BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:lt-nis2-cybersecurity-transitional-2026@eudeadlines.eu
DTSTAMP:20260908T111427Z
DTSTART;VALUE=DATE:20260417
DTEND;VALUE=DATE:20260418
SUMMARY:NIS2: Lithuania NIS2: in-scope cybersecurity subjects must implemen
 t organisational measures within 12 months of registration
DESCRIPTION:Lithuania's amended Cybersecurity Law transposes NIS2\, requiri
 ng essential and important entities across roughly 18 critical sectors to 
 register with the National Cyber Security Centre (NKSC) and then implement
  organisational cybersecurity measures within 12 months and technical meas
 ures within 24 months of registration.\n\nVoor wie geldt dit: Medium and l
 arge entities (plus some smaller entities NKSC designates as critical or a
 s a sole service provider) in NIS2 sectors: energy\, transport\, banking/f
 inance\, health\, digital infrastructure/software\, manufacturing\, agri-f
 ood\, public administration and more.\n\nWat u moet doen: Determine whethe
 r your entity meets NIS2 essential/important-entity criteria under the Kib
 ernetinio saugumo įstatymas. If so\, confirm your registration date and d
 eadline directly with NKSC\, then build a cybersecurity risk-management po
 licy\, incident-reporting workflow (24h/72h/1-month)\, and supply-chain se
 curity measures on the applicable 12/24-month clock.\n\nSanctie: Essential
  entities: up to €10M or 2% of global annual turnover. Important entitie
 s: up to €7M or 1.4% of global annual turnover.\n\nOpmerking bij de datu
 m: The Kibernetinio saugumo įstatymas (Act No. XII-1428)\, as amended by 
 NIS2-transposing Act No. XIV-2902 (adopted 2024-07-11\, in force from 2024
 -10-18)\, establishes a Cybersecurity Subjects Registry run by NKSC. Indep
 endent legal-tracker analysis (nis-2-directive.com\; v-formation.io) repor
 ts that entities identified/registered as cybersecurity subjects by 2025-0
 4-17 must implement organisational cybersecurity requirements within 12 mo
 nths (i.e. by 2026-04-17) and technical requirements within 24 months (by 
 2027-04-17)\; later-registered entities follow the same 12/24-month clock 
 from their own registration date. This transitional schedule could NOT be 
 independently confirmed against NKSC's own guidance in this run — nksc.l
 t\, kam.lt and vdai.lrv.lt all returned HTTP 403 (Cloudflare bot-challenge
 ) to automated tools. Verify your specific deadline directly with NKSC or 
 in a browser before relying on the exact date.\n\nStatus: Bevestigd\nhttps
 ://eudeadlines.eu/nl/deadline/lt-nis2-cybersecurity-transitional-2026
URL:https://eudeadlines.eu/nl/deadline/lt-nis2-cybersecurity-transitional-2
 026
CATEGORIES:LT,NIS2
LAST-MODIFIED:20260908T000000Z
TRANSP:TRANSPARENT
BEGIN:VALARM
ACTION:DISPLAY
DESCRIPTION:NIS2: Lithuania NIS2: in-scope cybersecurity subjects must impl
 ement organisational measures within 12 months of registration — due in 
 7 days
TRIGGER;VALUE=DURATION:-P6DT15H
END:VALARM
BEGIN:VALARM
ACTION:DISPLAY
DESCRIPTION:NIS2: Lithuania NIS2: in-scope cybersecurity subjects must impl
 ement organisational measures within 12 months of registration — due in 
 1 day
TRIGGER;VALUE=DURATION:-PT15H
END:VALARM
END:VEVENT
END:VCALENDAR
