All systems operational Your IP: 216.73.216.68 info@cloudhosting.lv +371 66 66 29 69 Client area

← All questions

NIS2 in Latvia 2026: what the June amendments changed

Updated:

The amendments to the Latvian National Cybersecurity Law have been in force since 18 June 2026, and from 1 October the law also covers companies the state designates as significant for national security. In short: the list of approved auditors is gone, the circle of subjects was made precise, personnel security rules arrived, and the deadlines finally line up. Here is what changed and what to do about it.

Four things that changed on 18 June

The public list of auditors was abolished. A cybersecurity audit used to be reserved for firms on an official list. You may now commission any auditor who meets the Cabinet requirements. In practice that means more supply and real price competition, because a short list kept prices high.

The circle of subjects was made precise. Private bodies performing delegated state administration tasks in the social and cultural sectors were taken out of it. A useful reminder that the law is not static: some organisations that thought they were subjects last year no longer are.

Personnel security requirements. An employer must now assess security risks when hiring people with privileged access to critical systems and ICT resources, and may request a certificate from the Punishment Register to confirm the person has no conviction for an intentional criminal offence. If three people in your company know the administrator password, this applies to them.

Deadlines were aligned. The three month deadline for appointing a cybersecurity manager is now tied to the self-assessment reporting deadline. They used to live apart, and companies simply could not tell which date came first.

What happens on 1 October

From 1 October 2026, companies, associations and foundations designated as significant for national security become essential service providers regardless of their size. That is an exception to the usual headcount and turnover thresholds. Those that have not yet registered with the National Cybersecurity Centre are given a proportionate transition period to comply.

Are you a subject at all

The thresholds come from the law itself and there are two of them.

An essential service provider is a large operator: at least 250 employees, or turnover above 50 million euro, or a balance sheet total above 43 million euro. Sectors: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space.

An important service provider is a medium operator: up to 249 employees and turnover of at least 10 million euro but not above 50 million, or a balance sheet total of at least 10 million euro but not above 43 million. Sectors: postal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers and research.

And here is the honest part that vendors tend to skip: if you have 12 people and 800 000 euro of turnover, you are most likely not a subject. Being outside NIS2 does not protect you from ransomware, but it does mean you owe the state no register entry, no manager and no self-assessment. Two cases sit outside the size logic, and they are not the same. An owner of ICT critical infrastructure is a subject regardless of size and is supervised by the Constitutional Protection Bureau. A domain name registration service provider, by contrast, falls under article 23, a separate and lighter regime: notify the Centre of your status and keep a domain registration data database to the Cabinet requirements, but a cybersecurity manager, a self-assessment and incident reporting are not part of it. Note the difference: the registry of a top level domain, for example the ".lv" registry, and a provider of a public recursive DNS service are a different matter entirely, they are essential service providers with the full set of duties.

The deadlines that start the day you become a subject

  • One month to register with the National Cybersecurity Centre, counted from the day you became a subject. Article 22 of the law.
  • Three months to appoint and report the person responsible for cybersecurity management.
  • 24 hours for the early warning about an incident, 72 hours for the full notification and one month for the final report. Article 34 of the law.
  • Self-assessment report: yearly for owners of ICT critical infrastructure, every three years for other subjects. The exact submission deadline is set by Cabinet regulation.

Existing subjects were due to register by 1 April 2025 and to have a manager and a first self-assessment by 1 October 2025. If those were missed, the right move is to register now rather than wait for a letter.

How to register and what follows

Registration uses a form whose template is approved by the Cabinet regulation on minimum cybersecurity requirements. You sign the completed form electronically and send it as an attachment to the official e-address of the National Cybersecurity Centre at the Ministry of Defence. The form asks for basic details of the subject, contacts, the status (essential or important), fields of activity, the countries you operate in, your IP address ranges and a contact person. Questions go to NIS2@mod.gov.lv.

Three things follow registration. First, the cybersecurity manager: within three months of gaining subject status you name the responsible person and report them to the supervisory authority, which is the National Cybersecurity Centre for essential and important providers and the Constitutional Protection Bureau for owners of ICT critical infrastructure. Second, the self-assessment report: yearly for owners of ICT critical infrastructure, every three years for other subjects. Third, incident reporting under article 34: 24 hours for the early warning, 72 hours for the full notification and a month for the final report.

In between sits the work without which a self-assessment is an empty form: mapping your processes and infrastructure, an ICT asset inventory, a risk assessment, a security policy and an incident response plan, and staff training. A domain name registration service provider does not owe this part, only the notification and the database.

What to do in the next few weeks

First, settle your status with two numbers, headcount and turnover, and check them against the sector list. Second, if you are a subject, appoint a cybersecurity manager; that person can sit outside your payroll. Third, prepare an ICT asset inventory, a risk assessment and an incident response plan, because without them a self-assessment is an empty form. Fourth, test your backups: supervisors look both at documents and at whether the technology actually does what the paperwork promises.

If you want a clear picture first, an IT audit shows where you stand against the requirements. The full service description with thresholds and deadlines is on the NIS2 compliance page, and if you are looking for someone to run the whole thing, that is outsourced IT support. The basics of the directive itself are in what is NIS2 and does it apply to your company.

Need the certificate itself?
Domain, business and wildcard certificates from Sectigo and partners, issued the same day, with free automatic renewal.
See what it costs

Ready to start?

Deploy in minutes or talk to an engineer about what fits your project.