?
Yes. Article 18(1)(2) requires cybersecurity entities to report incidents affecting their qualifying services even where they do not meet the significance criteria in Article 18(2), within the deadlines and in the form set by the national cyber incident management plan. This duty has no equivalent in most other member states.
Information provided for general guidance and verified against the Kibernetinio saugumo įstatymas as consolidated on 4 July 2026; always consult the official Lithuanian legislation, NKSC publications and legal counsel for definitive NIS2 compliance requirements.