NIS2
Directive (EU) 2022/2555NIS2 raises the baseline of cybersecurity risk management across essential and important sectors. Entities must adopt technical and organisational measures proportionate to their risk — governance, incident handling, business continuity, supply-chain security, vulnerability handling, and the testing and auditing of those measures — and report significant incidents to the national authority. Management bodies are accountable and can be held liable.
In scope Medium and large organisations in the sectors the directive lists — energy, transport, banking and financial-market infrastructure, health, water, digital infrastructure, ICT service management and public administration as essential entities; postal, waste, chemicals, food, manufacturing, digital providers and research as important entities. In Latvia the duties come from the National Cybersecurity Law, in force since September 2024.