$
./attiffet laws.sh
[OSI-style layers · L7 → L1 · from the international framework to technical implementation]
Legislation in clear language.
Latvian and European Union cybersecurity package, which applies to information systems. Acti arranged in OSI model layers: from the top of the abstract frame to the technical implementation at the bottom.
L7
NIS 2
A common EU cybersecurity framework
Directive (EU) 2022/2555 - Security of network and information systems
Set a common framework for high level cyber security requirements in the European Union. Defines relevant and important entities in 18 sectors (energy, transport, banking, healthcare, digital infrastructure, etc.), cybersecurity risk management measures and incident reporting obligations. This is a directive, so each Member State transposes it into national law.
Detailed: L4 · Covers with L6 sectors · LV transposition: L2
L6
DORA · Part-IS · NCCS
Directly applicable EU financial, aviation and energy legislation
Sector specific EU regulations
These European Union laws are directly applicable in Latvia, not transposed by the National Cybersecurity Law. NKDL aviation and energy are only covered as NIS 2 sectors, without sectoral technical requirements. Each act has a separate legal basis. DORA (Regulation (EU) 2022/2554) in the financial sector is a lex specialis in relation to NIS 2 and provides for ICT risk management, incident reporting and third party supervision. Part-IS (Regulation (EU) 2023/203 and 2022/1645) applies to EASA regulated organisations on the basis of EASA Framework Regulation (EU) 2018/1139. NCCS (Regulation (EU) 2024/1366) determines cyber security of cross-border flows of electricity on the basis of the Electricity Market Regulation (EU) 2019/943.
Complements L7 sectors · NOT includes L2 NKDL (directly applicable EU acts)
L5
CRA
Security of digital products
Regulation (EU) 2024/2847 - Cyber Resilience Act
Defines cyber security requirements for products with digital features. Equipment and software must be safe by default and development principle, with security updates throughout the product life cycle. The CE marking now confirms not only the physical but also cyber security of the product.
Parallel: L7 (products, not services)
L4
Reg. (EU) 2024/2690
Technical and methodological conditions for NIS 2
Commission Implementing Regulation (EU) 2024/2690
Specify NIS 2 risk management measures and incident reporting criteria for digital service providers (cloud services, data centres, DNA, content delivery networks, online outlets, etc.). The Regulation is directly applicable without transposition into national law.
Base: L7 (technical detail)
L3
VDAR (GDPR)
Protection of personal data
Regulation (EU) 2016/679 - General Data Protection Regulation (EU) 2016/679
Protects personal data. The processing of personal data requires a legal basis, the data subject must be informed and the data deleted upon request. The personal data breach shall be reported to the Data State Inspectorate within 72 hours.
Coating with: L7 (incident reporting)
L2
NKDL
Acquisition of NIS 2 in Latvia
National Cybersecurity Law
Latvian law transposing the NIS 2 Directive. Defines essential and important services in Latvia, incident reporting procedures (CERT.LV), competent authorities (National Cyber Security Centre) and responsibilities and responsibilities of entities.
Base: L7 · Technical performance: L1
L1
MK 397
Minimum cyber security requirements
Cabinet Regulation No 397
Minimum technical and organisational cyber security requirements shall be established. These include password policies (at least 12 characters), multifactor authentication for staff, event logging, software updates, security testing and backup copies. These requirements in practice ensure fulfilment of the obligations set out in the National Cybersecurity Law.
Base: L2
// DISCLAIMER:
Clarifications are informative and no legal advice. In a specific case, you should consult the official legislation or the specialist.