NIS2 Lithuania: Kibernetinio saugumo įstatymas 2026
Lithuania transposed NIS2 through the Kibernetinio saugumo įstatymas (Law on Cyber Security), in force since 18 October 2024 and amended twice in 2026 - the consolidated text in force today dates from 4 July 2026. This page sets out who counts as a kibernetinio saugumo subjektai (cybersecurity entity), what the NKSC can fine you and on what scale, and the clocks that start the day you are registered in KSIS.
Introduction: NIS2 Directive & the Lithuanian context
Lithuania already had a Law on Cyber Security before NIS2. What changed in 2024 was not the existence of the law but its reach: the Kibernetinio saugumo įstatymas was restated in full by amending act No. XIV-2902, adopted by the Seimas on 11 July 2024 and in force from 18 October 2024.
Two things about the Lithuanian regime catch organisations out, and both are on this page. First, your obligations do not begin when the law comes into force - they begin when you are registered, which means every deadline on this page is personal to your entity. Second, the headline fines everyone quotes are ceilings on ceilings: the Act sets a maximum, and then caps what share of that maximum a given breach can attract.
NIS2 implementation in Lithuania
Lithuania implemented NIS2 by restating the Kibernetinio saugumo įstatymas (Law on Cyber Security, No. XII-1428) through amending act No. XIV-2902, adopted by the Seimas on 11 July 2024, published in the Register of Legal Acts on 24 July 2024 and in force from 18 October 2024.
The detail sits in Government Resolution No. 818, substantially rewritten by Resolution No. 945 of 6 November 2024 (published 11 November, in force 12 November). That resolution approved six instruments at once, and two of them govern most of what you actually have to do: the Kibernetinio saugumo reikalavimų aprašas (Description of Cybersecurity Requirements), which sets the technical and organisational controls and the implementation deadlines, and the national cyber incident management plan, which sets the reporting routes and the deadlines for incidents that fall below the "significant" threshold.
Supervision is centralised. The Nacionalinis kibernetinio saugumo centras prie Krašto apsaugos ministerijos - the National Cyber Security Centre under the Ministry of National Defence, known as the NKSC - is the competent authority, the CSIRT and the single point of contact, and it is the body that imposes fines.
Status
Fully transposed and in force since 18 October 2024, ahead of most member states. The operative text today is the consolidated version of 4 July 2026.
Legal structure
Two layers. The Kibernetinio saugumo įstatymas sets scope, duties, supervisory powers and the fine ceilings. Resolution No. 818, as amended, carries the actual security requirements, the identification methodology and the implementation deadlines.
Supervisory approach
The NKSC identifies entities, enters them in the register, supervises, inspects, orders audits and imposes the fines itself - there is no separate sanctions commission and no court confirmation step.
Who is in scope
Lithuania follows the NIS2 split into essential (esminiai subjektai) and important (svarbūs subjektai) entities, known collectively as kibernetinio saugumo subjektai. The identification criteria are in Article 11, and they were amended as recently as 4 July 2026.
Who is in scope?
- Entities in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
- Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
- Size is not written as a flat headcount or turnover figure. Article 11 refers across to the Law on the Development of Small and Medium-sized Business, and an essential entity is one exceeding the medium-enterprise headcount and/or both financial thresholds. Read the conjunction: it is "both financial limits", not "either".
- Named national categories that have nothing to do with size: entities recognised as critical under the Crisis Management and Civil Protection Act; central, regional and municipal public administration bodies; managers of critical or important state information resources; and enterprises important to national security, or whose systems appear on the national-security assets list.
- In digital infrastructure, qualified trust service providers, top-level domain registries and DNS providers are essential regardless of size (root name server operators excepted); public electronic communications providers qualify at medium-enterprise size.
Core obligations
- Implement comprehensive cybersecurity risk-management measures aligned with NIS2 Article 21.
- Maintain governance documentation, including board-approved cybersecurity plans and policies.
- Ensure incident detection, response and reporting processes meet the 24h / 72h / 30-day notification ladder.
- Manage supply-chain cybersecurity risks and document security requirements for critical suppliers.
- Provide training and oversight at management level; directors are explicitly accountable for cybersecurity.
A revenue test most guides miss
For an Annex 2 (important-entity) activity, Article 11(4)(1) requires that the revenue from that activity exceeds 50% of the entity's total annual revenue. An organisation with a small qualifying sideline can therefore sit outside the regime on that limb.
