Lithuania NIS2 competent authority NKSC cybersecurity framework structure

NKSC, RRT, and CERT.LT: Lithuania’s NIS2 Authority Structure and What Entities Must Register

Lithuania took a structurally simpler approach to NIS2 authority design than most EU peers: one institution holds every supervisory function the Directive requires. The National Cybersecurity Centre (NKSC — Nacionalinis kibernetinio saugumo centras), operating under the Ministry of National Defence, acts simultaneously as the competent authority for essential entities, the competent authority for digital service providers, and Lithuania’s Single Point of Contact for EU-level coordination. Its incident-response team — CERT.LT — is the national CSIRT.

That structure is now operational. The Law on Cybersecurity of the Republic of Lithuania entered into force on 18 October 2024, and NKSC notified 1,443 organisations of their essential or important entity status around 17 April 2025. Compliance clocks are running: organisational measures are due by April 2026, technical measures by April 2027.

This guide explains what NKSC, RRT, and CERT.LT each supervise, how entity registration and the KSIS submission system work, and what the national cybersecurity law demands of organisations in scope.

NKSC: Lithuania’s Sole NIS2 Competent Authority

The National Cybersecurity Centre is the institution to know for NIS2 compliance in Lithuania. Under Article 8 of the NIS2 Directive, member states must designate one or more competent authorities and a Single Point of Contact. Lithuania consolidated all three required designations — competent authority for operators of essential services, competent authority for digital service providers, and Single Point of Contact for EU cooperation — into NKSC, a designation confirmed on the European Commission’s official NIS2 implementation register.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

NKSC’s supervisory powers under Articles 26–29 of the Lithuanian Cybersecurity Act (LCA) include:

  • Identifying and maintaining the national register of cybersecurity entities
  • Conducting planned audits and on-site inspections of essential and important entities
  • Issuing binding instructions requiring specific security measures
  • Demanding detailed security documentation, risk assessments, and audit evidence
  • Imposing financial fines and non-financial sanctions including management disqualification

The entity register is publicly accessible. From 17 April 2025, any organisation can check its registration status at nksc.lt/kssregistras/ by entering its company code. This is not a self-registration system — NKSC identifies qualifying entities based on sector and company size, then issues electronic notifications. Organisations that believe they qualify but have not received notification should contact NKSC directly rather than assuming they fall outside scope.

How RRT and CERT.LT Fit the Picture

RRT (Ryšių reguliavimo tarnyba — the Communications Regulatory Authority) is Lithuania’s independent regulator for electronic communications, postal services, and trust service providers. RRT is not designated as a NIS2 competent authority. For cybersecurity compliance under the Directive, all entities — including telecoms operators and digital infrastructure providers — report to NKSC, not RRT.

This distinction matters because Lithuania’s model departs from the authority-split approach used in some EU neighbours. Latvia, for example, assigns distinct NIS2 supervisory roles to three separate bodies: its NCSC under the Ministry of Defence, CERT.LV, and the Constitution Protection Bureau. Lithuania made the opposite structural choice. RRT retains its mandate for electronic communications market regulation — spectrum management, service continuity, consumer protection under the EECC — but that mandate operates in parallel to NIS2 cybersecurity obligations rather than replacing them. A telecoms operator in Lithuania has two separate regulatory relationships: RRT for market regulation, NKSC for cybersecurity.

CERT.LT is Lithuania’s national Computer Security Incident Response Team, operating as the incident-response function within NKSC — in practice, the two are the same institution. CERT.LT fulfils the national CSIRT mandate under Article 10 of the NIS2 Directive, which requires member states to maintain a response capability available on a continuous basis for significant incidents. Essential and important entities report significant incidents directly to CERT.LT:

  • Email: cert@cert.lt
  • Phone: +370 706 82 250
  • Hours: Monday–Friday, 08:00–17:00 EET; 24/7 for urgent cases

The Lithuanian Cybersecurity Law — What Changed in October 2024

Lithuania’s NIS2 transposition instrument is the Law on Cybersecurity of the Republic of Lithuania (Lietuvos Respublikos kibernetinio saugumo įstatymas, Nr. XII-1428). The Seimas amended and recast it on 11 July 2024; the revised law entered into force on 18 October 2024 — the EU-wide transposition deadline. A separate implementing instrument, Government Resolution No. 945, entered into force on 12 November 2024 and defines the technical content: the “Description of Cybersecurity Requirements” covering 12 obligation areas, plus the procedures for submitting compliance evidence through the Cybersecurity Information System (KSIS).

Lithuania’s LCA exceeds the NIS2 baseline in several areas that create distinct operational obligations not present in the Directive itself:

Lithuanian addition LCA article NIS2 baseline comparison
Named cybersecurity manager (kibernetinio saugumo vadovas) Art. 15 NIS2 Art. 20 requires management body oversight — no named position required
Named security officer (saugos įgaliotinis) Art. 15 Not required under NIS2
Biennial management cybersecurity training Art. 14(7) NIS2 Art. 20 mandates training; frequency unspecified
Public sector penalty cap (€60,000 / €30,000) Arts. 30–31 NIS2 applies no separate ceiling for government entities
Secure State Data Network for public institutions Arts. 37–38 Not required under NIS2

The most operationally significant addition is Article 15’s dual-role requirement. Every in-scope entity must appoint a kibernetinio saugumo vadovas (cybersecurity manager) responsible for overall compliance and reporting directly to senior leadership, alongside a saugos įgaliotinis (security officer) managing day-to-day operational security. NIS2 Article 20 holds management bodies accountable for approving and overseeing risk management measures — the LCA converts that general accountability into concrete job roles with explicit reporting lines and qualification criteria.

