Skip to main content

Regulation

The legal acts we work from

Compliance starts with clearly named legal acts. Below are the key ones - Lithuania's KSĮ, the EU implementing regulation (2024/2690), Government Resolution No. 818, and VIIVĮ. For each act we provide the official link and a local archive copy (in Markdown).

Note: Local archive copies reflect consolidated versions as of a specific date. For compliance work we always recommend referring to the official version on e-tar.lt / e-seimas.lrs.lt / EUR-Lex.

No. XII-1428

Cybersecurity Law of the Republic of Lithuania

Republic of Lithuania

Lithuania's transposition of the NIS2 directive. Defines essential and important entities, management accountability, cybersecurity risk management measures and incident notification deadlines.

Scope of application: Essential and important entities, their executives, and state information resource controllers.

Government Resolution No. 818

On the implementation of the Cybersecurity Law of the Republic of Lithuania

Republic of Lithuania

Consolidated version of Government Resolution No. 818 of 13 August 2018, in force from 2026-04-01. Approves the Cybersecurity Requirements Description, the Enforcement Measures Description, the Entity Identification Methodology and the National Cyber Incident Management Plan.

Scope of application: All cybersecurity entities under KSĮ.

(EU) 2024/2690

Commission Implementing Regulation (EU) 2024/2690

European Union

Technical and methodological requirements under NIS2 Art. 21(2) for DNS, TLD, cloud, data centre, CDN, managed service, marketplace, search engine and social network providers, and trust service providers. ANNEX - 13 detailed requirement chapters.

Scope of application: Directly applicable to providers in the listed sectors across the EU.

No. XI-1807

State Information Resources Management Law of the Republic of Lithuania

Republic of Lithuania

Defines management, security, register and information-system requirements for state information resources (VII). Links to KSĮ - critical information infrastructure (YSII).

Scope of application: State institutions and bodies managing VII.

Related material

Annexes to the National Cyber Incident Management Plan and a related Government Resolution draft. Use them as flowcharts and descriptions when drafting your internal incident management procedure.

Need help applying these acts to your organisation?

We help bridge from statutory text to specific internal procedures, an evidence base and a delivery plan. Start with the self-assessment or get in touch for a consultation.