This test was introduced by the amendment in force on 4 July 2026 and appears in no published English-language summary we could find.
Registration in KSIS, and when your duties actually start
This is the provision that reorders everything else. Article 11(2): a cybersecurity entity acquires the obligations of a cybersecurity entity only from the moment it is registered in the Kibernetinio saugumo informacinė sistema - the Cybersecurity Information System, known as KSIS. Until then, the duties in Articles 14, 15 and 18 do not bite.
Who files
Both sides act. The NKSC identifies entities and enters them in the register - the statutory deadline for the first sweep was 17 April 2025. But Article 13(4) also puts a duty on the entity: an organisation meeting the Article 11 criteria submits its own data to the operator of KSIS, in the form set by the Minister of National Defence.
What the register holds
Name, legal-entity code, legal form and economic activity; head-office address; contact details; the services that meet the criteria; the states where you provide them; the networks and information systems significant to them; the Annex 1 or 2 sector and subsector - and the IP addresses you use.
If you are not established in the EU
Article 12(3) requires a designated representative, whose name, legal form, activity and address also go into the register. Special-category providers - cloud, data centre, CDN, managed services, managed security services, online marketplaces, search engines, social platforms and trust services - must additionally list the addresses of their other EU establishments.
Your 12 and 24-month clocks
Lithuania's implementation deadlines are relative, not calendar. They run from the day your entity was registered in KSIS, which is why no single national date applies to everyone.
| What | By when | Source |
|---|---|---|
| The cybersecurity requirements generally | 12 months from registration in KSIS | Description of Cybersecurity Requirements, point 71 |
| The technical requirements set out in points 26, 31, 47, 57, 60, 64 and 69 of the Description | 24 months from registration in KSIS | Description, point 72 |
| Incident event and incident management arrangements | 12 months from registration, extendable once by up to 12 further months by the NKSC on a reasoned request | Resolution No. 818, point 3 |
The Act itself sets only a floor: Article 14(2) requires the Government to allow a period of not less than 12 months from registration. The 12 and 24-month figures are the Government's, in the Description of Cybersecurity Requirements - which is why they cannot be found by reading the Law on Cyber Security alone.
The cybersecurity manager and the security officer
Article 15 requires two appointments, not one, and it sets statutory qualification requirements for both. This is the most commonly missed obligation in the Lithuanian regime, and breaching it sits in the middle severity band - up to half the maximum fine.
Kibernetinio saugumo vadovas
The cybersecurity manager, appointed by the entity's head, directly accountable to that head, and responsible for the entity's compliance with Articles 14 and 18 - the risk-management measures and the incident reporting.
Saugos įgaliotinis
The security officer, responsible for the compliance of a specific network and information system. Where a system has a separate operator, the manager of the system may require that operator to appoint one.
One person, several roles, or bought in
The cybersecurity manager may also perform the security officer's functions, and either role may cover several entities or several systems. Article 15(4) expressly permits buying these functions in from a supplier, provided compliance with Articles 14 and 18 is still ensured.
Article 15(5) sets who may hold the role. The person must meet the impeccable reputation standard that applies to civil servants; must not have had an administrative penalty for breaches in networks and information systems or in data protection and privacy imposed less than one year ago; and must satisfy one of four alternatives -
- at least 2 years' experience in IT, cybersecurity or networks and information systems; or
- a higher-education diploma confirming qualification in those fields; or
- an internationally recognised qualification certificate; or
- completion of training and a pass in the cybersecurity manager examination set by the head of the NKSC.
Incident reporting: 24h / 72h / one month
Article 18 sets a four-stage chain, and Lithuania adds a duty most transpositions do not: you must report incidents that do not meet the significance threshold as well.
| Stage | Deadline | What it must contain |
|---|---|---|
| Early warning ankstyvasis perspėjimas |
24 hours from becoming aware | Whether the incident is suspected to have been caused by unlawful or malicious acts, and whether it could have cross-border impact. |
| Incident notification | 72 hours from becoming aware | Updates the early warning, adds an initial assessment of severity and impact, and indicators of compromise where there are any. |
| Interim report | On NKSC request, by the deadline it sets | Updated status information. |
| Final report | One month - see the note below | Full description including severity and impact; the threat or root cause; mitigation measures applied; and any cross-border effect. |
| Progress report | Where the incident is still running when the final report falls due | The final report is then due one month from the day the incident was contained. |
An incident is significant where it caused or could cause serious disruption to your services or financial loss, or where it affected or could affect other natural or legal persons by causing substantial material or non-material damage (Article 18(2)). The Description of Cybersecurity Requirements adds a concrete test that is easy to miss: more than one analogous incident within six months, with the same root cause and comparable financial loss, counts.
