NIS2 in Lithuania — no self-registration, a defense-ministry regulator, and clocks that run from notification.
Lithuania effectively met the directive deadline: the amended Law on Cyber Security entered into force on 18 October 2024, one day after the EU transposition date, with the recast implementing Government Resolution following on 12 November 2024. The regime is run by the National Cyber Security Centre (NKSC) under the Ministry of National Defence — sole competent authority, single point of contact, and operator of CERT-LT.
The distinctive choice is that entities do not register themselves. NKSC identifies essential and important entities, compiled the initial list by 17 April 2025 — 1,443 entities were notified, against NKSC estimates of 8,000–10,000 ultimately in scope — and notifies each entity electronically at the address recorded in the Register of Legal Entities. The register is reviewed annually and is not public.
Who it applies to
Entities identified by NKSC as essential or important across the NIS2 sectors. Because there is no self-registration, the operative fact is inclusion in the NKSC list: from notification, entities have 12 months to implement organizational measures and 24 months for technical measures. Incident reporting follows the directive standard — 24-hour early warning, 72-hour notification, one-month final report — and sanctions reach EUR 10 million or 2% of global turnover, with possible management disqualification.
The clock
Competent authority: NKSC (National Cyber Security Centre, Ministry of National Defence). Transposition: Law on Cyber Security, as amended (in force 18 October 2024).
| When | What happens |
|---|---|
| 18 Oct 2024 | Amended Law on Cyber Security enters into force |
| 12 Nov 2024 | Recast implementing Government Resolution in force |
| 17 Apr 2025 | NKSC initial entity list compiled · 1,443 entities notified |
| From notification | 12 months organizational measures · 24 months technical measures |
The authority finds you
Most transpositions make the entity work out its own position and register. Lithuania inverted it: NKSC owns the list, notifies electronically, and the compliance clocks — 12 months for organizational measures, 24 for technical — run from that notification, not from the law. The register is not public, so an entity cannot check a neighbour's status, and the initial 1,443 notifications against an 8,000–10,000 estimate mean the list is still growing into the estimate. Waiting to be notified is not a strategy either: the obligations are sized by the entity's facts, and the notification only starts the clock on work that the directive already assumes. TruSecure runs the applicability analysis against the directive today, then holds NKSC inclusion as a tracked, dated fact — so the 12- and 24-month clocks are pre-planned before they start, not discovered after.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Lithuania transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Determine scope before NKSC notifies | Applicability engine · sector and threshold analysis against the directive |
| Track inclusion in the NKSC list | Compliance workspace · notification held as a dated, clock-starting fact |
| Implement organizational measures within 12 months | Governance workspace · measures mapped, ownership assigned |
| Implement technical measures within 24 months | Control library · phased plan, evidence attached |
| Report incidents to CERT-LT: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- NKSC list status
- notified 29 Apr 2025 · important entity
- Organizational measures
- due 29 Apr 2026 · on plan
- Technical measures
- due 29 Apr 2027 · phased, 60% evidenced
- Incident reports
- 0 filed · workflow tested quarterly
- Export
- sealed · sha256:8d1b...44e9
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your position against NKSC's identification criteria, your 12- and 24-month clocks pre-planned from notification, and the controls you already operate credited where they genuinely apply. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Lithuania by NKSC (National Cyber Security Centre, Ministry of National Defence). TruSecure determines applicability against Lithuania's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.