Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification
Lietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428 as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 18 October 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds the same essential and important cybersecurity subjects, including the internet-search-engine, online-marketplace and social-networking-service-platform "special subjects", as this jurisdiction's companion risk-management row.
- Notify NKSC of a significant cyber incident without delay and in any event within 24 hours of becoming aware of it.
- Follow within 72 hours of becoming aware with the incident's severity and impact assessment and any evidence of compromise; report a minor incident within 72 hours without a separate 24-hour early warning.
- Submit a final report within one month of the incident's registration, and an interim report on NKSC's request.
- Report to NKSC every cyber incident affecting you, not only a significant one, and every near-miss incident; if you have no statutory duty to report, you may still do so to NKSC voluntarily.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
NKSC's sanctions for a violation, including a failure to report, are administrative and judicial-order measures culminating in a fine, plus a district court order temporarily removing an essential entity's head from office on NKSC's request. No description of a reporting failure treats it as a criminal offence.
Penalty structure
The same enforcement ladder and fine ceiling that govern an Article 14 risk-management violation govern an Article 18 reporting violation: up to EUR 10,000,000 or up to 2 percent of total worldwide annual turnover, per the Ministry of National Defence's public guidance. Industry commentary reports a lower important-entity tier of up to EUR 7,000,000 or 1.4 percent of turnover, consistent with the NIS2 Article 34(5) floor; that report is not independently confirmed against the Law's own text.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Nacionalinis kibernetinio saugumo centras (NKSC, National Cyber Security Centre) under the Ministry of National Defence (Krašto apsaugos ministerija).
Settledness
- As of
- 14 September 2026
- Guidance link
- https://kam.lt/kibernetinio-saugumo-istatymas/
- Guidance body
- Krašto apsaugos ministerija (Ministry of National Defence)
- Open questions
- What does Article 18 require as the content of an incident notification, and what are Articles 30-31's fine amounts as they apply to a reporting failure specifically?
- Does the centralised national cyber-incident reporting and management platform the Ministry's guidance describes as still under construction change the reporting channel, form or clock once it launches?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 18 requires an essential or important cybersecurity subject to notify NKSC of a significant cyber incident without delay and not later than within 24 hours of becoming aware of it, then follow within 72 hours with an assessment of the incident's severity and impact and any evidence of compromise.
A final report is due within one month of the incident's registration, with NKSC able to request an interim report, and a minor incident is reported within 72 hours without a separate 24-hour early warning. The Law requires an essential or important subject to notify NKSC of every cyber incident affecting it, not only a significant one. A subject with no statutory duty to report may still notify NKSC of a cyber incident, threat or near-miss voluntarily.
NKSC is developing a centralised national cyber-incident reporting and management platform, not yet launched, under a single-window principle for NKSC, the Lithuanian police and the State Data Protection Inspectorate to coordinate on.
When LexLint raises it
operates_social_platform