NIS2 Latvia: Kiberdrošības likums 2026
Latvia transposed NIS2 through the National Cybersecurity Law (Nacionālās kiberdrošības likums), in force since 1 September 2024 and amended with effect from 18 June 2026. This page sets out who is in scope, the registration and self-assessment duties, the cybersecurity manager Latvia invented, the 24-hour and 72-hour reporting chain, and what the fines actually are — including the EUR 500 million turnover gate that decides whether the percentage applies to you at all.
Introduction: NIS2 Directive & the Latvian context
Latvia replaced its old Law on the Security of Information Technologies with the National Cybersecurity Law (Nacionālās kiberdrošības likums), which has applied since 1 September 2024. Transposition is complete, the implementing regulation is in force, and the first compliance deadlines have already passed.
Two things make Latvia different from most member states, and both are missed by the English-language summaries. Supervision is split between two authorities rather than concentrated in one. And every entity in scope must appoint a named cybersecurity manager (kiberdrošības pārvaldnieks) and notify the regulators who that person is — an obligation with no direct equivalent in the Directive.
NIS2 implementation in Latvia
Latvia transposed NIS2 through the National Cybersecurity Law (Nacionālās kiberdrošības likums), adopted by the Saeima on 20 June 2024, published in Latvijas Vēstnesis 128A on 4 July 2024 and in force since 1 September 2024. It repealed the Law on the Security of Information Technologies outright.
The detail sits in Cabinet Regulation No. 397, Minimālās kiberdrošības prasības (minimum cybersecurity requirements), in force since 2 July 2025. That regulation — not the Act — carries incident classification, the reporting forms, availability and recovery requirements, encryption, cyber-hygiene, staff competence and the requirements a cybersecurity manager has to meet. Reading the Act alone will not tell you what to implement.
The Act has been amended once since transposition. A law of 4 June 2026 took effect on 18 June 2026, touching the scope provision, the self-assessment report and the audit rules. One part of that amendment is deferred: from 1 October 2026, the scope provision extends to commercial companies, foundations and associations significant to national security. If you assessed your scope before mid-2026, the answer can have changed.
Status
Fully transposed and operating. The Act has applied since 1 September 2024, Regulation 397 since 2 July 2025, and the first self-assessment reports were due on 1 October 2025.
Legal structure
The Act sets the duties, the supervisory powers and the fine ceilings. Cabinet regulations supply the technical requirements, the reporting forms, the criteria for calculating a fine and the requirements for cybersecurity managers and auditors.
Supervisory approach
Split in two. The National Cybersecurity Centre supervises essential and important service providers; the Constitution Protection Bureau supervises ICT critical infrastructure. Incident reports go to a third body again — see the authorities section.
Who is in scope in Latvia
Latvia uses two statutory categories that map onto the Directive but carry Latvian names: būtisko pakalpojumu sniedzējs (essential service provider) and svarīgo pakalpojumu sniedzējs (important service provider). A third group sits alongside them and is easy to miss: owners and lawful holders of ICT critical infrastructure, who answer to a different supervisor entirely.
Who is in scope?
- Entities operating in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
- Entities operating in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
- Medium-sized and larger organisations meeting NIS2 staff or turnover thresholds.
- Entities covered regardless of size, such as DNS and TLD service providers, trust services, and major cloud or data-centre operators.
Core obligations
- Implement risk-management measures aligned with NIS2, including governance, policies and technical controls.
- Maintain inventories of critical systems, networks and information assets.
- Detect, manage and report significant incidents within defined timeframes (early warning, incident notification, final report).
- Manage supply-chain cybersecurity risk and include security and notification clauses in key contracts.
- Ensure management bodies approve cybersecurity risk-management measures and exercise ongoing oversight.
Scope moves on 1 October 2026
The 4 June 2026 amendment extends the scope provision to commercial companies, foundations and associations significant to national security, with effect from 1 October 2026. An organisation that concluded it was out of scope in 2025 may be in scope this autumn.
Registration and the one-month clock
Latvia does not maintain a public register you can look yourself up in, and no authority will tell you that you are in scope. Article 22 puts the assessment on you and gives you a deadline measured from your own circumstances, not from a national date.
