Law / Latvia

Nacionālās kiberdrošības likums, Incident Notification

Nacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pants

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 July 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds an essential service provider (Article 20) or an important service provider (Article 21), which names an online marketplace, an online search engine and a social media platform service provider among the medium-or-large digital providers it reaches expressly, for the reason given on this jurisdiction's companion risk-management row.
  • Immediately take all action necessary to contain a detected cyber incident, immediately inform the competent cyber incident prevention institution (in practice CERT.LV for most private-sector and civilian public-sector subjects), and follow its instructions.
  • For a significant cyber incident, electronically submit an early warning to the competent institution without delay and no later than within 24 hours of becoming aware of it.
  • Follow with an initial report within 72 hours of becoming aware (within 24 hours instead, if you are a trust service provider).
  • Within one month of the initial report, submit a final report on the incident's resolution, or, if it is still unresolved at that point, a progress report followed by a final report once you have resolved it; submit an intermediate report if the competent institution requests one.
  • Where relevant, immediately inform your service recipients, including affected network or system users, of protective measures they can take, and, after coordinating with the competent institution, inform them of the significant incident or threat itself, unless disclosure would create a new significant-incident risk or conflict with national security.
  • Know that this notification clock did not itself bind until 1 July 2025, under the Law's own transitional provisions, even though the Law commenced on 1 September 2024.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 46's penalty for an Article 34 non-compliance (a late or knowingly false significant-incident notification is one of Article 46(5)'s three enumerated grounds) is an administrative fine the National Cybersecurity Centre or the Constitution Protection Bureau imposes directly; no provision reviewed here makes a failure to notify a criminal offence.

Penalty structure

Article 46(1) sets the essential-entity ceiling at EUR 10,000,000 or, where the entity's total net turnover for the last financial year exceeds EUR 500,000,000, up to 2 percent of that turnover, mirroring NIS2 Article 34(4). Article 46(2) sets the important-entity ceiling at EUR 7,000,000 or, above the same EUR 500,000,000 turnover gate, up to 1.4 percent, mirroring NIS2 Article 34(5). Article 46(3) applies the essential-entity tier to an owner or lawful possessor of ICT critical infrastructure through the Constitution Protection Bureau. The fine reaches only a 'material non-compliance' as Article 46(5) defines it, which includes a subject's failure to take the appropriate and proportionate measures this row's own Article 27 duty requires.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Nacionālais kiberdrošības centrs (National Cybersecurity Centre, NKDC, operating within the Ministry of Defence), as the Article 41(1) competent supervisory authority for an essential or important service provider other than information and communication technology (ICT) critical infrastructure; Satversmes aizsardzības birojs (Constitution Protection Bureau, SAB) for an owner or lawful possessor of ICT critical infrastructure under Article 41(2).

Settledness

As of
15 September 2026
Guidance link
https://www.cyber.gov.lv/lv/nozares-politika/nacionalas-kiberdrosibas-likums-0
Guidance body
Nacionālais kiberdrošības centrs (National Cybersecurity Centre), Ministry of Defence of the Republic of Latvia
Open questions
Has the Cabinet approved the significance criteria for a 'nozīmīgs kiberincidents' (significant cyber incident) that Article 36(1) requires, and does that regulation set a threshold an online marketplace, search engine or social media platform provider can apply directly to its own incidents?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 34 requires a subject to notify the competent cyber incident prevention institution immediately of any cyber incident and to follow its instructions.

For a significant cyber incident, the subject must submit an early warning within 24 hours of becoming aware, an initial report within 72 hours (24 hours for a trust service provider), and, within one month of the initial report, a final report (or, if unresolved, a progress report followed by a final report once resolved); where relevant, the subject must also inform affected service recipients of protective measures and, after coordinating with the institution, of the incident itself.

This is NIS2 Article 23's own clock. Although the Law commenced 1 September 2024, its transitional provisions delayed Article 34's paragraphs two through five, the notification clock itself, until 1 July 2025.

For most private-sector and civilian public-sector subjects the competent cyber incident prevention institution is the Institute of Mathematics and Computer Science of the University of Latvia, which operates publicly as CERT.LV; the Military Intelligence and Security Service holds the same role for the defence sector. A missed or knowingly false notification is one of Article 46(5)'s three enumerated grounds for a material non-compliance fine.

When LexLint raises it

  • operates_social_platform

Read the law

Nacionālās kiberdrošības likums (National Cybersecurity Law), consolidated text in force 18.06.2026-30.09.2026, likumi.lv, Article 34

Back to the example  ·  Lint your app