Article 21 of the NIS2 Directive lists ten cybersecurity risk-management measures. In Latvia two legal acts make them binding for the companies they cover. They are the National Cybersecurity Law (Nacionālās kiberdrošības likums, in force since 1 September 2024 and amended from 18 June 2026) and Cabinet Regulation No. 397 "Minimālās kiberdrošības prasības", in force since 2 July 2025. The regulation turns the ten measures into concrete duties, from four mandatory documents to multi-factor authentication, backup checks and clauses in supplier contracts.
This is a working checklist, not legal advice. The law leaves the responsibility with the company: the head of the subject ensures cybersecurity management and answers for it (Article 25 of the law).
Who has to do this
An essential service provider is a large company in a sector of high criticality: 250 or more employees, or turnover above 50 million EUR, or a balance sheet above 43 million EUR. An important service provider is a medium company in the same sectors, or a medium or large company in a second list of sectors such as postal services, waste management, food and manufacturing. The law counts a company as medium if it has up to 249 employees and a turnover or balance sheet of at least 10 million EUR; the official test of the Ministry of Defence, linked below, also treats any company with 50 to 249 employees as medium. A company with 12 people and 800 000 EUR of turnover is normally not a subject.
Size does not decide for companies, associations and foundations designated as significant for national security: from 1 October 2026 they are essential providers regardless of size. For a borderline case use the official test of the Ministry of Defence, and for a binding answer write to NIS2@mod.gov.lv. Our NIS2 page has a self-check with the thresholds.
Deadlines that come with the status
| Duty | Deadline | Where it is written |
|---|---|---|
| Notify the National Cybersecurity Centre of your status | Within one month of becoming a subject; changes within two weeks | Law, Article 22 |
| Appoint a cybersecurity manager | Within three months; report the name to the Centre and the Constitutional Protection Bureau within five working days | Law, Article 25 |
| Self-assessment report | Every three years by 1 October; every year for ICT critical infrastructure or if you run an A-class system; the first report within three months if you became a subject after 1 July | Law, Article 43; Regulation 397, points 141-143 |
Existing subjects had to register by 1 April 2025, and to name a manager and file the first self-assessment by 1 October 2025. If you missed those dates, register now rather than wait for a letter. The status form (Annex 1 of Regulation 397) is signed with a secure electronic signature and sent to the official e-address of the Ministry of Defence.
Incident reporting: 24 hours, 72 hours, one month
A subject that detects a cyber incident must act to stop it and inform the competent incident response institution without delay; for most companies that is CERT.LV at cert@cert.lv (Law, Article 34). For a significant incident the timeline is fixed:
- Early warning within 24 hours.
- Initial report within 72 hours (24 hours for a trust service provider).
- Final report within one month of the initial report. If it is not resolved by then, send a progress report and the final report after resolution; an intermediate report on request.
The forms are Annexes 10 to 14 of Regulation 397, signed with a secure electronic signature. Incidents that are not significant are reported by e-mail in free form. An incident is significant, among other criteria, when it disrupts the essential or important service, can harm someone's life or health, crosses borders, or causes losses of at least 500 000 EUR or 5% of last year's turnover, whichever is lower (point 118). Every incident goes into your incident log within 24 hours of detection (point 47), and customers who may be hit by a significant incident must be told what they can do to protect themselves.
The ten measures, mapped to Latvian rules
The letter in brackets refers to NIS2 Article 21(2).
1. Risk analysis and security policies (a)
Latvian rule: Law, Articles 27 and 28; Regulation 397, points 21-45.
In practice: a written cybersecurity policy, reviewed at least every three years; a catalogue of all ICT resources and information systems, each given a security class A, B or C; and a cyber risk management and ICT continuity plan with a risk method, a risk assessment that includes supply chain risks, and measures with owners and deadlines. An important provider reviews the plan at least every three years; an essential provider every two years, or every year if it runs an A-class system.
Evidence: the approved policy with its date, the catalogue with classes, the risk register with owners, and a record of the last review.
2. Incident handling (b)
Latvian rule: Law, Article 34; Regulation 397, points 46-48, 57-66 and 117-121.
In practice: named roles and written procedures to detect, log, contain and analyse incidents, near misses and vulnerabilities; the incident log; and system and network logs kept for at least 6, 12 or 18 months for C, B and A-class systems.
Evidence: the procedure, a contact list that includes CERT.LV, entries in the incident log, log retention settings and a record of a practice run.
3. Business continuity, backups and crisis management (c)
Latvian rule: Law, Article 28; Regulation 397, points 41-42 and 67-75.
In practice: recovery targets written for each system (RPO, RTO and maximum tolerable downtime), backups for every information system, an alert whenever a backup fails, and a check that the backup of a randomly chosen system can actually be read and restored, at least every six months for A-class systems and once a year for B-class. For an A-class system at least one full copy is kept in a geographically separate, protected place.
