Latvia's NIS2 transposition, the Nacionālās kiberdrošības likums (National Cybersecurity Law, NKDL), was adopted by the Saeima on 20 June 2024, published in Latvijas Vēstnesis (128A, 04.07.2024), and entered into force on 1 September 2024; its own transitional provisions repealed the prior Informācijas tehnoloģiju drošības likums (Information Technology Security Law, the 2010 NIS1 transposition) outright on the same date, so no predecessor regime survives alongside it.
The version in force as of this review reflects amendments enacted 4 June 2026 that took effect 18 June 2026, with a further, narrower tranche (adding a national-security ownership category to Article 20) due to take effect 1 October 2026 and not yet reflected in the displayed text.
The Law binds a būtisko pakalpojumu sniedzējs (essential service provider, Article 20) or svarīgo pakalpojumu sniedzējs (important service provider, Article 21) by sector and, for most sectors, a large- or medium-enterprise size gate; Article 21(1)(2)(l)-(n) names an online marketplace, an online search engine and a social media platform provider expressly among the medium-or-large digital providers it reaches, and Article 20(8)(s)-(v) separately reaches a large cloud-computing, content-delivery-network, data-centre or domain-name-system provider as essential (with the medium tier of the same list important under Article 21(1)(1)), a sector class no activity in this vocabulary expresses.
The Law also binds direct and indirect state and municipal administration and other public-law bodies (Article 3(1)(2), Article 20(5)(6)(10)), excluding the state security services, so it reaches a government duty-bearer as well as a private one.
Article 27 sets the core risk-management duty (appropriate and proportionate technical and organisational measures), Article 28 requires a written cyber-risk-management and ICT-business-continuity plan with staff training, and Article 26 has the Cabinet set the minimum cybersecurity requirements the plan must meet, done by Cabinet Regulation No. 397 of 25 June 2025; a personnel-security screening duty for ICT staff with privileged access, Article 26.1, was inserted by the 2026 amendment.
Article 34 sets NIS2's own graduated incident-notification clock to the competent cyber incident prevention institution (an early warning within 24 hours, an initial report within 72 hours, a final report within one month), but that clock did not itself bind until 1 July 2025 under the Law's transitional provisions, nine months after the Law's own commencement.
Articles 39 and 40 add a coordinated-vulnerability-disclosure regime distinct from Article 34: any person who discovers a vulnerability in a subject's system must report it within five working days, and the subject must then remediate within a deadline the institution sets, capped at 90 days and extendable to 180 days on request; Article 46's fine, however, defines 'material non-compliance' by a closed three-item list that does not name a missed Article 40 remediation deadline, an open question flagged below rather than an unsupported penalty figure for that duty.
Supervision splits between the Nacionālais kiberdrošības centrs (National Cybersecurity Centre, NKDC, within the Ministry of Defence), which is the Article 41 competent authority for essential and important service providers generally and receives most subjects' incident and vulnerability reports through the Institute of Mathematics and Computer Science of the University of Latvia (the body that operates publicly as CERT.LV), and the Satversmes aizsardzības birojs (Constitution Protection Bureau, SAB), which holds the same role for an owner or lawful possessor of ICT critical infrastructure.
Article 46 sets NIS2's own two-tier fine, up to EUR 10,000,000 or, above EUR 500,000,000 turnover, 2 percent of turnover for an essential entity, and up to EUR 7,000,000 or 1.4 percent for an important entity, imposed directly by NKDC or SAB as an administrative fine with no criminal offence and no private right of action, appealable to court by the subject under the Administrative Procedure Law.
No Latvian instrument reviewed here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Latvia has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33-34 and the Fizisko personu datu apstrādes likums sits in the privacy topic rather than here.
Article 3(3)-(4) exempts a financial entity already subject to Regulation (EU) 2022/2554 (DORA), and any essential or important service provider covered by an equivalent sector-specific EU cybersecurity regime, from the Law's risk-management and supervision provisions to the extent that regime's own requirements are at least equivalent.