NIS2 Country Guide

NIS2 Latvia: Kiberdrošības likums 2026

Latvia transposed NIS2 through the National Cybersecurity Law (Nacionālās kiberdrošības likums), in force since 1 September 2024 and amended with effect from 18 June 2026. This page sets out who is in scope, the registration and self-assessment duties, the cybersecurity manager Latvia invented, the 24-hour and 72-hour reporting chain, and what the fines actually are — including the EUR 500 million turnover gate that decides whether the percentage applies to you at all.

In force: 1 September 2024 Amended: 18 June 2026 Supervisors: NKDC and SAB Early warning: 24 hours Last updated: 11 August 2026

Introduction: NIS2 Directive & the Latvian context

Latvia replaced its old Law on the Security of Information Technologies with the National Cybersecurity Law (Nacionālās kiberdrošības likums), which has applied since 1 September 2024. Transposition is complete, the implementing regulation is in force, and the first compliance deadlines have already passed.

Two things make Latvia different from most member states, and both are missed by the English-language summaries. Supervision is split between two authorities rather than concentrated in one. And every entity in scope must appoint a named cybersecurity manager (kiberdrošības pārvaldnieks) and notify the regulators who that person is — an obligation with no direct equivalent in the Directive.

The law has moved since most guidance was written. It was amended by a law of 4 June 2026, in force 18 June 2026, and a further change to the scope provision takes effect on 1 October 2026. Summaries published before mid-2026 do not reflect either.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

NIS2 implementation in Latvia

Latvia transposed NIS2 through the National Cybersecurity Law (Nacionālās kiberdrošības likums), adopted by the Saeima on 20 June 2024, published in Latvijas Vēstnesis 128A on 4 July 2024 and in force since 1 September 2024. It repealed the Law on the Security of Information Technologies outright.

The detail sits in Cabinet Regulation No. 397, Minimālās kiberdrošības prasības (minimum cybersecurity requirements), in force since 2 July 2025. That regulation — not the Act — carries incident classification, the reporting forms, availability and recovery requirements, encryption, cyber-hygiene, staff competence and the requirements a cybersecurity manager has to meet. Reading the Act alone will not tell you what to implement.

The Act has been amended once since transposition. A law of 4 June 2026 took effect on 18 June 2026, touching the scope provision, the self-assessment report and the audit rules. One part of that amendment is deferred: from 1 October 2026, the scope provision extends to commercial companies, foundations and associations significant to national security. If you assessed your scope before mid-2026, the answer can have changed.

Status

Fully transposed and operating. The Act has applied since 1 September 2024, Regulation 397 since 2 July 2025, and the first self-assessment reports were due on 1 October 2025.

Legal structure

The Act sets the duties, the supervisory powers and the fine ceilings. Cabinet regulations supply the technical requirements, the reporting forms, the criteria for calculating a fine and the requirements for cybersecurity managers and auditors.

Supervisory approach

Split in two. The National Cybersecurity Centre supervises essential and important service providers; the Constitution Protection Bureau supervises ICT critical infrastructure. Incident reports go to a third body again — see the authorities section.

Who is in scope in Latvia

Latvia uses two statutory categories that map onto the Directive but carry Latvian names: būtisko pakalpojumu sniedzējs (essential service provider) and svarīgo pakalpojumu sniedzējs (important service provider). A third group sits alongside them and is easy to miss: owners and lawful holders of ICT critical infrastructure, who answer to a different supervisor entirely.

We do not publish an entity count for Latvia. Figures circulating in English-language guidance range from “over 2,000” to “nearly 8,000” and none is sourced to a published register. The Act does not state a number, and the list of identified providers is approved administratively.

Who is in scope?

  • Entities operating in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities operating in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
  • Medium-sized and larger organisations meeting NIS2 staff or turnover thresholds.
  • Entities covered regardless of size, such as DNS and TLD service providers, trust services, and major cloud or data-centre operators.

Core obligations

  • Implement risk-management measures aligned with NIS2, including governance, policies and technical controls.
  • Maintain inventories of critical systems, networks and information assets.
  • Detect, manage and report significant incidents within defined timeframes (early warning, incident notification, final report).
  • Manage supply-chain cybersecurity risk and include security and notification clauses in key contracts.
  • Ensure management bodies approve cybersecurity risk-management measures and exercise ongoing oversight.

