NIS2 in Lithuania: who is in scope and what the law requires
Lithuania's amended Cybersecurity Law applies NIS2 from 18 October 2024: who is in scope, NKSC supervision, incident deadlines, transition periods and fines.
AFKzona Group · 6 min read
The short answer
- Lithuania transposed NIS2 through the amended Law on Cybersecurity (Kibernetinio saugumo įstatymas), applied from 18 October 2024, with NKSC as the supervisor.
- In general, medium and large organisations in the sectors listed in the law's annexes are in scope; small and micro enterprises are excluded except in specific cases.
- NKSC notified identified entities of their inclusion in the Cybersecurity Entities Register by 17 April 2025.
- Organisational requirements apply within 12 months and technical ones within 24 months of an entity's inclusion in the register, so each entity's own dates depend on its notification.
- A significant incident must be reported within 24 hours, with an assessment within 72 hours.
NIS2 in Lithuania is implemented through the amended Law on Cybersecurity (Kibernetinio saugumo įstatymas), which has applied since 18 October 2024 and is supervised by the National Cyber Security Centre (NKSC). It covers, in general, medium and large organisations in the sectors listed in the law's annexes. Those organisations must manage cyber risk, appoint a head of cybersecurity, report significant incidents within 24 hours and pass a cybersecurity audit at least every three years.
This article summarises what the primary sources say and where to confirm your own dates with NKSC.
What NIS2 is, and how Lithuania applied it
NIS2 is the EU directive on a high common level of cybersecurity, Directive (EU) 2022/2555. It widened the range of sectors and organisations that must manage cyber risk and report incidents. Each member state had to transpose it into national law; Lithuania did so by amending its existing Law on Cybersecurity.
Cybersecurity entity (kibernetinio saugumo subjektas) is an organisation that NKSC has identified as falling under the law and included in the Cybersecurity Entities Register. Entities are divided into essential (esminiai) and important (svarbūs) entities, with different supervision and different maximum fines.
According to NKSC, the law's provisions apply from 18 October 2024. On 6 November 2024 the Government adopted Resolution No. 945 and related documents implementing the law, and the detailed requirements are set out in the Description of Cybersecurity Requirements, approved by Government Resolution No. 818 of 13 August 2018 in its current wording.
Who is in scope
An organisation is in scope when two tests are met: it operates in one of the sectors listed in Annexes 1 and 2 of the law, and it is a medium or large enterprise under the Law on Small and Medium-Sized Business Development, which looks at average headcount, annual revenue and balance-sheet total. Small and micro enterprises are generally excluded.
The annexes follow the directive. In NIS2, Annex I lists 11 sectors of high criticality (including energy, transport, banking, health, drinking water, digital infrastructure, ICT service management and public administration) and Annex II lists 7 other critical sectors (including postal services, waste management, chemicals, food, manufacturing, digital providers and research). Sector assignment in Lithuania is based on the economic activity classification, taking into account all of the organisation's activities and services.
The Ministry of National Defence notes exceptions to the size rule: a small or micro enterprise can still be covered when its services are critical, for example when it is the sole provider of a service, or when a disruption could significantly affect public safety or public health.
| Question | Where to look | Primary source |
|---|---|---|
| Is my sector listed? | Annexes 1 and 2 of the Law on Cybersecurity; NIS2 Annexes I and II | NKSC (law text), EUR-Lex |
| Am I medium or large? | Law on Small and Medium-Sized Business Development criteria | KAM FAQ |
| Am I in the register? | NKSC notification; voluntary application | NKSC |
| Essential or important? | The category in the NKSC notification | NKSC |
| When do requirements apply to me? | 12 / 24 months from inclusion in the register | NKSC |
If you are not directly in scope, you may still feel NIS2 through your customers. Entities in scope must manage supply-chain risk, so software vendors, hosting providers and IT contractors can expect security questionnaires and contract clauses.
Key dates: what is confirmed and what depends on you
The confirmed dates are the start of application on 18 October 2024 and NKSC's identification of entities by 17 April 2025. After that, the dates are entity-specific: they run from the moment each entity is included in the register, so there is no single national compliance deadline that applies to everyone.
The Ministry of National Defence states that NKSC identified cybersecurity entities, included them in the Cybersecurity Entities Register and sent them notifications by 17 April 2025. The register is reviewed at least once a year, so new entities can be added later, and organisations can apply to be registered voluntarily.
