BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:nis2-latvia-annual-self-assessment@eudeadlines.eu
DTSTAMP:20260907T230823Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:NIS2: Latvia NIS2 (National Cybersecurity Law): cybersecurity self-
 assessment report to NKDC
DESCRIPTION:Latvia transposed NIS2 through the Nacionālās kiberdrošības
  likums. Essential and important service providers had to register\, appoi
 nt a cybersecurity manager and submit a first self-assessment by 1 October
  2025\; ICT critical-infrastructure owners must repeat the self-assessment
  annually\, while other in-scope entities must repeat it at least once eve
 ry 3 years. All in-scope entities must maintain minimum security measures 
 and report significant incidents to CERT.LV.\n\nQui est concerné: Medium 
 and large companies registered in Latvia in NIS2 sectors (energy\, transpo
 rt\, banking\, health\, water\, digital infrastructure\, ICT services\, ma
 nufacturing of critical goods\, food\, chemicals\, postal\, waste\, resear
 ch)\, plus smaller firms designated as ICT critical infrastructure or sole
  provider of a service.\n\nQue faire: Confirm your registration status (es
 sential/important entity) with the National Cybersecurity Centre (NKDC). I
 f you own/operate designated ICT critical infrastructure\, resubmit the se
 lf-assessment annually by 1 October\; other in-scope entities must resubmi
 t at least once every 3 years per MK noteikumi Nr. 397 — check your spec
 ific deadline with NKDC rather than assuming an annual cycle. Maintain min
 imum security measures (access control\, backups\, incident response\, sup
 plier security) and keep 24h/72h CERT.LV incident-reporting procedures cur
 rent.\n\nSanction: Essential entities up to €10M or 2% of turnover\; imp
 ortant entities up to €7M or 1.4% (NIS2 levels)\n\nNote sur la date : Co
 rrected: the cybersecurity-manager notification and the FIRST self-assessm
 ent report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrenc
 e is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdr
 ošības prasības' (in force 2025-07-02\, published Latvijas Vēstnesis 2
 025/123.1\, point 8.3)\, only ICT critical-infrastructure owners/operators
  must resubmit the self-assessment report at least once a year (next due ~
 2026-10-01)\; other essential/important entities ('svarīgie pakalpojumu s
 niedzēji') must resubmit at least once every 3 years (next due ~2028). Th
 e exact per-subject deadline and form are set by Cabinet regulation\, not 
 the law itself (Nacionālās kiberdrošības likums\, 43. pants).\n\nStatu
 s: Confirmée\nhttps://eudeadlines.eu/fr/deadline/nis2-latvia-annual-self-
 assessment
URL:https://eudeadlines.eu/fr/deadline/nis2-latvia-annual-self-assessment
CATEGORIES:LV,NIS2
LAST-MODIFIED:20260907T000000Z
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