Scope moves on 1 October 2026

The 4 June 2026 amendment extends the scope provision to commercial companies, foundations and associations significant to national security, with effect from 1 October 2026. An organisation that concluded it was out of scope in 2025 may be in scope this autumn.

Scope is self-assessed, and the duty is continuous. Nobody sends you a letter. Under Article 22 you assess your own status, and if you qualify you notify the National Cybersecurity Centre within one month. That duty did not expire with the 2025 cohort deadline — it applies whenever you first qualify, including as a result of growth or the October 2026 scope change.

Registration and the one-month clock

Latvia does not maintain a public register you can look yourself up in, and no authority will tell you that you are in scope. Article 22 puts the assessment on you and gives you a deadline measured from your own circumstances, not from a national date.

The duty

Carry out a self-assessment against the essential and important service provider definitions. If you meet either, notify the National Cybersecurity Centre within one month. The notification has to carry your name and registration number, legal form, legal address and contact details, including an official electronic address.

The 2025 cohort deadline

Organisations that already qualified when the Act took effect had until 1 April 2025 to notify, and the list of identified providers was approved by 17 April 2025. Domain name registration service providers had the same 1 April 2025 date under Article 23.

If you qualified later

The one-month clock in Article 22(1) applies instead. This is the point most guidance misses: the April 2025 dates were transitional provisions for the first cohort, not the end of the duty.

The Centre can also decide you are in scope. Where it establishes that an organisation has assessed its own status incorrectly, it can take a decision to that effect, and the organisation then has one month from receiving it to supply the registration information. Your obligations date from that decision.

The cybersecurity manager

This is Latvia's most distinctive obligation and it has no direct Directive equivalent. The Act makes the head of the entity responsible for cybersecurity governance personally, and then requires them to name a specific individual to run it.

StepDeadlineDetail
Appoint the manager Within 3 months Measured from your Article 22(1) notification, or from the date the Centre decided you are in scope. The requirements the person must meet are set by Cabinet Regulation 397.
Notify both regulators Within 5 working days Tell the National Cybersecurity Centre and the Constitution Protection Bureau the manager's name, personal identity code, position, email address and telephone number.
ICT critical infrastructure only Before appointment The candidate must be agreed with the Constitution Protection Bureau, which checks them against the requirements. The candidate is put forward within three months.
First-time notification 1 October 2025 Transitional deadline for entities already in scope when the regime started.
A named individual, vetted by a security service. For critical infrastructure this is not a paperwork exercise — the Bureau verifies the person before they can take the role. No other member state reviewed on this site subjects the equivalent role to security vetting.

The self-assessment report

Article 43 requires a pašvērtējuma ziņojums — a compliance self-assessment report — filed with whichever authority supervises you. It is a recurring return, not a one-off.

  • It goes to the National Cybersecurity Centre, or to the Constitution Protection Bureau if you hold ICT critical infrastructure.
  • The form, the information required, the deadline and how often you file are all set by Cabinet regulation rather than by the Act.
  • It reports your level of compliance with the minimum cybersecurity requirements, including the technical and organisational measures you have actually implemented.
  • The first report was due 1 October 2025.
Do not confuse the two 2025 dates. One widely read English guide gives 1 April 2025 as the self-assessment report deadline. That is the date for notifying that you are in scope. The self-assessment report is 1 October 2025, under a different transitional provision.

Authorities, CSIRTs and who actually supervises you

Latvia is not a centralised single-regulator model, and describing it as one is the most common error in English-language guidance. Supervision is split between two authorities under Article 41, and incident reports go to a different body again — of which there are two, divided by sector under Article 9.

