ConfirmedLatviaNIS2

Latvia NIS2 (National Cybersecurity Law): annual self-assessment report for essential and important entities

24 days from today

Date note: Law in force since 2024-09-01; registration deadline was 2025-04-01, first cybersecurity manager notification and self-assessment report 2025-10-01; annual report by 1 October each year per NKDC guidance – confirm exact date with cyber.gov.lv

What changes

Latvia transposed NIS2 through the Nacionālās kiberdrošības likums. Essential and important service providers had to register, appoint a cybersecurity manager and submit a first self-assessment in 2025; they now have to run a yearly security review and self-assessment, keep risk-management and continuity plans, and report significant incidents to CERT.LV.

Who is affected

Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms that are the sole provider of a service or own critical ICT infrastructure.

Sizes: medium, large · Sectors: Energy, Transport / logistics, Finance / insurance, Health, Software / SaaS, Manufacturing, Agriculture / food, Professional services · Applies if: We operate in a critical sector (NIS2); We rely on cloud services

What to do

Confirm whether you are registered as an essential or important entity with the National Cybersecurity Centre (NKDC). Have your cybersecurity manager complete the annual self-assessment and submit it by 1 October. Maintain the minimum security measures (access control, backups, incident response, supplier security) and test incident reporting to CERT.LV (24h early warning, 72h notification).

Penalty

Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4% (NIS2 levels)

Sources

Last verified 7 September 2026. Informational only, not legal advice.

More NIS2 deadlines