World Watch/Lithuania/Cybersecurity

Cybersecurity · Lithuania

Cybersecurity regulation in Lithuania (2026)

Comprehensive lawLaw on Cybersecurity of the Republic of Lithuania (amended 11 July 2024, in force 18 October 2024), transposing EU NIS2 Directive (2022/2555); supplemented by Government Resolution on Implementation (in force 12 November 2024). Competent authority and national CSIRT: National Cyber Security Centre (NKSC/NCSC) under the Ministry of National Defence.Country index 93 · A+

Lithuania shaded by its cybersecurity status

Lithuania fully transposed the EU NIS2 Directive through an amended Law on Cybersecurity that entered into force on 18 October 2024, with implementing technical/organisational requirements following on 12 November 2024. The National Cyber Security Centre (NKSC) acts as the single national cybersecurity authority, CSIRT, and supervisory body, with enforcement powers including binding instructions, on-site inspections, and fines. Entities classified as essential or important face tiered compliance timelines — organisational measures within 12 months of registration, technical measures within 24 months.

Key points

NIS2 Transposition

The revised Law on Cybersecurity was adopted on 11 July 2024 and entered into force on 18 October 2024, meeting the EU deadline. The Government's implementing Resolution setting technical and organisational requirements entered into force on 12 November 2024.

Supervisory Authority (NKSC)

The National Cyber Security Centre (NKSC) under the Ministry of National Defence is the sole competent authority, national CSIRT, and supervisory body. It manages the national Register of cybersecurity entities, monitors compliance, and coordinates incident response within the EU cybersecurity network.

Entity Registration & Scope

By 17 April 2025, NKSC compiled the initial Register, identifying 1,443 essential and important entities across critical sectors. The total universe of in-scope entities is estimated at 8,000–10,000 once the full identification process is complete.

Incident Reporting Obligations

Essential and important entities must report significant incidents to NKSC following the NIS2 three-stage timeline: early warning within 24 hours, full incident notification within 72 hours, and a final (or progress) report within one month. Affected service recipients must also be notified where an incident impacts service delivery.

Compliance Timelines

Entities notified of their inclusion in the Register have 12 months to implement organisational measures (e.g. appoint a cybersecurity officer, adopt cybersecurity policies) — deadline approximately April 2026 for the first cohort — and 24 months to implement full technical measures.

Penalties & Enforcement

Essential entities face fines up to €10 million or 2% of global annual turnover (whichever is greater); important entities face up to €7 million or 1.4% of global turnover. Additional non-financial sanctions include temporary suspension of activities and temporary dismissal of the responsible manager.

Lithuania - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →