Diese Seite wurde maschinell übersetzt. Englisches Original: Englische Version
BestätigtLettlandNIS2
Latvia NIS2 (National Cybersecurity Law): cybersecurity self-assessment report to NKDC
24 Tage ab heute
Hinweis zum Datum: Corrected: the cybersecurity-manager notification and the FIRST self-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasības' (in force 2025-07-02, published Latvijas Vēstnesis 2025/123.1, point 8.3), only ICT critical-infrastructure owners/operators must resubmit the self-assessment report at least once a year (next due ~2026-10-01); other essential/important entities ('svarīgie pakalpojumu sniedzēji') must resubmit at least once every 3 years (next due ~2028). The exact per-subject deadline and form are set by Cabinet regulation, not the law itself (Nacionālās kiberdrošības likums, 43. pants).
Latvia transposed NIS2 through the Nacionālās kiberdrošības likums. Essential and important service providers had to register, appoint a cybersecurity manager and submit a first self-assessment by 1 October 2025; ICT critical-infrastructure owners must repeat the self-assessment annually, while other in-scope entities must repeat it at least once every 3 years. All in-scope entities must maintain minimum security measures and report significant incidents to CERT.LV.
Wer betroffen ist
Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms designated as ICT critical infrastructure or sole provider of a service.
Größen: mittel, groß · Branchen: Energie, Transport / Logistik, Finanzen / Versicherungen, Gesundheit, Software / SaaS, Produzierendes Gewerbe, Landwirtschaft / Lebensmittel, Freiberufliche Dienstleistungen · Gilt, wenn: Wir sind in einem kritischen Sektor tätig (NIS2); Wir nutzen Cloud-Dienste
Was zu tun ist
Confirm your registration status (essential/important entity) with the National Cybersecurity Centre (NKDC). If you own/operate designated ICT critical infrastructure, resubmit the self-assessment annually by 1 October; other in-scope entities must resubmit at least once every 3 years per MK noteikumi Nr. 397 — check your specific deadline with NKDC rather than assuming an annual cycle. Maintain minimum security measures (access control, backups, incident response, supplier security) and keep 24h/72h CERT.LV incident-reporting procedures current.
Sanktion
Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4% (NIS2 levels)
Mittlere und große estnische Unternehmen in NIS2-Sektoren (Energie, Verkehr, Bankwesen, Gesundheit, Wasser, digitale Infrastruktur und IKT-Dienste, Herstellung kritischer Güter, Lebensmittel, Chemie, Post, Abfall, Forschung) sowie bestimmte von der RIA benannte kleinere Anbieter.