Law / Lithuania

Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures

Lietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428 as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 14

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 October 2024.

A sector security regimes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds a cybersecurity subject (essential or important entity) that NKSC has entered in the Cybersecurity Subjects Register under Annex 1 or Annex 2 of the Law, sector lists that reach, among others, an internet search engine, an online marketplace and a social-networking-service platform provider as a "special subject"; the wider sector classes the Annexes also reach (critical-infrastructure operators, energy, transport, health, finance, public administration and others) are a designation this vocabulary cannot express and are recorded here rather than flagged on an unrelated activity.
  • Adopt and keep current cybersecurity policy documents, periodically analyse and manage your cybersecurity risks, designate the persons responsible for cybersecurity, manage cybersecurity incidents and report on them, secure your supply chain, and deploy technical cybersecurity measures.
  • Designate a cybersecurity manager and/or security officer who organises your risk assessment and prepares your risk-assessment reports and risk-management plans for approval, and have your management body, head and designated representative complete cybersecurity training at least once every two years.
  • Follow the detailed technical and organisational measures the Government's Cybersecurity Requirements Description sets out; if you are newly registered, you have 12 months from registration to implement the organisational measures and 24 months to implement the technical measures.
  • Where you are a DNS service provider, top-level-domain registry, cloud service provider, data-centre service provider, content-delivery-network provider, managed service provider, managed security service provider, electronic-marketplace service provider, internet search engine or social-networking-service-platform provider, or a trust service provider, follow instead the cybersecurity risk-management measures of the European Commission's directly-applicable Implementing Regulation (EU) 2024/2690, binding from the moment you enter the Register rather than the Government's own Requirements Description.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

NKSC's sanctions for a violation are administrative and judicial-order measures, a graduated ladder of enforcement measures culminating in a fine, plus a district court order temporarily removing an essential entity's head from office on NKSC's request. No description of Article 14 treats its violation as a criminal offence.

Penalty structure

NKSC's public guidance states it may ultimately impose fines of up to EUR 10,000,000 or up to 2 percent of total worldwide annual turnover for a cybersecurity subject's failure to meet the Law's requirements, and separately states that the fines NKSC may impose "differ" in size, without stating the lower figure. Industry commentary reports a lower important-entity tier of up to EUR 7,000,000 or 1.4 percent of turnover, consistent with the floor NIS2 Article 34(5) itself sets; that report is not independently confirmed against the Law's own text.

Rule
Higher of
As of
14 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Nacionalinis kibernetinio saugumo centras (NKSC, National Cyber Security Centre) under the Ministry of National Defence (Krašto apsaugos ministerija), transposing the NIS2 Directive's competent-authority, single-point-of-contact and CSIRT designations.

Settledness

As of
14 September 2026
Guidance link
https://kam.lt/kibernetinio-saugumo-istatymas/
Guidance body
Krašto apsaugos ministerija (Ministry of National Defence)
Open questions
  • The Ministry's guidance states that the fines NKSC may impose differ by entity type without giving the lower figure: what are Articles 30 (Baudos) and 31's (Baudų skyrimo tvarka) fine amounts for an important entity specifically?
  • Does the centralised national cyber-incident reporting and management platform the Ministry's guidance describes as still under construction change the reporting channel or clock once it launches?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 14 requires a cybersecurity subject entered in NKSC's Cybersecurity Subjects Register under Annex 1 or Annex 2 of the Law to adopt and keep current cybersecurity policy documents, periodically analyse and manage its cybersecurity risks, designate the persons responsible for cybersecurity, manage cybersecurity incidents and report on them, secure its supply chain, and deploy technical cybersecurity measures.

The Government's Cybersecurity Requirements Description sets out the detailed technical and organisational measures Article 14 requires, with a 12-month grace period from registration for the organisational measures and 24 months for the technical measures. Article 14(7) separately requires the subject's management-body members, head and designated representative to complete cybersecurity training at least once every two years.

A named subset of digital-service "special subjects" includes a DNS service provider, a top-level-domain registry, a cloud or data-centre service provider, a content-delivery-network, managed-service or managed-cybersecurity-service provider, an electronic-marketplace provider, and an internet-search-engine or social-networking-service-platform provider.

A special subject or trust service provider must comply only with the European Commission's directly-applicable Implementing Regulation (EU) 2024/2690 risk-management measures from the moment of its own entry into the Register, under Article 14(4) of the Law. Only an essential entity's activity or services may be temporarily suspended, and only an essential entity's head may be temporarily removed from office by a district court order on NKSC's request.

When LexLint raises it

  • operates_social_platform

Read the law

Krašto apsaugos ministerija (Ministry of National Defence), public guidance FAQ on the Law on Cyber Security, kam.lt

Back to the example  ·  Lint your app