NIS2 in Latvia — CERT.LV, combined CERT-regulator model, and streamlined oversight.
Latvia transposed NIS2 through national legislation, with CERT.LV serving as both the competent authority and the national CSIRT. What makes Latvia distinctive is the combined model: one body holds both operational CERT functions and regulatory authority, unlike countries that split these roles across separate agencies. This structural choice simplifies oversight for organizations subject to NIS2 in Latvia — there is one authority to register with, one authority to report incidents to, and one authority to demonstrate compliance to.
The transposition follows the standard EU structure, but the CERT.LV consolidation creates a streamlined authority model. For organizations subject to NIS2 in Latvia, this means reporting to an authority that handles both operational incident response and regulatory supervision rather than navigating separate bodies. CERT.LV maintains distinct functions within the organization, but the single-body structure is notable and shapes how oversight is delivered.
Who it applies to
Essential and important entities across NIS2 sectors, with CERT.LV providing oversight under its combined mandate. Entities that meet the size thresholds must register and submit risk-management documentation. The combined CERT-regulator model does not change the compliance obligations but simplifies the authority structure.
The clock
Competent authority: CERT.LV. Transposition: National Cybersecurity Law (NIS2 transposition).
| When | What happens |
|---|---|
| National transposition | NIS2 law enters into force · CERT.LV authority confirmed |
| On registration | Registration with CERT.LV · risk-management filing |
| Ongoing | Incident reporting to CERT.LV · annual compliance updates |
Combined CERT and regulator in one body
Latvia's CERT.LV holds both operational CERT and regulatory functions under Latvian law, a structural choice that is distinctive among member states. Most countries split these roles across separate bodies — a national CSIRT for incident response and a competent authority for supervision. Latvia consolidates both in CERT.LV, creating a streamlined authority model where organizations subject to NIS2 register, report incidents, and demonstrate compliance to a single body rather than navigating separate agencies. This simplification does not change the compliance obligations but reduces administrative overhead.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Latvia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with CERT.LV | Entity profile · single registration point for regulatory and operational functions |
| File risk-management documentation | Risk register · aligned with Latvian NIS2 requirements |
| Report incidents to CERT.LV | Incident workflow · clocked reporting, to the same body for both response and supervision |
| Document controls and evidence | Control library · evidence collection under combined oversight |
| Demonstrate compliance to one authority | Compliance workspace · streamlined reporting to CERT.LV |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- CERT.LV registration
- complete · single body for regulatory and operational functions
- Authority structure
- combined · CERT and regulator consolidated
- Controls evidenced
- 58/79 · 21 open, with clear ownership
- Incident reports
- 2 filed · both to CERT.LV within statutory timeframes
- Export
- sealed · sha256:4f9a...7c2e
Where teams usually start
With a demo walked through by TruSecure — CERT.LV's combined model understood, with Latvian NIS2 requirements mapped against the EU baseline and national specifics.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Latvia by CERT.LV. TruSecure determines applicability against Latvia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.