Latvia NIS2 (National Cybersecurity Law): annual self-assessment report for essential and important entities
24 days from today
Date note: Law in force since 2024-09-01; registration deadline was 2025-04-01, first cybersecurity manager notification and self-assessment report 2025-10-01; annual report by 1 October each year per NKDC guidance – confirm exact date with cyber.gov.lv
Latvia transposed NIS2 through the Nacionālās kiberdrošības likums. Essential and important service providers had to register, appoint a cybersecurity manager and submit a first self-assessment in 2025; they now have to run a yearly security review and self-assessment, keep risk-management and continuity plans, and report significant incidents to CERT.LV.
Who is affected
Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms that are the sole provider of a service or own critical ICT infrastructure.
Sizes: medium, large · Sectors: Energy, Transport / logistics, Finance / insurance, Health, Software / SaaS, Manufacturing, Agriculture / food, Professional services · Applies if: We operate in a critical sector (NIS2); We rely on cloud services
What to do
Confirm whether you are registered as an essential or important entity with the National Cybersecurity Centre (NKDC). Have your cybersecurity manager complete the annual self-assessment and submit it by 1 October. Maintain the minimum security measures (access control, backups, incident response, supplier security) and test incident reporting to CERT.LV (24h early warning, 72h notification).
Penalty
Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4% (NIS2 levels)
Medium and large Estonian companies in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure and ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus certain smaller providers designated by RIA.