BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:nis2-latvia-annual-self-assessment@eudeadlines.eu
DTSTAMP:20260907T230823Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:NIS2: Latvia NIS2 (National Cybersecurity Law): cybersecurity self-
 assessment report to NKDC
DESCRIPTION:Latvia transposed NIS2 through the Nacionālās kiberdrošības
  likums. Essential and important service providers had to register\, appoi
 nt a cybersecurity manager and submit a first self-assessment by 1 October
  2025\; ICT critical-infrastructure owners must repeat the self-assessment
  annually\, while other in-scope entities must repeat it at least once eve
 ry 3 years. All in-scope entities must maintain minimum security measures 
 and report significant incidents to CERT.LV.\n\nKogo dotyczy: Medium and l
 arge companies registered in Latvia in NIS2 sectors (energy\, transport\, 
 banking\, health\, water\, digital infrastructure\, ICT services\, manufac
 turing of critical goods\, food\, chemicals\, postal\, waste\, research)\,
  plus smaller firms designated as ICT critical infrastructure or sole prov
 ider of a service.\n\nCo zrobić: Confirm your registration status (essent
 ial/important entity) with the National Cybersecurity Centre (NKDC). If yo
 u own/operate designated ICT critical infrastructure\, resubmit the self-a
 ssessment annually by 1 October\; other in-scope entities must resubmit at
  least once every 3 years per MK noteikumi Nr. 397 — check your specific
  deadline with NKDC rather than assuming an annual cycle. Maintain minimum
  security measures (access control\, backups\, incident response\, supplie
 r security) and keep 24h/72h CERT.LV incident-reporting procedures current
 .\n\nSankcje: Essential entities up to €10M or 2% of turnover\; importan
 t entities up to €7M or 1.4% (NIS2 levels)\n\nUwaga do daty: Corrected: 
 the cybersecurity-manager notification and the FIRST self-assessment repor
 t were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT 
 uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības 
 prasības' (in force 2025-07-02\, published Latvijas Vēstnesis 2025/123.1
 \, point 8.3)\, only ICT critical-infrastructure owners/operators must res
 ubmit the self-assessment report at least once a year (next due ~2026-10-0
 1)\; other essential/important entities ('svarīgie pakalpojumu sniedzēji
 ') must resubmit at least once every 3 years (next due ~2028). The exact p
 er-subject deadline and form are set by Cabinet regulation\, not the law i
 tself (Nacionālās kiberdrošības likums\, 43. pants).\n\nStatus: Potwie
 rdzony\nhttps://eudeadlines.eu/pl/deadline/nis2-latvia-annual-self-assessm
 ent
URL:https://eudeadlines.eu/pl/deadline/nis2-latvia-annual-self-assessment
CATEGORIES:LV,NIS2
LAST-MODIFIED:20260907T000000Z
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
