BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:nis2-latvia-annual-self-assessment@eudeadlines.eu
DTSTAMP:20260907T220947Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:NIS2: Latvia NIS2 (National Cybersecurity Law): cybersecurity self-
 assessment report to NKDC
DESCRIPTION:Latvia transposed NIS2 through the Nacionālās kiberdrošības
  likums. Essential and important service providers had to register\, appoi
 nt a cybersecurity manager and submit a first self-assessment by 1 October
  2025\; ICT critical-infrastructure owners must repeat the self-assessment
  annually\, while other in-scope entities must repeat it at least once eve
 ry 3 years. All in-scope entities must maintain minimum security measures 
 and report significant incidents to CERT.LV.\n\nWho is affected: Medium an
 d large companies registered in Latvia in NIS2 sectors (energy\, transport
 \, banking\, health\, water\, digital infrastructure\, ICT services\, manu
 facturing of critical goods\, food\, chemicals\, postal\, waste\, research
 )\, plus smaller firms designated as ICT critical infrastructure or sole p
 rovider of a service.\n\nWhat to do: Confirm your registration status (ess
 ential/important entity) with the National Cybersecurity Centre (NKDC). If
  you own/operate designated ICT critical infrastructure\, resubmit the sel
 f-assessment annually by 1 October\; other in-scope entities must resubmit
  at least once every 3 years per MK noteikumi Nr. 397 — check your speci
 fic deadline with NKDC rather than assuming an annual cycle. Maintain mini
 mum security measures (access control\, backups\, incident response\, supp
 lier security) and keep 24h/72h CERT.LV incident-reporting procedures curr
 ent.\n\nPenalty: Essential entities up to €10M or 2% of turnover\; impor
 tant entities up to €7M or 1.4% (NIS2 levels)\n\nNote: Corrected: the cy
 bersecurity-manager notification and the FIRST self-assessment report were
  both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT unifor
 mly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasī
 bas' (in force 2025-07-02\, published Latvijas Vēstnesis 2025/123.1\, poi
 nt 8.3)\, only ICT critical-infrastructure owners/operators must resubmit 
 the self-assessment report at least once a year (next due ~2026-10-01)\; o
 ther essential/important entities ('svarīgie pakalpojumu sniedzēji') mus
 t resubmit at least once every 3 years (next due ~2028). The exact per-sub
 ject deadline and form are set by Cabinet regulation\, not the law itself 
 (Nacionālās kiberdrošības likums\, 43. pants).\n\nStatus: Confirmed\nh
 ttps://eudeadlines.eu/deadline/nis2-latvia-annual-self-assessment
URL:https://eudeadlines.eu/deadline/nis2-latvia-annual-self-assessment
CATEGORIES:LV,NIS2
LAST-MODIFIED:20260907T000000Z
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
