Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation
Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 September 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential service provider (Article 20) or an important service provider (Article 21), which names an online marketplace, an online search engine and a social media platform service provider among the medium-or-large digital providers it reaches expressly, for the reason given on this jurisdiction's companion risk-management row; the reporting duty in Article 39 itself binds any person who discovers the vulnerability, not only a covered subject.
- Once the competent cyber incident prevention institution relays a substantiated report that a vulnerability exists in a system or network you operate, remediate it within the deadline the institution sets, no later than 90 days from when you received the information.
- Report your remediation progress to the institution as you go, and, if you cannot remediate within 90 days for objective reasons, request an extension, which the institution may grant up to a total of 180 days from the report's submission.
- Where you discover a vulnerability yourself in another subject's system, know that Article 39 lets you report it to the competent institution within five working days, anonymously if you choose, with your identity kept confidential.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
No provision reviewed here makes a missed Article 40 remediation deadline a criminal offence; Article 45 gives the competent authority non-monetary corrective powers (a warning, a corrective order, or, on continued non-compliance, suspension of the affected system, resource, product or service) generally, but Article 46(5)'s closed list of fine-triggering material non-compliance does not itself name a missed Article 40 deadline (see settledness.open_questions).
Who enforces it
Enforcement body
Nacionālais kiberdrošības centrs (National Cybersecurity Centre, NKDC, operating within the Ministry of Defence), as the Article 41(1) competent supervisory authority for an essential or important service provider other than information and communication technology (ICT) critical infrastructure; Satversmes aizsardzības birojs (Constitution Protection Bureau, SAB) for an owner or lawful possessor of ICT critical infrastructure under Article 41(2).
Settledness
- As of
- 15 September 2026
- Guidance link
- https://www.cyber.gov.lv/lv/nozares-politika/nacionalas-kiberdrosibas-likums-0
- Guidance body
- Nacionālais kiberdrošības centrs (National Cybersecurity Centre), Ministry of Defence of the Republic of Latvia
- Open questions
- Does Article 46(5)'s closed list of material non-compliance, which does not name a missed Article 40 vulnerability-remediation deadline, mean a subject who misses that deadline faces only the non-monetary corrective and suspension powers of Article 45 rather than the Article 46 fine?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 39 requires any person who discovers a vulnerability in a subject's information system or electronic communications network to report it to the competent cyber incident prevention institution within five working days, and lets that person report anonymously and have their identity kept confidential.
Once the institution has assessed a report as substantiated and relayed it, Article 40 requires the affected subject to take the actions necessary to remediate the vulnerability within the institution's own deadline, capped at 90 days from receiving the information and extendable to 180 days on the subject's request for objective reasons, reporting progress to the institution as it goes. This is a subject-facing remediation clock rather than only a state-run coordination function.
Article 46(5), however, defines a fine-triggering 'material non-compliance' with a closed three-item list (failing to take appropriate measures, repeatedly refusing supervisory information requests, and a late or false significant-incident notification) that does not name a missed Article 40 deadline, so whether that specific failure draws the Article 46 fine, rather than only the non-monetary corrective and suspension powers Article 45 gives generally, is not settled by the text and is recorded as an open question here rather than as a penalty figure.
When LexLint raises it
operates_social_platform