Role Authority Notes
National competent authority and single point of contact Nacionālais kiberdrošības centrs (National Cybersecurity Centre), operating within the Ministry of Defence Article 4. National cybersecurity oversight, policy, international cooperation, and the single contact point. Maintains and approves the list of identified providers. Supervises all essential and important service providers except ICT critical infrastructure.
Supervisor for ICT critical infrastructure Satversmes aizsardzības birojs (Constitution Protection Bureau) Article 41(2). Supervises, audits and fines owners and lawful holders of ICT critical infrastructure, vets cybersecurity managers for those entities, and approves their auditors.
Incident response body — general Latvijas Universitātes Matemātikas un informātikas institūts, operating as CERT.LV Article 9(2)(2). Covers state and municipal institutions other than the security services, and all private-law legal persons — so for most businesses this is where incident reports go. Operates under the functional subordination of the Minister of Defence.
Incident response body — defence Militārās izlūkošanas un drošības dienests Article 9(2)(1). Covers the Ministry of Defence, its subordinate institutions and the National Armed Forces. Reports from those bodies do not go to CERT.LV.
Sectoral bodies (information exchange, not supervision) Latvijas Banka; Sabiedrisko pakalpojumu regulēšanas komisija Article 13(3). The Bank of Latvia for financial entities under Regulation 2022/2554 (DORA), and the Public Utilities Commission for electronic communications undertakings. Their statutory role is periodic exchange of information, not supervising you.

Incident reporting: 24 hours, 72 hours, one month

Article 34 sets a four-stage chain, plus two reports that only appear in particular circumstances. Reports go to the incident response body competent for you — CERT.LV for private organisations, the military service for defence bodies.

Immediately, for any incident — take the necessary steps, inform the competent incident response body and follow the instructions it gives. Owners of ICT critical infrastructure must also inform the competent state security institution.
24 hours — early warning (agrīnais brīdinājums), submitted electronically, for a significant incident.
72 hours — initial report (sākotnējais ziņojums). Trust service providers have 24 hours, not 72.
Without delay — tell your service recipients about measures they can take, and, after coordinating with the incident response body, about the incident itself — unless disclosure would create a fresh risk or conflict with national security.
One month — final report (galaziņojums) on resolution. The month runs from submission of the initial report, not from the incident.
On request — interim report, at any point while the incident is being handled.
If still unresolved at one month — progress report instead, with the final report following once the incident is actually resolved.
The regulator owes you something back. Within 24 hours of receiving your initial information, the incident response body must agree with you what support it will provide, give an initial assessment of the incident and propose remediation. That is a statutory duty on the authority, and few organisations know they can hold it to that.
A widely repeated error. English-language guidance states the final report is due “within 30 days to CERT.LV”. The Act says one month from the initial report, and for Ministry of Defence bodies and the Armed Forces the destination is the military intelligence and security service, not CERT.LV.

NIS2 timeline & key dates (Latvia)

20 June 2024 — Parliament adopts the National Cybersecurity Law implementing NIS2.
1 September 2024 — National Cybersecurity Law enters into force and replaces the Law on the Security of Information Technologies.
1 April 2025 — Entities must identify their status and register (self-identification/registration deadline).
17 April 2025 — Deadline for approving the list of essential/important entities.
2 July 2025 — Cabinet Regulation No. 397 on minimum cybersecurity requirements enters into force.
1 July 2025 — the incident reporting provisions of Article 34 become applicable.
1 October 2025 — first self-assessment report due, and first-time notification of the appointed cybersecurity manager.
18 June 2026 — amending law of 4 June 2026 takes effect, changing the scope provision, the self-assessment report and the audit rules.
1 October 2026 — scope extends to commercial companies, foundations and associations significant to national security.

Sector-specific notes for Latvia

  • Energy: electricity and gas infrastructure operators are treated as essential entities, with strict continuity and reporting requirements.
  • Transport: key road, rail, air and port operators are covered as essential or important entities.
  • Digital infrastructure: data centres, cloud providers, electronic communications networks and DNS/TLD operators are a major focus of the Latvian regime.
  • Public administration: central and selected local public authorities are brought into scope to protect critical public services and e-government systems.
  • Manufacturing and services: certain manufacturers and service providers critical to national security or economic stability are included based on NIS2 and national criteria.

Penalties and fines

The Act uses soda nauda — an administrative penalty payment — and sets ceilings rather than floors. The figure that decides your real exposure is not the headline maximum but the EUR 500 million turnover gate: the percentage alternative only engages above it.