NKSC states that requirements apply after a transition period of no less than 12 months from inclusion in the register, with the aim that entities meet organisational requirements (such as having a head of cybersecurity) within 12 months and implement technical requirements within 24 months.
| Milestone | Date | Status |
|---|---|---|
| Amended law applies | 18 October 2024 | Confirmed by NKSC |
| Implementing Government resolution No. 945 | 6 November 2024 | Confirmed by NKSC |
| NKSC notifies identified entities | By 17 April 2025 | Confirmed by the Ministry of National Defence |
| Organisational requirements | 12 months from your inclusion in the register | Entity-specific; check your notification |
| Technical requirements | 24 months from your inclusion in the register | Entity-specific; check your notification |
| Cybersecurity audit | At least once every 3 years | Confirmed by NKSC |
You may see "17 April 2026" quoted as a compliance deadline. It is what the 12-month period gives for an entity included in the register on 17 April 2025, not a date that applies to every organisation. Check your own notification and NKSC's current guidance.
Key obligations
The obligations fall into five groups: governance, risk management, incident reporting, audits and supply chain. The head of the organisation is responsible for making sure the organisation meets them, and the detail sits in the Description of Cybersecurity Requirements.
- Head of cybersecurity. Entities must appoint a person responsible for cybersecurity who reports to management. The Ministry of National Defence states the role needs at least two years of experience in IT, cybersecurity, or networks and information systems.
- Risk management. Regular cyber-risk assessment, security policies, access control, backups, business continuity, and staff training.
- Incident reporting. A significant cyber incident must be reported without delay and no later than within 24 hours. Within 72 hours of becoming aware of it, the organisation must give NKSC an assessment of its severity and impact and any evidence of intrusion. Under NIS2 Article 23, a final report follows within one month.
- Audits. A cybersecurity audit at least once every three years, following the methodology NKSC approves.
- Supply chain. Security of suppliers and service providers is part of risk management, which is why vendors are asked for evidence.
Significant incident (didelis kibernetinis incidentas) is an incident that causes, or can cause, serious disruption to services or financial loss, or significant damage to others, as defined in the law and its implementing acts.
Enforcement and fines
NKSC supervises compliance and can apply enforcement measures. According to the Ministry of National Defence, these include temporary suspension of a manager from duties, temporary suspension of activity and, ultimately, fines of up to €10 million or up to 2% of global annual turnover.
Stronger measures such as suspending a manager are aimed at essential entities. Maximum fines differ between essential and important entities, so check the law for your category rather than relying on the headline figure.
A practical starting point for an IT team
If you are in scope, or supply software to someone who is, the technical work starts with an honest inventory. We suggest this order:
- Inventory systems, data, admin accounts, suppliers and where each runs.
- Access control: multi-factor authentication for all admin access, removal of shared and stale accounts.
- Backups and restore tests: a backup that has never been restored is an assumption, not a control.
- Logging that can answer "who did what, when" for your critical systems, kept long enough to support a 72-hour assessment.
- Patching and dependency updates on a schedule, with evidence.
- An incident runbook that names who calls NKSC within 24 hours, and a rehearsal.
- A written report ranking the gaps by risk, which you can use for the audit and for customer questionnaires.
How we can help
We do code reviews and security audits that end in a written report: what is broken, what is risky and what to fix first. We also build the logging, backup and access-control pieces into the systems we deliver, as a routine part of the work.
- Service: code review and security audit, from €1,500
- What we check: code reviews, audits and due diligence
- All prices: pricing
- Book a free 30-minute call and bring your NKSC notification if you have one.
Common questions
Does NIS2 apply to my company in Lithuania?
It may if you operate in one of the sectors listed in Annexes 1 and 2 of the Law on Cybersecurity and you are a medium or large enterprise under the Law on Small and Medium-Sized Business Development. Small and micro enterprises are generally excluded, with exceptions such as sole providers of a critical service. NKSC identifies entities and notifies them; you can also apply voluntarily.
What is the NIS2 deadline in Lithuania?
The law applies from 18 October 2024. NKSC notified identified entities by 17 April 2025. Requirements then apply with a transition of at least 12 months from inclusion in the register for organisational measures and 24 months for technical measures. Your own dates run from your notification, so check it and NKSC's current guidance.
What are NIS2 fines in Lithuania?
According to the Ministry of National Defence, NKSC can apply enforcement measures including temporary suspension of a manager and temporary suspension of activity, and fines of up to €10 million or up to 2% of global annual turnover. Ceilings differ between essential and important entities, so check the law for your category.
Who supervises NIS2 in Lithuania?
The National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras, NKSC) under the Ministry of National Defence. It identifies entities, keeps the Cybersecurity Entities Register, receives incident reports, approves the audit methodology and carries out supervision and enforcement. If you are unsure whether your organisation is covered, NKSC is the body to ask, and it accepts voluntary registration requests.
Sources
- NKSC: the amended Law on Cybersecurity enters into force, main changes and implementation stages
- NKSC: Government approves documents implementing the Law on Cybersecurity
- Ministry of National Defence: what to know about the amended Law on Cybersecurity (FAQ)
- NKSC: Law on Cybersecurity
- Directive (EU) 2022/2555 (NIS2) (EUR-Lex)