BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:nis2-latvia-annual-self-assessment@eudeadlines.eu
DTSTAMP:20260907T230823Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:NIS2: Latvia NIS2 (National Cybersecurity Law): cybersecurity self-
 assessment report to NKDC
DESCRIPTION:Latvia transposed NIS2 through the Nacionālās kiberdrošības
  likums. Essential and important service providers had to register\, appoi
 nt a cybersecurity manager and submit a first self-assessment by 1 October
  2025\; ICT critical-infrastructure owners must repeat the self-assessment
  annually\, while other in-scope entities must repeat it at least once eve
 ry 3 years. All in-scope entities must maintain minimum security measures 
 and report significant incidents to CERT.LV.\n\nWer betroffen ist: Medium 
 and large companies registered in Latvia in NIS2 sectors (energy\, transpo
 rt\, banking\, health\, water\, digital infrastructure\, ICT services\, ma
 nufacturing of critical goods\, food\, chemicals\, postal\, waste\, resear
 ch)\, plus smaller firms designated as ICT critical infrastructure or sole
  provider of a service.\n\nWas zu tun ist: Confirm your registration statu
 s (essential/important entity) with the National Cybersecurity Centre (NKD
 C). If you own/operate designated ICT critical infrastructure\, resubmit t
 he self-assessment annually by 1 October\; other in-scope entities must re
 submit at least once every 3 years per MK noteikumi Nr. 397 — check your
  specific deadline with NKDC rather than assuming an annual cycle. Maintai
 n minimum security measures (access control\, backups\, incident response\
 , supplier security) and keep 24h/72h CERT.LV incident-reporting procedure
 s current.\n\nSanktion: Essential entities up to €10M or 2% of turnover\
 ; important entities up to €7M or 1.4% (NIS2 levels)\n\nHinweis zum Datu
 m: Corrected: the cybersecurity-manager notification and the FIRST self-as
 sessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recu
 rrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās ki
 berdrošības prasības' (in force 2025-07-02\, published Latvijas Vēstne
 sis 2025/123.1\, point 8.3)\, only ICT critical-infrastructure owners/oper
 ators must resubmit the self-assessment report at least once a year (next 
 due ~2026-10-01)\; other essential/important entities ('svarīgie pakalpoj
 umu sniedzēji') must resubmit at least once every 3 years (next due ~2028
 ). The exact per-subject deadline and form are set by Cabinet regulation\,
  not the law itself (Nacionālās kiberdrošības likums\, 43. pants).\n\n
 Status: Bestätigt\nhttps://eudeadlines.eu/de/deadline/nis2-latvia-annual-
 self-assessment
URL:https://eudeadlines.eu/de/deadline/nis2-latvia-annual-self-assessment
CATEGORIES:LV,NIS2
LAST-MODIFIED:20260907T000000Z
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
