BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:nis2-latvia-annual-self-assessment@eudeadlines.eu
DTSTAMP:20260907T230824Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:NIS2: Latvia NIS2 (National Cybersecurity Law): cybersecurity self-
 assessment report to NKDC
DESCRIPTION:Latvia transposed NIS2 through the Nacionālās kiberdrošības
  likums. Essential and important service providers had to register\, appoi
 nt a cybersecurity manager and submit a first self-assessment by 1 October
  2025\; ICT critical-infrastructure owners must repeat the self-assessment
  annually\, while other in-scope entities must repeat it at least once eve
 ry 3 years. All in-scope entities must maintain minimum security measures 
 and report significant incidents to CERT.LV.\n\nVoor wie geldt dit: Medium
  and large companies registered in Latvia in NIS2 sectors (energy\, transp
 ort\, banking\, health\, water\, digital infrastructure\, ICT services\, m
 anufacturing of critical goods\, food\, chemicals\, postal\, waste\, resea
 rch)\, plus smaller firms designated as ICT critical infrastructure or sol
 e provider of a service.\n\nWat u moet doen: Confirm your registration sta
 tus (essential/important entity) with the National Cybersecurity Centre (N
 KDC). If you own/operate designated ICT critical infrastructure\, resubmit
  the self-assessment annually by 1 October\; other in-scope entities must 
 resubmit at least once every 3 years per MK noteikumi Nr. 397 — check yo
 ur specific deadline with NKDC rather than assuming an annual cycle. Maint
 ain minimum security measures (access control\, backups\, incident respons
 e\, supplier security) and keep 24h/72h CERT.LV incident-reporting procedu
 res current.\n\nSanctie: Essential entities up to €10M or 2% of turnover
 \; important entities up to €7M or 1.4% (NIS2 levels)\n\nOpmerking bij d
 e datum: Corrected: the cybersecurity-manager notification and the FIRST s
 elf-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv)
 . Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimāl
 ās kiberdrošības prasības' (in force 2025-07-02\, published Latvijas V
 ēstnesis 2025/123.1\, point 8.3)\, only ICT critical-infrastructure owner
 s/operators must resubmit the self-assessment report at least once a year 
 (next due ~2026-10-01)\; other essential/important entities ('svarīgie pa
 kalpojumu sniedzēji') must resubmit at least once every 3 years (next due
  ~2028). The exact per-subject deadline and form are set by Cabinet regula
 tion\, not the law itself (Nacionālās kiberdrošības likums\, 43. pants
 ).\n\nStatus: Bevestigd\nhttps://eudeadlines.eu/nl/deadline/nis2-latvia-an
 nual-self-assessment
URL:https://eudeadlines.eu/nl/deadline/nis2-latvia-annual-self-assessment
CATEGORIES:LV,NIS2
LAST-MODIFIED:20260907T000000Z
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
