Alessandro AleddaInsider Threat and Risk

ITER/LVLatvia

What the record establishes for Latvia: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
None recorded
NIS2
In force 1 September 2024, by article 64
Terms moved
Yes
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Data State Inspectorate reportededpb members
CSIRT or competent authorityNIS2, article 23The competent cyber incident prevention institution, which article 34 names by function reported

Electronically, under article 34(2) and (3), and there is no portal. The Cabinet of Ministers sets the forms: early warning, initial report, progress report, interim report and final report. It each is filled in, signed with a secure electronic signature and sent to the institution's address, cert@cert.lv or cert@cert.gov.lv. The parties may agree to encrypt with PGP or to identify with eParaksts.

lv nacionalas kiberdrosibas likums · cert lv riciba
Financial supervisorDORA, article 19Latvijas Banka reportedeba competent authorities
Market authorityMAR, article 17Latvijas Banka reportedesma mar nca

Transposition of NIS2 binding

ActNacionālās kiberdrošības likums
In force1 September 2024, by article 64. Adopted by the Saeima on 20 June 2024, and amended on 4 June 2026 with effect from 18 June 2026.
RecipientThe competent cyber incident prevention institution, which article 34 names by function
Moves a termYes. The hours are the Directive's. The point they run from is not stated. Article 34(2) reads «Nozīmīga kiberincidenta gadījumā subjekts nekavējoties, bet ne vēlāk kā 24 stundu laikā ... iesniedz ... agrīno brīdinājumu», and 34(3) puts the initial report at seventy-two hours, twenty-four for a trust service provider, in the same construction. Neither names an anchor. The nearest thing to one is 34(1), which speaks of «Konstatējot kiberincidentu», on establishing a cyber incident. The final report keeps the Directive's measure: «mēneša laikā pēc šā panta trešajā daļā minētā ziņojuma iesniegšanas», one month after the initial report, with a progress report where the incident cannot be resolved in time and the final report after it is.
StandingRead in the act on Likumi.lv, in the version in force. An organization in Latvia holds the intervals and has to supply the starting point from somewhere else. Whether konstatējot in 34(1) carries into 34(2) is a question of Latvian construction that this record does not answer.
Sourcelv nacionalas kiberdrosibas likums

An event in Latvia

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.