Lithuania NIS2: in-scope cybersecurity subjects must implement organisational measures within 12 months of registration
för 144 dagar sedan (Bekräftad)
Anmärkning om datumet: The Kibernetinio saugumo įstatymas (Act No. XII-1428), as amended by NIS2-transposing Act No. XIV-2902 (adopted 2024-07-11, in force from 2024-10-18), establishes a Cybersecurity Subjects Registry run by NKSC. Independent legal-tracker analysis (nis-2-directive.com; v-formation.io) reports that entities identified/registered as cybersecurity subjects by 2025-04-17 must implement organisational cybersecurity requirements within 12 months (i.e. by 2026-04-17) and technical requirements within 24 months (by 2027-04-17); later-registered entities follow the same 12/24-month clock from their own registration date. This transitional schedule could NOT be independently confirmed against NKSC's own guidance in this run — nksc.lt, kam.lt and vdai.lrv.lt all returned HTTP 403 (Cloudflare bot-challenge) to automated tools. Verify your specific deadline directly with NKSC or in a browser before relying on the exact date.
Lithuania's amended Cybersecurity Law transposes NIS2, requiring essential and important entities across roughly 18 critical sectors to register with the National Cyber Security Centre (NKSC) and then implement organisational cybersecurity measures within 12 months and technical measures within 24 months of registration.
Vem som berörs
Medium and large entities (plus some smaller entities NKSC designates as critical or as a sole service provider) in NIS2 sectors: energy, transport, banking/finance, health, digital infrastructure/software, manufacturing, agri-food, public administration and more.
Storlekar: medelstort företag, stort företag · Branscher: Energi, Transport / logistik, Finans / försäkring, Hälso- och sjukvård, Programvara / SaaS, Tillverkning, Jordbruk / livsmedel, Konsult- och tjänsteföretag · Gäller om: Vi är verksamma i en kritisk sektor (NIS2); Vi är beroende av molntjänster
Vad du ska göra
Determine whether your entity meets NIS2 essential/important-entity criteria under the Kibernetinio saugumo įstatymas. If so, confirm your registration date and deadline directly with NKSC, then build a cybersecurity risk-management policy, incident-reporting workflow (24h/72h/1-month), and supply-chain security measures on the applicable 12/24-month clock.
Sanktion
Essential entities: up to €10M or 2% of global annual turnover. Important entities: up to €7M or 1.4% of global annual turnover.
The Küberturvalisuse seaduse ja teiste seaduste muutmise seadus (transposing NIS2) was passed by the Riigikogu on 10 December 2025, proclaimed by the President on 18 December 2025, published in Riigi Teataja on 30 December 2025, and entered into force on 1 January 2026, expanding scope from roughly 3,000 to about 6,500 regulated entities.
Medium and large Estonian companies in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure and ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus certain smaller providers designated by RIA.
Entities that already met the essential/important-entity criteria when the amended Küberturvalisuse seadus took effect on 2026-01-01 had to submit registration data (name, registry code, address, contacts, IP ranges, sector) to RIA within 3 months, i.e. by 2026-03-31 (RIA's own notice flagged issues with its automated notification tooling around that date). Entities that become in-scope later must still self-register with RIA within 3 months of first meeting the criteria — an ongoing rule, not a one-off deadline.
Medium and large companies in NIS2 sectors that are or become in scope of Estonia's Cybersecurity Act, plus smaller entities RIA designates as critical or as sole providers of a service.
Corrected: the cybersecurity-manager notification and the FIRST self-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasības' (in force 2025-07-02, published Latvijas Vēstnesis 2025/123.1, point 8.3), only ICT critical-infrastructure owners/operators must resubmit the self-assessment report at least once a year (next due ~2026-10-01); other essential/important entities ('svarīgie pakalpojumu sniedzēji') must resubmit at least once every 3 years (next due ~2028). The exact per-subject deadline and form are set by Cabinet regulation, not the law itself (Nacionālās kiberdrošības likums, 43. pants).
Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms designated as ICT critical infrastructure or sole provider of a service.