Latvia

← All Member States
Transposed, in force
NIS2 status
Transposed, in force
National law
Nacionālās kiberdrošības likums (NKDL) (Latvijas Vēstnesis, June 2024)
Competent authority
National Cyber Security Centre (at the Ministry of Defence)
CSIRT
CERT.LV
Last verified
2026-07-16

Latvia

✅ NIS2 transposed and in force.

NIS2 transposition

  • National law: Nacionālās kiberdrošības likums (NKDL) (Latvijas Vēstnesis, June 2024)
  • Status / entry into force: In force 2024-09-01

Competent authority & CSIRT

  • Competent authority: National Cyber Security Centre (at the Ministry of Defence)
  • CSIRT / incident response: CERT.LV
  • Registration: Self-identification register due 2025-04-01; cybersecurity manager + first self-assessment by 2025-10-01

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

Early transposition.

Sources