NIS2 timeline & key dates (Lithuania)
Sector-specific notes for Lithuania
- Energy: the scope covers a broad set of energy operators, including electricity, gas, LNG, hydrogen and district heating operators, with strong monitoring and reporting to energy regulators.
- Digital infrastructure: data centres, cloud providers, electronic communications networks and DNS/TLD operators are treated as highly critical, often essential regardless of size.
- Healthcare: the number of covered healthcare providers has increased substantially, with expectations around incident drills and alignment with standards such as ISO/IEC 27001.
- Manufacturing & industry: many manufacturing companies become important entities, particularly where they support critical supply chains or national strategic sectors.
- Public sector: central, regional and municipal public administration bodies are named directly in Article 11(3) as essential-entity criteria. Note that public bodies are not exempt from fines in Lithuania - they are fined on a separate scale, set out under penalties.
- Trust services: qualified trust service providers are essential regardless of size, and are the one group with a second regulator in the loop - the Ryšių reguliavimo tarnyba, which the NKSC must inform within 24 hours of any incident notification they file.
Penalties and fines
Article 30 sets four maximums, not two - and then Article 30(3) caps what proportion of that maximum any given breach can attract. Quoting "up to 10 million euro" describes the worst case for one class of breach by one class of entity.
| Entity | Maximum fine |
|---|---|
| Essential entity | EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial period, whichever is higher |
| Important entity | EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
| Budgetary institution that is an essential entity | Up to 1% of its current-year budget and other gross annual income received in the previous year, but not more than EUR 60,000 |
| Budgetary institution that is an important entity | Up to 0.5% on the same base, capped at EUR 30,000 |
Lithuania fines public bodies. It does not exempt them, as Spain, France and Finland do - it applies a different base and a hard low cap.
The severity bands, and why they change the number
Article 30(3) allows only a share of the maximum above, according to how Article 29 classifies the breach:
| Severity | Share of the maximum | Effective cap, essential entity | Which duties |
|---|---|---|---|
| Dangerous pavojingas |
up to 100% | EUR 10,000,000 | Article 14(1) risk-management measures; Article 18(1)(1) - the 24-hour early warning |
| Medium vidutinio pavojingumo |
up to 50% | EUR 5,000,000 | Article 14(6) and 14(8); Article 15(1)-(3), the responsible persons; obstructing an inspection; Article 17 duties where breached by a top-level domain registry |
| Low nedidelio pavojingumo |
up to 10% | EUR 1,000,000 | Article 14(3) and 14(7); Article 18(1)(2) - the 72-hour notification; Article 19(4); Article 17 duties where breached by a domain name registration service |
How a fine is actually imposed
- The fine is imposed by the head of the NKSC or a person they authorise - no court confirmation, no separate sanctions commission.
- The default is a written procedure with no hearing. An oral hearing happens on the entity's request or the NKSC's own initiative, with at least 10 working days' notice.
- The hearing is public by default, closed only to protect state, official, professional or commercial secrets or personal data. It is held in Lithuanian, with a guaranteed right to an interpreter, and the audio recording serves as the minutes.
- Decision within 20 working days; a copy is sent within 3 working days.
- No fine is imposed where one has already been imposed for the same breach under Article 58(2)(i) of the GDPR.
- Appeal lies to the administrative courts. The fine must be paid within 3 months of service, or of the court judgment upholding it.
- A breach counts as repeated where the same breach is committed within 12 months of an enforcement decision taking effect.
What the NKSC can do to you
Article 28 gives the NKSC eleven enforcement measures, and a fine can be combined with any of them. Two reach further than most readers expect.
- Warnings that the entity is in breach.
- Binding instructions to essential entities on the measures needed to prevent or contain an incident, with deadlines for implementing them and for reporting back.
- Orders to stop conduct that breaches the Act and not to repeat it.
- Orders to bring risk-management measures into line with Article 14(1), or to comply with the Article 18 reporting duty, in a specified way and within a specified period.
- Orders to inform your own customers of a significant cyber threat, its nature, and what they can do about it.
- Orders to implement the recommendations of a cybersecurity audit within a reasonable period.
