Skip to main content
NIS2 · LATVIA

NIS2 in Latvia — one law, two bodies, and a named cybersecurity manager for every entity.

Latvia moved early: the National Cybersecurity Law was adopted on 20 June 2024 and entered into force on 1 September 2024, replacing the previous information-technology security law. The Commission nevertheless issued a reasoned opinion on 7 May 2025 over incomplete notification of transposition — a reminder that an in-force law and a settled transposition are not the same thing. The minimum-requirements detail sits in Cabinet Regulation No. 397, in force since 2 July 2025.

The structure is a deliberate split: supervision belongs to the National Cybersecurity Centre within the Ministry of Defence — with the Constitution Protection Bureau (SAB) overseeing ICT critical infrastructure — while CERT.LV, operated by the University of Latvia's Institute of Mathematics and Computer Science, serves as the national CSIRT. Registration, supervision and incident reporting therefore go to different doors, and the law adds a distinctly Latvian requirement: every in-scope entity must appoint a named cybersecurity manager and run an annual ICT security review.

Who it applies to

Essential and important entities across the NIS2 sectors. Self-assessment and registration were due by 1 April 2025, the approved entity list followed on 17 April 2025, and newly qualifying entities must register within one month. The first self-assessment report — together with notification of the appointed cybersecurity manager — was due by 1 October 2025. Incident reporting runs the directive's 24-hour, 72-hour and one-month stages (24-hour initial report for trust services), applicable since 1 July 2025.

The clock

Competent authority: National Cybersecurity Centre (Ministry of Defence). Transposition: National Cybersecurity Law (in force 1 September 2024).

NIS2 in Latvia · timeline
WhenWhat happens
1 Sep 2024National Cybersecurity Law enters into force
1 Apr 2025Self-assessment and registration deadline · entity list approved 17 Apr 2025
1 Jul 2025Incident-reporting provisions apply · Cabinet Regulation No. 397 in force 2 Jul 2025
1 Oct 2025First self-assessment report + cybersecurity-manager notification due

Regulator and CSIRT are different doors

Latvia rejected the combined-authority model: the National Cybersecurity Centre in the Ministry of Defence supervises, the Constitution Protection Bureau covers ICT critical infrastructure, and CERT.LV — institutionally part of a university institute — handles incidents. For an entity that means the registration record, the supervision relationship and the incident channel are three separate artifacts, and the named cybersecurity manager ties them together as the accountable person the regime expects to exist. TruSecure holds that separation as structure: each obligation routed to the correct authority, the manager appointment and annual review tracked as dated records, and the self-assessment cycle kept current against Cabinet Regulation No. 397 — so the split reads as clarity, not confusion.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Latvia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Latvia requirements · how TruSecure answers them
What the law asksWhere it is answered
Register and complete self-assessment (late if after 1 Apr 2025)Entity profile · registration and self-assessment held as records
Appoint a named cybersecurity managerGovernance workspace · appointment documented, training tracked
Run the annual ICT security reviewControl library · review cycle scheduled, evidence attached
Report incidents to CERT.LV: 24 h, 72 h, one monthIncident workflow · clocked from awareness, trust-service 24 h variant pre-built
Answer NCSC (or SAB) supervision with evidenceSupervision export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Latvia NIS2 readiness file · excerptSample data
Registration
NCSC · filed 28 Mar 2025
Cybersecurity manager
appointed · notified 15 Sep 2025
Annual ICT review
current · next due Oct 2026
Controls evidenced
68/89 · 21 open, each with an owner and a date
Export
sealed · sha256:3c9e...b571

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your routing across the NCSC, SAB and CERT.LV mapped per obligation, your cybersecurity-manager appointment documented, and the controls you already operate credited against Cabinet Regulation No. 397. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Latvia by National Cybersecurity Centre (Ministry of Defence). TruSecure determines applicability against Latvia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Does Latvia have separate CERT and NIS2 regulator bodies?
Yes — supervision sits with the National Cybersecurity Centre within the Ministry of Defence (with the Constitution Protection Bureau for ICT critical infrastructure), while CERT.LV, run by the University of Latvia's Institute of Mathematics and Computer Science, is the national CSIRT. TruSecure routes your registration, supervision and incident reporting to the correct body per obligation.