Ta strona została przetłumaczona maszynowo. Oryginał w języku angielskim: Wersja angielska
PotwierdzonyŁotwaNIS2

Latvia NIS2 (National Cybersecurity Law): cybersecurity self-assessment report to NKDC

24 dni od dzisiaj

Uwaga do daty: Corrected: the cybersecurity-manager notification and the FIRST self-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasības' (in force 2025-07-02, published Latvijas Vēstnesis 2025/123.1, point 8.3), only ICT critical-infrastructure owners/operators must resubmit the self-assessment report at least once a year (next due ~2026-10-01); other essential/important entities ('svarīgie pakalpojumu sniedzēji') must resubmit at least once every 3 years (next due ~2028). The exact per-subject deadline and form are set by Cabinet regulation, not the law itself (Nacionālās kiberdrošības likums, 43. pants).

Co się zmienia

Latvia transposed NIS2 through the Nacionālās kiberdrošības likums. Essential and important service providers had to register, appoint a cybersecurity manager and submit a first self-assessment by 1 October 2025; ICT critical-infrastructure owners must repeat the self-assessment annually, while other in-scope entities must repeat it at least once every 3 years. All in-scope entities must maintain minimum security measures and report significant incidents to CERT.LV.

Kogo dotyczy

Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms designated as ICT critical infrastructure or sole provider of a service.

Wielkości: średnia, duża · Sektory: Energetyka, Transport / logistyka, Finanse / ubezpieczenia, Ochrona zdrowia, Oprogramowanie / SaaS, Produkcja, Rolnictwo / żywność, Usługi profesjonalne · Dotyczy, jeśli: Działamy w sektorze krytycznym (NIS2); Korzystamy z usług chmurowych

Co zrobić

Confirm your registration status (essential/important entity) with the National Cybersecurity Centre (NKDC). If you own/operate designated ICT critical infrastructure, resubmit the self-assessment annually by 1 October; other in-scope entities must resubmit at least once every 3 years per MK noteikumi Nr. 397 — check your specific deadline with NKDC rather than assuming an annual cycle. Maintain minimum security measures (access control, backups, incident response, supplier security) and keep 24h/72h CERT.LV incident-reporting procedures current.

Sankcje

Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4% (NIS2 levels)

Źródła

Ostatnia weryfikacja: 7 września 2026. Wyłącznie w celach informacyjnych, nie stanowi porady prawnej.

Więcej terminów: NIS2