Lithuania

← All Member States
Transposed, in force
NIS2 status
Transposed, in force
National law
Kibernetinio saugumo įstatymas (amended) (Teisės aktų registras, July 2024)
Competent authority
Nacionalinis kibernetinio saugumo centras (NKSC), under the Ministry of National Defence
CSIRT
NKSC / CERT-LT
Last verified
2026-07-16

Lithuania

✅ NIS2 transposed and in force.

NIS2 transposition

  • National law: Kibernetinio saugumo įstatymas (amended) (Teisės aktų registras, July 2024)
  • Status / entry into force: In force 2024-10-18 (met the EU deadline)

Competent authority & CSIRT

  • Competent authority: Nacionalinis kibernetinio saugumo centras (NKSC), under the Ministry of National Defence
  • CSIRT / incident response: NKSC / CERT-LT
  • Registration: Per NKSC; implementing government regulation adopted 2024-11-06

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

One of only four states to meet the October 2024 deadline.

Sources