Evidence: the continuity plan, the backup schedule and logs, failed-backup alerts and dated restore test reports.
4. Supply chain security (d)
Latvian rule: Regulation 397, points 86-92.
In practice: no ICT supplier registered in Russia, Belarus or a state recognised as supporting terrorism, or owned, run or staffed on the service by their citizens, and no products made there. Before buying, assess the risks and plan an exit. The contract gives you the right to monitor the service and receive logs, and obliges the supplier to report incidents immediately, disclose subcontractors, keep confidentiality and delete or return your data at the end. The cybersecurity manager approves the contract before it is signed.
Evidence: a supplier list with risk ratings, contracts with these clauses and the manager's approval.
5. Secure acquisition, development and maintenance (e)
Latvian rule: Regulation 397, points 46, 88 and 131; Law, Articles 39 and 40 on coordinated vulnerability disclosure.
In practice: a process to find and fix vulnerabilities, updates installed on time and systems kept on software that still receives security fixes. Development contracts fix the support period and allow moving to newer versions of the software the system needs; an A-class system gets a penetration test before launch and at least every three years.
Evidence: patch reports, vulnerability scan results with closed tickets, and a list of unsupported software with replacement dates. A common entry right now is Windows Server 2016, whose support ends on 12 January 2027.
6. Checking that the measures work (f)
Latvian rule: Law, Articles 25(5), 43 and 44.
In practice: the cybersecurity manager runs an ICT security check at least once a year and organises the fixes, and the self-assessment report goes to the Centre on schedule. If the authority suspects a breach, it may audit you or order an external audit at your cost.
Evidence: the yearly check report with its fix list, the submitted self-assessment and any audit reports.
7. Cyber hygiene and training (g)
Latvian rule: Law, Articles 25(5) and 33; Regulation 397, points 76-80.
In practice: a first security briefing within one month of a person getting an account, a regular one at least once a calendar year, and extra briefings when a new threat appears; yearly training for IT staff; and at least yearly training for the cybersecurity manager run by the incident response institution.
Evidence: attendance records with dates, the training materials and test results.
8. Cryptography and encryption (h)
Latvian rule: Regulation 397, points 81-85.
In practice: where technically possible, encrypt A and B confidentiality information sent over public networks and over wireless networks, and encrypt stored A confidentiality information. Write down the minimum encryption strength and how keys are created, stored, changed and destroyed.
Evidence: the encryption rules, the key management procedure, and configuration proof for TLS, VPN and disk encryption.
9. Personnel security, access control and asset management (i)
Latvian rule: Law, Article 26.1 (since 18 June 2026); Regulation 397, points 30-38 and 49-56.
In practice: access rights by user group on need-to-know and least privilege; a decision process for hiring people with privileged access, with the right to request a criminal record certificate; an up-to-date catalogue of assets; and a segmented network with a separate guest network, isolated management interfaces and at least WPA2 on Wi-Fi.
Evidence: an access matrix, records of joiners and leavers, the asset catalogue and a network diagram.
10. Multi-factor authentication and secure communication (j)
Latvian rule: Regulation 397, point 52, plus the communication plans in point 46.
In practice: multi-factor authentication is mandatory for administrator and user accounts of A-class systems, for administrator accounts of B-class systems, and for B-class users who connect from outside without a VPN protected by multi-factor authentication. Plan how people will reach each other if e-mail and phones are down.
Evidence: a report showing where multi-factor authentication is enforced, a list of exceptions with reasons, and an emergency contact list that exists outside the systems it covers.
What non-compliance can cost
Fines for material non-compliance reach 10 million EUR for an essential provider and 7 million EUR for an important one, or 2% and 1.4% of turnover for companies with turnover above 500 million EUR. Not taking appropriate measures and not reporting a significant incident on time both count (Law, Article 46).
How CloudHosting helps
We do not sell "NIS2 compliance", because no provider can take that duty over: the law keeps it with your company and its head. What we can do is make individual measures real and provable.
- Gap audit. An IT audit from 200 EUR as a fixed fee checks your network, backups, access and NIS2 readiness and ranks the fixes.
- Documents. Policy, ICT catalogue, risk and continuity plan and incident procedures written for your company, not copied from a template. See NIS2 and the National Cybersecurity Law.
- Infrastructure measures. Servers in our Riga data centre, which we run ourselves, so the location and the operator of every server are known; backups with written recovery targets and tested restores; FortiGate firewalls, VPN and segmentation as an authorised Fortinet partner; and monitoring and incident response 24/7, with engineers answering on working days 9:00-17:00 Riga time. See IT infrastructure for companies.