Five practical steps for companies in Latvia to translate NIS2 and Cabinet Regulation No. 397 legal requirements into an actionable security roadmap.

Published: · 7 min read

NIS2 in practice: where should a Latvian company start?
Illustrative image · BR²SEC

If you have been following recent changes to cybersecurity regulation in Latvia, the NIS2 Directive may seem like yet another extensive compliance burden. NIS2, however, is no longer merely a theoretical European document. It has been incorporated into Latvian law through the National Cyber Security Law (NKDL) and the detailed Cabinet Regulation No. 397, “Minimum Cybersecurity Requirements”.

When trying to understand the new requirements, it is easy to feel overwhelmed and assume that the first step is to purchase expensive cybersecurity tools. The reality is different: effectiveness begins with clarity and governance. Before investing in new technology, a company should answer three fundamental questions:

  • Which services are genuinely critical to our business?
  • Which data and systems keep those services running?
  • Who makes decisions when a cyber incident occurs?

To help turn the list of requirements into a clear and actionable plan, we have summarised five practical steps that follow the logic of Latvia’s Cabinet Regulation No. 397.

1. Determine your status and scope

Before implementing security measures, establish whether and to what extent the regulation applies to your organisation. Under the NKDL and Cabinet Regulation No. 397, a company should determine whether it qualifies as an essential-service or important-service provider, or whether it is an owner or lawful possessor of ICT critical infrastructure.

2. Appoint a cybersecurity manager

If the company is an entity within the scope of the NKDL, it must appoint a cybersecurity manager. This person becomes the official contact for communications with the National Cybersecurity Centre and CERT.LV and oversees internal security processes.

3. Identify and classify ICT resources

The regulation requires full visibility of the organisation’s digital environment. You must establish and regularly update a catalogue of ICT resources and information systems.

4. Develop the core documentation and train the team

Good intentions are not enough: security processes must be documented and operational. Cabinet Regulation No. 397 defines the mandatory set of cybersecurity-governance documents.

5. Perform a self-assessment and build a roadmap

Not every gap must be closed in one day, but the organisation must clearly understand its current shortcomings. Compare existing controls with Cabinet Regulation No. 397 and prepare the required self-assessment report.

Summary

Preparing for NIS2 and Latvia’s Cabinet Regulation No. 397 does not have to be an insurmountable obstacle. By breaking the work into practical, sequential steps, you will not only support compliance but also strengthen the real protection of your business, customer trust and operational continuity.