Law / Latvia

Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures

Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024, redakcija uz 18.06.2026), 25.-28. panti

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 September 2024.

A sector security regimes rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds an essential service provider (Article 20) or an important service provider (Article 21), which names an online marketplace, an online search engine and a social media platform service provider (Article 21(1)(2)(l)-(n)) among the medium-or-large digital providers it reaches expressly; the wider sector classes both Articles also reach (energy, transport, health, finance, drinking water, a large or medium cloud, content-delivery-network, data-centre or domain-name-system provider, and direct and indirect public administration) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
  • Take appropriate and proportionate technical and organisational measures to manage the cyber risks to the security of the electronic communications networks and information systems you use, and to prevent or minimise to the greatest extent possible the impact of a cyber incident on your service recipients and on other services.
  • Draft a cyber-risk-management and ICT-business-continuity plan and give your staff regular training on carrying it out; the plan's required content and the minimum cybersecurity requirements your systems must meet are set by Cabinet Regulation No. 397 of 25 June 2025, 'Minimālās kiberdrošības prasības'.
  • Have your head or governing body appoint a cybersecurity manager within three months of notifying your essential- or important-provider status, and notify the National Cybersecurity Centre and the Constitution Protection Bureau of the appointment within five working days.
  • Since 18 June 2026, screen a staff member with privileged access to your ICT systems against a criminal-record check for a listed offence (terrorism, an offence against the state, or an offence against property or the economy) before assigning them that access, unless they are rehabilitated or their conviction has been expunged.
  • Where you are a financial entity already covered by Regulation (EU) 2022/2554 (DORA), or covered by another sector-specific EU cybersecurity regime with at least equivalent requirements, expect this duty to give way to that regime's own risk-management rules under Article 3(3)-(4).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 46's penalty for a material non-compliance with Article 27 or 28 is an administrative fine (soda nauda) the National Cybersecurity Centre or the Constitution Protection Bureau imposes directly; no provision reviewed here makes the underlying non-compliance a criminal offence.

Penalty structure

Article 46(1) sets the essential-entity ceiling at EUR 10,000,000 or, where the entity's total net turnover for the last financial year exceeds EUR 500,000,000, up to 2 percent of that turnover, mirroring NIS2 Article 34(4). Article 46(2) sets the important-entity ceiling at EUR 7,000,000 or, above the same EUR 500,000,000 turnover gate, up to 1.4 percent, mirroring NIS2 Article 34(5). Article 46(3) applies the essential-entity tier to an owner or lawful possessor of ICT critical infrastructure through the Constitution Protection Bureau. The fine reaches only a 'material non-compliance' as Article 46(5) defines it, which includes a subject's failure to take the appropriate and proportionate measures this row's own Article 27 duty requires.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Nacionālais kiberdrošības centrs (National Cybersecurity Centre, NKDC, operating within the Ministry of Defence), as the Article 41(1) competent supervisory authority for an essential or important service provider other than information and communication technology (ICT) critical infrastructure; Satversmes aizsardzības birojs (Constitution Protection Bureau, SAB) for an owner or lawful possessor of ICT critical infrastructure under Article 41(2).

Settledness

As of
15 September 2026
Guidance link
https://www.cyber.gov.lv/lv/nozares-politika/nacionalas-kiberdrosibas-likums-0
Guidance body
Nacionālais kiberdrošības centrs (National Cybersecurity Centre), Ministry of Defence of the Republic of Latvia
Open questions
Does Cabinet Regulation No. 397 of 25 June 2025, which sets the Article 26 minimum cybersecurity requirements, narrow the Article 27 measures duty specifically as it reaches an online marketplace, online search engine or social media platform provider?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 27 requires a subject (an essential service provider under Article 20, an important service provider under Article 21, or an owner or lawful possessor of ICT critical infrastructure) to take appropriate and proportionate technical and organisational measures to manage the cyber risks to the security of the electronic communications networks and information systems it uses, and to prevent or minimise the impact of a cyber incident on its service recipients and on other services.

Article 21(1)(2)(l)-(n) names an online marketplace, an online search engine and a social media platform provider expressly among the medium-or-large digital providers this duty reaches as important entities.

Article 28 additionally requires the subject to draft a cyber-risk-management and ICT-business-continuity plan and to train staff on it, with the plan's required content and the minimum cybersecurity requirements the subject's systems must meet set by Cabinet Regulation No. 397 of 25 June 2025; Article 25 requires the subject's head to appoint a cybersecurity manager (kiberdrošības pārvaldnieks) within three months of the subject's status notification, and Article 26.1, inserted by the amendment in force since 18 June 2026, adds a criminal-record screening duty for ICT staff with privileged system access.

Article 3(3)-(4) exempts a financial entity already covered by Regulation (EU) 2022/2554 (DORA), and any subject covered by an equivalent sector-specific EU cybersecurity regime, from these provisions to the extent that regime's own requirements are at least equivalent.

When LexLint raises it

  • operates_social_platform

Read the law

Nacionālās kiberdrošības likums (National Cybersecurity Law)
consolidated text in force 18.06.2026-30.09.2026, likumi.lv, Articles 20, 21, 25-28

Back to the example  ·  Lint your app