The duty
Carry out a self-assessment against the essential and important service provider definitions. If you meet either, notify the National Cybersecurity Centre within one month. The notification has to carry your name and registration number, legal form, legal address and contact details, including an official electronic address.
The 2025 cohort deadline
Organisations that already qualified when the Act took effect had until 1 April 2025 to notify, and the list of identified providers was approved by 17 April 2025. Domain name registration service providers had the same 1 April 2025 date under Article 23.
If you qualified later
The one-month clock in Article 22(1) applies instead. This is the point most guidance misses: the April 2025 dates were transitional provisions for the first cohort, not the end of the duty.
The cybersecurity manager
This is Latvia's most distinctive obligation and it has no direct Directive equivalent. The Act makes the head of the entity responsible for cybersecurity governance personally, and then requires them to name a specific individual to run it.
| Step | Deadline | Detail |
|---|---|---|
| Appoint the manager | Within 3 months | Measured from your Article 22(1) notification, or from the date the Centre decided you are in scope. The requirements the person must meet are set by Cabinet Regulation 397. |
| Notify both regulators | Within 5 working days | Tell the National Cybersecurity Centre and the Constitution Protection Bureau the manager's name, personal identity code, position, email address and telephone number. |
| ICT critical infrastructure only | Before appointment | The candidate must be agreed with the Constitution Protection Bureau, which checks them against the requirements. The candidate is put forward within three months. |
| First-time notification | 1 October 2025 | Transitional deadline for entities already in scope when the regime started. |
The self-assessment report
Article 43 requires a pašvērtējuma ziņojums — a compliance self-assessment report — filed with whichever authority supervises you. It is a recurring return, not a one-off.
- It goes to the National Cybersecurity Centre, or to the Constitution Protection Bureau if you hold ICT critical infrastructure.
- The form, the information required, the deadline and how often you file are all set by Cabinet regulation rather than by the Act.
- It reports your level of compliance with the minimum cybersecurity requirements, including the technical and organisational measures you have actually implemented.
- The first report was due 1 October 2025.
Incident reporting: 24 hours, 72 hours, one month
Article 34 sets a four-stage chain, plus two reports that only appear in particular circumstances. Reports go to the incident response body competent for you — CERT.LV for private organisations, the military service for defence bodies.
NIS2 timeline & key dates (Latvia)
Sector-specific notes for Latvia
- Energy: electricity and gas infrastructure operators are treated as essential entities, with strict continuity and reporting requirements.
- Transport: key road, rail, air and port operators are covered as essential or important entities.
- Digital infrastructure: data centres, cloud providers, electronic communications networks and DNS/TLD operators are a major focus of the Latvian regime.
- Public administration: central and selected local public authorities are brought into scope to protect critical public services and e-government systems.
- Manufacturing and services: certain manufacturers and service providers critical to national security or economic stability are included based on NIS2 and national criteria.
Penalties and fines
The Act uses soda nauda — an administrative penalty payment — and sets ceilings rather than floors. The figure that decides your real exposure is not the headline maximum but the EUR 500 million turnover gate: the percentage alternative only engages above it.
| Who | Maximum | Percentage alternative | Imposed by |
|---|---|---|---|
| Essential service provider | EUR 10 million | 2 % of last financial year total net turnover — only where that turnover exceeds EUR 500 million | National Cybersecurity Centre |
| Important service provider | EUR 7 million | 1.4 % — same EUR 500 million condition | National Cybersecurity Centre |
| Owner or lawful holder of ICT critical infrastructure | EUR 10 million | 2 % — same EUR 500 million condition | Constitution Protection Bureau |
| Coercive payment to enforce a decision | EUR 10,000 per imposition | — | Either supervisor |
What counts as substantial non-compliance
The Act defines it, which is unusual and useful. A fine requires one of three things:
- failing to take appropriate and proportionate technical and organisational measures to reduce the impact of a cyber threat or incident;
- repeatedly refusing to comply with lawful requests from officials of either supervisor for information within cybersecurity supervision;
- failing to report a significant incident within the statutory deadline, or knowingly supplying false information about it.
How the amount is set, and what happens next
- The amount must be proportionate to the infringement, and the supervisor must take into account the statutory aggravating and mitigating factors and the person's financial position.
- The decision is appealable to the administrative courts.
- A fine is payable within one month of the decision taking effect. If it is not paid voluntarily it is enforced by a bailiff, and the authority pays no state fee to start enforcement.
