Skip to main content
NIS2 · LITHUANIA

NIS2 in Lithuania — no self-registration, a defense-ministry regulator, and clocks that run from notification.

Lithuania effectively met the directive deadline: the amended Law on Cyber Security entered into force on 18 October 2024, one day after the EU transposition date, with the recast implementing Government Resolution following on 12 November 2024. The regime is run by the National Cyber Security Centre (NKSC) under the Ministry of National Defence — sole competent authority, single point of contact, and operator of CERT-LT.

The distinctive choice is that entities do not register themselves. NKSC identifies essential and important entities, compiled the initial list by 17 April 2025 — 1,443 entities were notified, against NKSC estimates of 8,000–10,000 ultimately in scope — and notifies each entity electronically at the address recorded in the Register of Legal Entities. The register is reviewed annually and is not public.

Who it applies to

Entities identified by NKSC as essential or important across the NIS2 sectors. Because there is no self-registration, the operative fact is inclusion in the NKSC list: from notification, entities have 12 months to implement organizational measures and 24 months for technical measures. Incident reporting follows the directive standard — 24-hour early warning, 72-hour notification, one-month final report — and sanctions reach EUR 10 million or 2% of global turnover, with possible management disqualification.

The clock

Competent authority: NKSC (National Cyber Security Centre, Ministry of National Defence). Transposition: Law on Cyber Security, as amended (in force 18 October 2024).

NIS2 in Lithuania · timeline
WhenWhat happens
18 Oct 2024Amended Law on Cyber Security enters into force
12 Nov 2024Recast implementing Government Resolution in force
17 Apr 2025NKSC initial entity list compiled · 1,443 entities notified
From notification12 months organizational measures · 24 months technical measures

The authority finds you

Most transpositions make the entity work out its own position and register. Lithuania inverted it: NKSC owns the list, notifies electronically, and the compliance clocks — 12 months for organizational measures, 24 for technical — run from that notification, not from the law. The register is not public, so an entity cannot check a neighbour's status, and the initial 1,443 notifications against an 8,000–10,000 estimate mean the list is still growing into the estimate. Waiting to be notified is not a strategy either: the obligations are sized by the entity's facts, and the notification only starts the clock on work that the directive already assumes. TruSecure runs the applicability analysis against the directive today, then holds NKSC inclusion as a tracked, dated fact — so the 12- and 24-month clocks are pre-planned before they start, not discovered after.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Lithuania transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Lithuania requirements · how TruSecure answers them
What the law asksWhere it is answered
Determine scope before NKSC notifiesApplicability engine · sector and threshold analysis against the directive
Track inclusion in the NKSC listCompliance workspace · notification held as a dated, clock-starting fact
Implement organizational measures within 12 monthsGovernance workspace · measures mapped, ownership assigned
Implement technical measures within 24 monthsControl library · phased plan, evidence attached
Report incidents to CERT-LT: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Lithuania NIS2 readiness file · excerptSample data
NKSC list status
notified 29 Apr 2025 · important entity
Organizational measures
due 29 Apr 2026 · on plan
Technical measures
due 29 Apr 2027 · phased, 60% evidenced
Incident reports
0 filed · workflow tested quarterly
Export
sealed · sha256:8d1b...44e9

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your position against NKSC's identification criteria, your 12- and 24-month clocks pre-planned from notification, and the controls you already operate credited where they genuinely apply. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Lithuania by NKSC (National Cyber Security Centre, Ministry of National Defence). TruSecure determines applicability against Lithuania's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

What is Lithuania's national NIS2 authority?
NKSC, the National Cyber Security Centre under the Ministry of National Defence — Lithuania's Baltic-region posture means its guidance and enforcement tend to run ahead of the EU baseline given proximity-driven threat awareness.