NIS2 in Latvia — one law, two bodies, and a named cybersecurity manager for every entity.
Latvia moved early: the National Cybersecurity Law was adopted on 20 June 2024 and entered into force on 1 September 2024, replacing the previous information-technology security law. The Commission nevertheless issued a reasoned opinion on 7 May 2025 over incomplete notification of transposition — a reminder that an in-force law and a settled transposition are not the same thing. The minimum-requirements detail sits in Cabinet Regulation No. 397, in force since 2 July 2025.
The structure is a deliberate split: supervision belongs to the National Cybersecurity Centre within the Ministry of Defence — with the Constitution Protection Bureau (SAB) overseeing ICT critical infrastructure — while CERT.LV, operated by the University of Latvia's Institute of Mathematics and Computer Science, serves as the national CSIRT. Registration, supervision and incident reporting therefore go to different doors, and the law adds a distinctly Latvian requirement: every in-scope entity must appoint a named cybersecurity manager and run an annual ICT security review.
Who it applies to
Essential and important entities across the NIS2 sectors. Self-assessment and registration were due by 1 April 2025, the approved entity list followed on 17 April 2025, and newly qualifying entities must register within one month. The first self-assessment report — together with notification of the appointed cybersecurity manager — was due by 1 October 2025. Incident reporting runs the directive's 24-hour, 72-hour and one-month stages (24-hour initial report for trust services), applicable since 1 July 2025.
The clock
Competent authority: National Cybersecurity Centre (Ministry of Defence). Transposition: National Cybersecurity Law (in force 1 September 2024).
| When | What happens |
|---|---|
| 1 Sep 2024 | National Cybersecurity Law enters into force |
| 1 Apr 2025 | Self-assessment and registration deadline · entity list approved 17 Apr 2025 |
| 1 Jul 2025 | Incident-reporting provisions apply · Cabinet Regulation No. 397 in force 2 Jul 2025 |
| 1 Oct 2025 | First self-assessment report + cybersecurity-manager notification due |
Regulator and CSIRT are different doors
Latvia rejected the combined-authority model: the National Cybersecurity Centre in the Ministry of Defence supervises, the Constitution Protection Bureau covers ICT critical infrastructure, and CERT.LV — institutionally part of a university institute — handles incidents. For an entity that means the registration record, the supervision relationship and the incident channel are three separate artifacts, and the named cybersecurity manager ties them together as the accountable person the regime expects to exist. TruSecure holds that separation as structure: each obligation routed to the correct authority, the manager appointment and annual review tracked as dated records, and the self-assessment cycle kept current against Cabinet Regulation No. 397 — so the split reads as clarity, not confusion.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Latvia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register and complete self-assessment (late if after 1 Apr 2025) | Entity profile · registration and self-assessment held as records |
| Appoint a named cybersecurity manager | Governance workspace · appointment documented, training tracked |
| Run the annual ICT security review | Control library · review cycle scheduled, evidence attached |
| Report incidents to CERT.LV: 24 h, 72 h, one month | Incident workflow · clocked from awareness, trust-service 24 h variant pre-built |
| Answer NCSC (or SAB) supervision with evidence | Supervision export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Registration
- NCSC · filed 28 Mar 2025
- Cybersecurity manager
- appointed · notified 15 Sep 2025
- Annual ICT review
- current · next due Oct 2026
- Controls evidenced
- 68/89 · 21 open, each with an owner and a date
- Export
- sealed · sha256:3c9e...b571
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your routing across the NCSC, SAB and CERT.LV mapped per obligation, your cybersecurity-manager appointment documented, and the controls you already operate credited against Cabinet Regulation No. 397. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Latvia by National Cybersecurity Centre (Ministry of Defence). TruSecure determines applicability against Latvia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.