- Where binding decisions are ignored, the supervisors can impose the EUR 10,000 coercive payment, repeatedly, until compliance.
Supervision, security scanning and ordered audits
Latvia's supervisory powers go further than most transpositions, and three of them are absent from every English-language summary we audited.
They can scan your systems
Article 42 lists security scanning of the entity's electronic communications networks and information systems as a supervision measure, alongside on-site inspections, remote monitoring and checks of data and documents. The criteria and procedure are set by Cabinet regulation.
They can order an audit you pay for
Where a breach is suspected or established, the supervisor may audit you directly or require you to commission an external audit by an independent cybersecurity auditor with no conflict of interest. You bear the cost and you must remediate what it finds.
And they see the results
You must hand over a copy of the external audit report immediately on completion, and produce the underlying evidence for its conclusions on request. For ICT critical infrastructure the auditor must be agreed with the Constitution Protection Bureau.
How Latvia differs from the Directive
- Two supervisors, not one. The Satversmes aizsardzības birojs (Constitution Protection Bureau) — a state security institution — supervises and fines ICT critical infrastructure. Most member states give the cyber authority the whole field.
- Two incident response bodies, split between defence and everyone else, so the correct destination for a report depends on who you are.
- A named, notified cybersecurity manager, security-vetted where critical infrastructure is involved. The Directive requires management accountability; Latvia requires a person, a deadline and a phone number.
- A percentage that only bites above EUR 500 million of turnover, rather than a straightforward alternative ceiling.
- Security scanning as a routine supervisory power, written into the Act.
- A recurring self-assessment return whose frequency is set by regulation rather than by the Act.
- No statutory minimum fine, where nine other member states we have reviewed set one.
Latvian terms you will meet
The Act, the regulation and all correspondence are in Latvian, and several of these terms have no settled English rendering. These are the ones worth recognising.
| Latvian | What it means |
|---|---|
| Nacionālās kiberdrošības likums | The National Cybersecurity Law itself |
| kiberdrošības likums | How Latvians usually refer to it in search and in practice |
| Nacionālais kiberdrošības centrs | The National Cybersecurity Centre, which supervises most entities |
| Satversmes aizsardzības birojs | The Constitution Protection Bureau, which supervises ICT critical infrastructure |
| būtisko pakalpojumu sniedzējs | Essential service provider |
| svarīgo pakalpojumu sniedzējs | Important service provider |
| kiberdrošības pārvaldnieks | The cybersecurity manager you must appoint and notify |
| pašvērtējuma ziņojums | The compliance self-assessment report |
| agrīnais brīdinājums | The 24-hour early warning |
| sākotnējais ziņojums | The 72-hour initial report |
| galaziņojums | The final report, due one month after the initial report |
| soda nauda | The administrative penalty payment (the fine) |
| piespiedu nauda | The coercive payment used to enforce a decision |
| Minimālās kiberdrošības prasības | Regulation 397, the minimum cybersecurity requirements |
How to prepare for NIS2 in Latvia
- Assess if you are in scope: map your services and size against NIS2 Annex I & II sectors and the categories defined in the National Cybersecurity Law.
- Notify, and check the one-month clock: if you qualify and have not notified the National Cybersecurity Centre, the one-month duty under Article 22 is already running.
- Appoint and notify a cybersecurity manager: three months to appoint, five working days to notify both regulators — and prior agreement with the Constitution Protection Bureau if you hold ICT critical infrastructure.
- File the self-assessment report: to whichever authority supervises you, on the form and cycle set by Cabinet regulation.
- Re-check your scope against the 1 October 2026 change: organisations significant to national security come into scope on that date.
- Run a NIS2 gap assessment: compare your existing cybersecurity posture against legal requirements and minimum cybersecurity regulations.
- Strengthen incident detection & reporting: implement monitoring, escalation and reporting processes that meet Latvian timelines and formats.
- Review supply-chain risk: identify critical ICT and service providers and update contracts to include cybersecurity and incident-notification obligations.
- Align with recognised frameworks: use ISO/IEC 27001, NIST CSF or similar frameworks to structure governance, risk management and documentation.
- Train leadership and staff: ensure management and key teams understand their responsibilities under the National Cybersecurity Law and NIS2.