- Appointment of a monitoring officer (stebėsenos pareigūnas) with defined tasks, for a defined period, to supervise an essential entity's compliance with Articles 14 and 18.
- An order to make aspects of the breach public, in a specified manner.
- A fine under Articles 30 and 31, combinable with any of the above.
- Initiation of a temporary suspension of the right to carry on part or all of an essential entity's activity, or to provide services (Article 32). The suspension is ordered by a district court, for no more than 4 months, extendable by up to 2 months at a time.
- Initiation of the temporary removal of an essential entity's chief executive (Article 33), for no more than 6 months, extendable by up to a further 3. Decisions taken by a suspended chief executive are void.
In setting a measure the NKSC must weigh the circumstances, the severity band, the duration of the breach, any breaches in the previous 2 years, the material and non-material damage caused, the steps taken to prevent or reduce it, adherence to approved codes of conduct or certification schemes, cooperation with the NKSC, and the scale of the breach.
The three-year cybersecurity audit
Article 14(8) requires every cybersecurity entity to carry out a cybersecurity audit at least once every three years, to a methodology the NKSC approves. Omitting it is a medium severity breach - up to half the maximum fine.
Who may audit
Independent information systems security compliance auditors, audit firms or other bodies certified by internationally recognised organisations. The methodology is the NKSC's, not the auditor's.
The regulator can commission one too
Under Article 7(3) the NKSC may engage an independent auditor, audit firm or other body - meeting its own independence, impartiality and reputation requirements - to carry out an audit, and can then order you to implement the recommendations.
And scanning, every six months
Separately from the audit cycle, the Description of Cybersecurity Requirements requires regular vulnerability assessment and a full vulnerability scan of the network and information system at least every six months.
How Lithuania differs from the Directive
Six things in the Lithuanian regime are not obvious from reading NIS2, and each of them changes what a compliance programme has to do.
- Your duties start on registration, not on the law. Article 11(2). Every deadline is personal to your entity, which is why no single national compliance date exists.
- The fine ceiling is banded by severity. Article 30(3) caps a low-severity breach at 10% of the headline maximum. The headline number applies to two duties only.
- Public bodies are fined, on their own scale. Up to 1% or 0.5% of budget, capped at EUR 60,000 and EUR 30,000. Not exempt, and not on the commercial scale either.
- Sub-threshold incidents are reportable. Article 18(1)(2) reaches incidents that do not meet the significance test, on the timetable in the national incident management plan.
- Two named roles, with a statutory qualification test. A kibernetinio saugumo vadovas and a saugos įgaliotinis, each subject to Article 15(5) - including, as one route to qualifying, a cybersecurity manager examination set by the head of the NKSC. Most transpositions name one role, or none.
- The regulator can switch services off for 48 hours. Article 7(2)(6) lets the NKSC order public electronic communications providers, online marketplaces, search engines, cloud providers and hosting providers to restrict provision for up to 48 hours to stop an incident's impact.
How to prepare for NIS2 in Lithuania
- Check if you are likely in scope: review your sector, size and role against NIS2 Annex I & II and national criteria; use the NCSC self-check tools where available.
- Establish your registration status in KSIS, and do it first: it determines whether you have any obligations at all and when your clocks started. If you meet the Article 11 criteria and are not registered, Article 13(4) puts the duty to submit your data on you.
- Run a gap assessment: compare your current controls against NIS2 Article 21 and Lithuanian cybersecurity requirements (governance, technical measures, documentation, reporting).
- Appoint your kibernetinio saugumo vadovas and saugos įgaliotinis: check the Article 15(5) qualification test for each, and remember the carry-over for incumbent security officers ends on 18 October 2026. The functions can be bought in from a supplier if you cannot staff them.
- Plan against your own registration date: 12 months for the requirements generally, 24 for the seven listed technical requirements - and apply early if you need the one-off extension.
- Build the reporting chain into your incident plan, weighted correctly: the 24-hour early warning is a dangerous-band duty and the 72-hour notification is a low-band one, so the first alert must never be the step that slips. Include the duty to report sub-threshold incidents, and the interim and final reports.
- Review supply-chain risk: map critical suppliers and update contracts with explicit cybersecurity, audit and incident-notification clauses.
- Align with recognised frameworks: leverage ISO/IEC 27001, NIST CSF or similar frameworks to structure your ISMS and evidence NIS2 compliance.
- Engage the board: ensure that management formally approves the cybersecurity programme and receives regular updates and training on NIS2 obligations.