WhoMaximumPercentage alternativeImposed by
Essential service provider EUR 10 million 2 % of last financial year total net turnover — only where that turnover exceeds EUR 500 million National Cybersecurity Centre
Important service provider EUR 7 million 1.4 % — same EUR 500 million condition National Cybersecurity Centre
Owner or lawful holder of ICT critical infrastructure EUR 10 million 2 % — same EUR 500 million condition Constitution Protection Bureau
Coercive payment to enforce a decision EUR 10,000 per imposition Either supervisor
Why the gate matters. Guidance that writes “up to EUR 10 million or up to 2 % of turnover” invites a company with EUR 20 million of turnover to calculate its exposure as EUR 400,000. Under the Act as written, that company's ceiling is EUR 10 million. The percentage is not a smaller alternative for smaller companies; it is an uplift for very large ones.

What counts as substantial non-compliance

The Act defines it, which is unusual and useful. A fine requires one of three things:

  • failing to take appropriate and proportionate technical and organisational measures to reduce the impact of a cyber threat or incident;
  • repeatedly refusing to comply with lawful requests from officials of either supervisor for information within cybersecurity supervision;
  • failing to report a significant incident within the statutory deadline, or knowingly supplying false information about it.

How the amount is set, and what happens next

  • The amount must be proportionate to the infringement, and the supervisor must take into account the statutory aggravating and mitigating factors and the person's financial position.
  • The decision is appealable to the administrative courts.
  • A fine is payable within one month of the decision taking effect. If it is not paid voluntarily it is enforced by a bailiff, and the authority pays no state fee to start enforcement.
  • Where binding decisions are ignored, the supervisors can impose the EUR 10,000 coercive payment, repeatedly, until compliance.
We do not state a minimum fine for Latvia. Unlike the nine member states we have reviewed that set statutory floors, the Act contains none — it sets ceilings only. The criteria for calculating the amount are delegated to Cabinet regulation, so we would rather say the Act is silent than assert that no floor exists anywhere in the framework.

Supervision, security scanning and ordered audits

Latvia's supervisory powers go further than most transpositions, and three of them are absent from every English-language summary we audited.

They can scan your systems

Article 42 lists security scanning of the entity's electronic communications networks and information systems as a supervision measure, alongside on-site inspections, remote monitoring and checks of data and documents. The criteria and procedure are set by Cabinet regulation.

They can order an audit you pay for

Where a breach is suspected or established, the supervisor may audit you directly or require you to commission an external audit by an independent cybersecurity auditor with no conflict of interest. You bear the cost and you must remediate what it finds.

And they see the results

You must hand over a copy of the external audit report immediately on completion, and produce the underlying evidence for its conclusions on request. For ICT critical infrastructure the auditor must be agreed with the Constitution Protection Bureau.

Both supervisors can prioritise. The Act expressly allows the Centre and the Bureau to decide which supervision measures to apply first based on current cyber risk, so an absence of contact is not evidence that you are out of scope or compliant.

How Latvia differs from the Directive

  • Two supervisors, not one. The Satversmes aizsardzības birojs (Constitution Protection Bureau) — a state security institution — supervises and fines ICT critical infrastructure. Most member states give the cyber authority the whole field.
  • Two incident response bodies, split between defence and everyone else, so the correct destination for a report depends on who you are.
  • A named, notified cybersecurity manager, security-vetted where critical infrastructure is involved. The Directive requires management accountability; Latvia requires a person, a deadline and a phone number.
  • A percentage that only bites above EUR 500 million of turnover, rather than a straightforward alternative ceiling.
  • Security scanning as a routine supervisory power, written into the Act.
  • A recurring self-assessment return whose frequency is set by regulation rather than by the Act.
  • No statutory minimum fine, where nine other member states we have reviewed set one.

Latvian terms you will meet

The Act, the regulation and all correspondence are in Latvian, and several of these terms have no settled English rendering. These are the ones worth recognising.

LatvianWhat it means
Nacionālās kiberdrošības likumsThe National Cybersecurity Law itself
kiberdrošības likumsHow Latvians usually refer to it in search and in practice
Nacionālais kiberdrošības centrsThe National Cybersecurity Centre, which supervises most entities
Satversmes aizsardzības birojsThe Constitution Protection Bureau, which supervises ICT critical infrastructure
būtisko pakalpojumu sniedzējsEssential service provider
svarīgo pakalpojumu sniedzējsImportant service provider
kiberdrošības pārvaldnieksThe cybersecurity manager you must appoint and notify
pašvērtējuma ziņojumsThe compliance self-assessment report
agrīnais brīdinājumsThe 24-hour early warning
sākotnējais ziņojumsThe 72-hour initial report
galaziņojumsThe final report, due one month after the initial report
soda naudaThe administrative penalty payment (the fine)
piespiedu naudaThe coercive payment used to enforce a decision
Minimālās kiberdrošības prasībasRegulation 397, the minimum cybersecurity requirements

