$ ./attiffet laws.sh

[OSI-style layers · L7 → L1 · from the international framework to technical implementation]

Legislation in clear language. Latvian and European Union cybersecurity package, which applies to information systems. Acti arranged in OSI model layers: from the top of the abstract frame to the technical implementation at the bottom.
L7
NIS 2 A common EU cybersecurity framework

Directive (EU) 2022/2555 - Security of network and information systems

Set a common framework for high level cyber security requirements in the European Union. Defines relevant and important entities in 18 sectors (energy, transport, banking, healthcare, digital infrastructure, etc.), cybersecurity risk management measures and incident reporting obligations. This is a directive, so each Member State transposes it into national law.
Detailed: L4 · Covers with L6 sectors · LV transposition: L2
Of which: Medium and large enterprises in 18 sectors Official source
L6
DORA · Part-IS · NCCS Directly applicable EU financial, aviation and energy legislation

Sector specific EU regulations

These European Union laws are directly applicable in Latvia, not transposed by the National Cybersecurity Law. NKDL aviation and energy are only covered as NIS 2 sectors, without sectoral technical requirements. Each act has a separate legal basis. DORA (Regulation (EU) 2022/2554) in the financial sector is a lex specialis in relation to NIS 2 and provides for ICT risk management, incident reporting and third party supervision. Part-IS (Regulation (EU) 2023/203 and 2022/1645) applies to EASA regulated organisations on the basis of EASA Framework Regulation (EU) 2018/1139. NCCS (Regulation (EU) 2024/1366) determines cyber security of cross-border flows of electricity on the basis of the Electricity Market Regulation (EU) 2019/943.
Complements L7 sectors · NOT includes L2 NKDL (directly applicable EU acts)
For: Financial, aviation and energy operators in the EU Official source
L5
CRA Security of digital products

Regulation (EU) 2024/2847 - Cyber Resilience Act

Defines cyber security requirements for products with digital features. Equipment and software must be safe by default and development principle, with security updates throughout the product life cycle. The CE marking now confirms not only the physical but also cyber security of the product.
Parallel: L7 (products, not services)
For: All selling digital products on the EU market Official source
L4
Reg. (EU) 2024/2690 Technical and methodological conditions for NIS 2

Commission Implementing Regulation (EU) 2024/2690

Specify NIS 2 risk management measures and incident reporting criteria for digital service providers (cloud services, data centres, DNA, content delivery networks, online outlets, etc.). The Regulation is directly applicable without transposition into national law.
Base: L7 (technical detail)
To: Digital services and infrastructure providers in the EU Official source
L3
VDAR (GDPR) Protection of personal data

Regulation (EU) 2016/679 - General Data Protection Regulation (EU) 2016/679

Protects personal data. The processing of personal data requires a legal basis, the data subject must be informed and the data deleted upon request. The personal data breach shall be reported to the Data State Inspectorate within 72 hours.
Coating with: L7 (incident reporting)
Of which: All processing personal data of EU citizens Official source
L2
NKDL Acquisition of NIS 2 in Latvia

National Cybersecurity Law

Latvian law transposing the NIS 2 Directive. Defines essential and important services in Latvia, incident reporting procedures (CERT.LV), competent authorities (National Cyber Security Centre) and responsibilities and responsibilities of entities.
Base: L7 · Technical performance: L1
Covered by: Latvian authorities and companies in the list of essential/important services Official source
L1
MK 397 Minimum cyber security requirements

Cabinet Regulation No 397

Minimum technical and organisational cyber security requirements shall be established. These include password policies (at least 12 characters), multifactor authentication for staff, event logging, software updates, security testing and backup copies. These requirements in practice ensure fulfilment of the obligations set out in the National Cybersecurity Law.
Base: L2
Covered by: Entities defined by public authorities + NKDL Official source
// DISCLAIMER: Clarifications are informative and no legal advice. In a specific case, you should consult the official legislation or the specialist.