Lithuania's NIS2 transposition is enacted and in force. The Lietuvos Respublikos kibernetinio saugumo įstatymo Nr. XII-1428 pakeitimo įstatymas (the Law amending the Republic of Lithuania's Law on Cyber Security No. XII-1428), Document No. XIV-2902, was adopted by the Seimas on 11 July 2024, published in the Register of Legal Acts (TAR) on 24 July 2024, and entered into force on 18 October 2024.
It restates the Law on Cyber Security in a new consolidated wording that transposes NIS2 (Directive (EU) 2022/2555).
Article 14 requires a cybersecurity subject (essential or important entity, kibernetinio saugumo subjektas), identified against the Annex 1 and Annex 2 sector lists that the National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras, NKSC, under the Ministry of National Defence) maintains in a Cybersecurity Subjects Register, to adopt cybersecurity policy documents, periodically analyse and manage its cybersecurity risks, designate a cybersecurity manager and/or security officer, manage and report cybersecurity incidents, secure its supply chain, and deploy technical cybersecurity measures, detailed further in the Government's Cybersecurity Requirements Description (Kibernetinio saugumo reikalavimų aprašas, Government Resolution No. 818 of 13 August 2018, as restated) with a 12-month grace period for organisational measures and 24 months for technical measures from an entity's own registration date.
A named subset of digital-service "special subjects" (specialieji subjektai), including a DNS service provider, a top-level-domain registry, a cloud or data-centre service provider, a content-delivery-network or managed-service provider, an electronic-marketplace provider, and an internet-search-engine or social-networking-service-platform provider, follow instead the directly-applicable European Commission Implementing Regulation (EU) 2024/2690, in force since 7 November 2024.
Article 18 requires the same essential and important entities to notify NKSC of a significant cyber incident within 24 hours of becoming aware of it, follow within 72 hours with a severity and impact assessment and any evidence of compromise, and submit a final report within one month of the incident's registration; Lithuania's transposition extends the reporting duty beyond NIS2's own floor by also requiring notice of a minor incident, within 72 hours, and of a near-miss, and by letting a subject with no statutory duty report voluntarily.
NKSC enforces both duties through a graduated ladder of NKSC-ordered measures culminating in a fine of up to EUR 10,000,000 or up to 2 percent of total worldwide annual turnover, and, for an essential entity only, temporary suspension of part or all of its activity or right to provide services, or temporary removal of its head from office by order of a district court on NKSC's request.
Industry commentary reports a lower important-entity fine tier of up to EUR 7,000,000 or 1.4 percent of turnover, consistent with the floor NIS2 Article 34(5) itself sets; that report is not independently confirmed against the Law's own text.
Personal-data breach notification under General Data Protection Regulation (GDPR) Articles 33 and 34 is separate law that sits in the privacy topic rather than here. e-seimas.lrs.lt, the Seimas legal-acts register, returns an HTTP 522 origin-server error; e-tar.lt, the Official Gazette register, and nksc.lt, NKSC's own site, both return an HTTP 403 despite resolving their Cloudflare challenge; and infolex.lt disallows every path in robots.txt. The Ministry of National Defence, which formed and administers Lithuania's cybersecurity policy, publishes public guidance on the Law at kam.lt.