How to prepare for NIS2 in Latvia

  1. Assess if you are in scope: map your services and size against NIS2 Annex I & II sectors and the categories defined in the National Cybersecurity Law.
  2. Notify, and check the one-month clock: if you qualify and have not notified the National Cybersecurity Centre, the one-month duty under Article 22 is already running.
  3. Appoint and notify a cybersecurity manager: three months to appoint, five working days to notify both regulators — and prior agreement with the Constitution Protection Bureau if you hold ICT critical infrastructure.
  4. File the self-assessment report: to whichever authority supervises you, on the form and cycle set by Cabinet regulation.
  5. Re-check your scope against the 1 October 2026 change: organisations significant to national security come into scope on that date.
  6. Run a NIS2 gap assessment: compare your existing cybersecurity posture against legal requirements and minimum cybersecurity regulations.
  7. Strengthen incident detection & reporting: implement monitoring, escalation and reporting processes that meet Latvian timelines and formats.
  8. Review supply-chain risk: identify critical ICT and service providers and update contracts to include cybersecurity and incident-notification obligations.
  9. Align with recognised frameworks: use ISO/IEC 27001, NIST CSF or similar frameworks to structure governance, risk management and documentation.
  10. Train leadership and staff: ensure management and key teams understand their responsibilities under the National Cybersecurity Law and NIS2.

Official links & resources

Nacionālās kiberdrošības likums — consolidated text (likumi.lv) — the authoritative version, including the 4 June 2026 amendment
CERT.LV — the incident response body for private organisations and most public bodies

FAQ: NIS2 in Latvia

Has Latvia fully transposed NIS2?
Yes. Latvia has fully transposed NIS2 through the National Cybersecurity Law, which entered into force on 1 September 2024, supported by minimum cybersecurity requirements adopted in 2025.
Who supervises us — and is it the same body we report incidents to?
Usually not, and this catches people out. The National Cybersecurity Centre supervises essential and important service providers; the Constitution Protection Bureau supervises ICT critical infrastructure. Incident reports go somewhere else again: CERT.LV, operated by the University of Latvia's Institute of Mathematics and Computer Science, for private organisations and most public bodies, and the military intelligence and security service for Ministry of Defence bodies and the Armed Forces.
Do we have to register, and has the deadline passed?
You must self-assess and, if you qualify, notify the National Cybersecurity Centre within one month. The 1 April 2025 date that appears in most guidance was a transitional deadline for organisations already in scope when the Act started — it did not end the duty. If you qualify today, the one-month clock applies to you now.
What is a cybersecurity manager and do we need one?
Every entity in scope does. The head of the organisation is responsible for cybersecurity governance and must designate a kiberdrošības pārvaldnieks within three months, then notify both the Centre and the Bureau within five working days with that person's name, identity code, position, email and telephone number. If you hold ICT critical infrastructure, the candidate must be agreed with the Constitution Protection Bureau first.
Could we really be fined 2 % of turnover?
Only if your last financial year net turnover exceeded EUR 500 million. Below that threshold the ceiling is EUR 10 million for an essential service provider and EUR 7 million for an important one. Guidance that writes “EUR 10 million or 2 % of turnover” without the threshold understates the exposure of mid-sized companies considerably.
Has the law changed recently?
Yes, twice in effect. An amending law of 4 June 2026 took effect on 18 June 2026, and a deferred part of it extends the scope provision to organisations significant to national security from 1 October 2026. Guidance written before mid-2026 does not reflect either change.
Is ISO 27001 certification mandatory?
No specific certification is mandated by name, but aligning with recognised standards such as ISO/IEC 27001 is strongly recommended to structure and demonstrate NIS2 compliance in Latvia.
Information provided for general guidance; always consult the consolidated text of the Nacionālās kiberdrošības likums on likumi.lv, Cabinet Regulation No. 397, the publications of the Nacionālais kiberdrošības centrs and legal counsel for definitive NIS2 compliance requirements.