Ta strona została przetłumaczona maszynowo. Oryginał w języku angielskim: Wersja angielska
PotwierdzonyŁotwaNIS2
Latvia NIS2 (National Cybersecurity Law): cybersecurity self-assessment report to NKDC
24 dni od dzisiaj
Uwaga do daty: Corrected: the cybersecurity-manager notification and the FIRST self-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasības' (in force 2025-07-02, published Latvijas Vēstnesis 2025/123.1, point 8.3), only ICT critical-infrastructure owners/operators must resubmit the self-assessment report at least once a year (next due ~2026-10-01); other essential/important entities ('svarīgie pakalpojumu sniedzēji') must resubmit at least once every 3 years (next due ~2028). The exact per-subject deadline and form are set by Cabinet regulation, not the law itself (Nacionālās kiberdrošības likums, 43. pants).
Latvia transposed NIS2 through the Nacionālās kiberdrošības likums. Essential and important service providers had to register, appoint a cybersecurity manager and submit a first self-assessment by 1 October 2025; ICT critical-infrastructure owners must repeat the self-assessment annually, while other in-scope entities must repeat it at least once every 3 years. All in-scope entities must maintain minimum security measures and report significant incidents to CERT.LV.
Kogo dotyczy
Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms designated as ICT critical infrastructure or sole provider of a service.
Wielkości: średnia, duża · Sektory: Energetyka, Transport / logistyka, Finanse / ubezpieczenia, Ochrona zdrowia, Oprogramowanie / SaaS, Produkcja, Rolnictwo / żywność, Usługi profesjonalne · Dotyczy, jeśli: Działamy w sektorze krytycznym (NIS2); Korzystamy z usług chmurowych
Co zrobić
Confirm your registration status (essential/important entity) with the National Cybersecurity Centre (NKDC). If you own/operate designated ICT critical infrastructure, resubmit the self-assessment annually by 1 October; other in-scope entities must resubmit at least once every 3 years per MK noteikumi Nr. 397 — check your specific deadline with NKDC rather than assuming an annual cycle. Maintain minimum security measures (access control, backups, incident response, supplier security) and keep 24h/72h CERT.LV incident-reporting procedures current.
Sankcje
Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4% (NIS2 levels)
Średnie i duże estońskie firmy w sektorach objętych NIS2 (energetyka, transport, bankowość, zdrowie, woda, infrastruktura cyfrowa i usługi ICT, produkcja towarów krytycznych, żywność, chemikalia, usługi pocztowe, odpady, badania naukowe), a także niektórzy mniejsi dostawcy wyznaczeni przez RIA.