$ ./attiffet laws.sh

[OSI-style layers, L7 → L1, from the international framework to technical implementation]

Legislation in clear language. Latvian and European Union cybersecurity package, which applies to information systems. Acti arranged in OSI model layers: from the top of the abstract frame to the technical implementation at the bottom.
L7
NIS 2 A common EU cybersecurity framework

Directive (EU) 2022/2555 - Security of network and information systems

Set a common framework for high level cyber security requirements in the European Union. Defines the relevant and relevant entities, the risk management measures applicable to them, management responsibilities and incident reporting obligations. The size of an undertaking is not the only criterion: some entities, including domain name systems and providers of electronic communications services, are subject to requirements regardless of size. This is a directive, so each Member State transposes it into national law.
Detailed: L4, Covers with L6 sectors, LV transposition: L2
Covered by: Subjects of certain sectors; size is not the only criterion Official source
L6
DORA, Part-IS, NCCS Directly applicable EU financial, aviation and energy legislation

Sector specific EU regulations

These European Union laws are directly applicable in Latvia, not transposed by the National Cyber Security Law. The financial sector of DORA is lex specialis in relation to NIS 2 and determines risk management of information and communication technologies, incident reporting, stress testing and supervision of external service providers. Part-IS concerns aviation organisations regulated by the European Union Aviation Safety Agency. The NCCS determines cyber security of cross-border electricity flows.
Complements L7 sectors, NOT included in L2 NKDL (directly applicable EU acts)
For: Financial, aviation and energy operators in the EU Official source
L5
CRA Security of digital products

Regulation (EU) 2024/2847 - Cyber Resilience Act

Defines cyber security requirements for products with digital features. The hardware and software must be secure by design principle and by default, with vulnerability management and security updates during the support period. The manufacturer must report on injuries actively used. The CE marking now confirms not only the physical but also cyber security of the product.
Parallel: L7 (products, not services)
For: All selling digital products on the EU market Official source
L4
Reg. (EU) 2024/2690 Technical and methodological conditions for NIS 2

Commission Implementing Regulation (EU) 2024/2690

Specify the NIS 2 risk management measures and determine when an incident is considered significant. For digital infrastructure and digital service providers: domain name system services, top-level domain registers, cloud computing, data centres, content delivery networks, managed services and managed security services, online marketplaces, search engines, social network platforms and trust services. The technical requirements are based on international standards. The Regulation is directly applicable without transposition into national law.
Base: L7 (technical detail)
To: Digital services and infrastructure providers in the EU Official source
L3
VDAR (GDPR) Protection of personal data

Regulation (EU) 2016/679 - General Data Protection Regulation (EU) 2016/679

Protects personal data. The processing of personal data requires a legal basis, the data subject must be informed and the data deleted upon request. A personal data breach must be reported to the supervisory authority, but also to the people themselves in case of high risk. This is not a step in the hierarchy of other layers, but a parallel axis: one incident can simultaneously create a cybersecurity and personal data reporting obligation, and two separate messages with different addressees and deadlines.
Coating with: L7 (incident reporting)
Of which: All processing personal data of EU citizens Official source
L2
NKDL Acquisition of NIS 2 in Latvia

National Cybersecurity Law

Latvian law transposing the NIS 2 Directive. Defines essential and important services in Latvia, entity inventory, cyber security management obligations, incident reporting procedures, self-assessment reports, compliance audits and responsibility of entities. In addition to the NIS 2 minimum, domain name registration services, cyber security of data centres, centralised protection against service attack and a single national internet traffic exchange point are regulated separately.
Base: L7, Technical execution: L1
Covered by: Latvian authorities and companies in the list of essential/important services Official source
L1
MK 397 Minimum cyber security requirements

Cabinet of Ministers Regulations No. 397

Minimum technical and organisational cyber security requirements are established, which in practice fulfil the obligations laid down in the National Cybersecurity Law. The requirements shall cover cybersecurity managers, management documentation and policies, information and communication technology resources catalogue, cyber risk management plan, cyber incident management, access rights, network and log file management, backup copies, cyberhygiene and encryption. Individually regulated outsourcing, additional requirements for critical infrastructure and supervision of entities. The scope of the requirements depends on the security class of the information system.
Base: L2
Subject: Providers of essential and essential services, owners and holders of critical infrastructure Official source
// DISCLAIMER: Clarifications are informative and no legal advice. In a specific case, you should consult the official legislation or the specialist.