Who Must Comply — Essential and Important Entity Scope

Lithuania applies NIS2’s standard two-tier classification. Essential entities (esminiai subjektai) come from Annex I sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities (svarbūs subjektai) cover Annex II sectors including postal and courier services, waste management, manufacture of certain critical products, food production and distribution, online marketplaces and search engines, and research organisations.

The default threshold is company size: medium enterprises (50 or more employees, or annual turnover above €10 million) and large enterprises operating in listed sectors. Micro and small companies are generally excluded unless a disruption of their services would significantly affect the public sector or create substantial systemic risk. An Article 11(5) LCA sole-provider exemption applies to entities with no viable substitute on the Lithuanian market — organisations meeting this condition can apply to NKSC for a formal determination.

NKSC initially identified 1,443 entities in the first registration exercise and acknowledges the eventual scope may reach 8,000–10,000 entities once sector-level mapping is complete. For a detailed breakdown of what classifies an entity as essential versus important — including how supervisory intensity and audit frequency differ between the two tiers — see the guide on essential vs. important entities under NIS2.

Registration, KSIS, and the Compliance Timeline

Lithuania’s entity identification is passive from the organisation’s perspective: NKSC maintains the register and notifies qualifying entities electronically, rather than requiring self-registration. Two separate systems handle different parts of the process, and conflating them creates compliance errors.

nksc.lt/kssregistras/ — the public entity register lookup. Available from 17 April 2025, any organisation can enter its company registration code here to check whether it appears in the essential or important entity register. This is a read-only status check, not a compliance submission platform.

KSIS (Kibernetinio saugumo informacinė sistema) — the closed compliance platform where registered entities submit internal security documentation: risk assessments, business continuity test results, security audit reports, and cybersecurity requirement implementation records. Documents must be submitted within 5 days of completion, not at a fixed annual deadline.

Compliance deadlines run from the date of NKSC notification, not from the law’s entry-into-force date:

Milestone Date
LCA enters into force 18 October 2024
NKSC entity registration deadline 17 April 2025
Organisational measures deadline (including cybersecurity manager appointment) 17 April 2026
Technical measures deadline 17 April 2027
Ex-post evaluation for essential entities 1 January 2029

Lithuania’s 12 Cybersecurity Requirement Areas

Government Resolution No. 945 defines 12 technical and organisational areas that cybersecurity entities must implement and document through KSIS. These map closely to NIS2’s Article 21(2) security measures but are articulated in Lithuania-specific operational terms:

  1. Network and information systems security policy — governance framework, scope definition, and continuous improvement commitments
  2. Cybersecurity risk analysis — threat identification, vulnerability assessment, and impact evaluation
  3. Responsibilities for cybersecurity — cybersecurity manager and security officer designations, reporting channels and escalation procedures
  4. Cyber incident management — detection, containment, recovery, and stakeholder notification procedures
  5. Business continuity — operational resilience plans with defined recovery timeframes and regular testing schedules
  6. Supply chain security — vendor vetting, contractual security requirements, and third-party compliance monitoring
  7. Systems acquisition and maintenance — secure development lifecycle, patch management, and vulnerability disclosure
  8. Evaluating effectiveness — regular audits, compliance documentation, and corrective action processes
  9. Cyber hygiene and training — employee awareness covering phishing recognition, password management, and social engineering
  10. Cryptography policies — encryption requirements for data in transit and at rest, with key management procedures
  11. Human resources and physical security — personnel screening, facility access controls, and asset inventory management
  12. Access control and multi-factor authentication — user account management with mandatory MFA for critical systems

Areas 6 (supply chain), 4 (incident management), and 12 (access control and MFA) are where organisations most commonly identify compliance gaps during initial assessments. For implementation guidance on supply chain obligations under NIS2, see the supply chain security guide. For the incident notification requirements — including the 24-hour early warning and 72-hour incident report timelines — see the Article 23 incident notification guide.

Supervision, Enforcement, and Penalties

NKSC applies different oversight intensities depending on entity tier. Essential entities face proactive ex-ante supervision — NKSC audits them on a planned cycle before problems arise. Important entities are subject to reactive ex-post oversight triggered by incidents, complaints, or indications of non-compliance.

Lithuania introduced an enforcement mechanism that goes beyond the NIS2 baseline: a mandatory 3-year independent conformity assessment cycle for essential entities. Accredited certification bodies conduct these assessments, with results submitted to NKSC and integrated into the entity’s ongoing compliance record. This creates a structured evidence trail separate from routine KSIS documentation submissions.

Financial penalties under Articles 30–31 of the LCA follow NIS2’s framework, with one important modification for public sector bodies:

Entity type Maximum fine
Essential entity (private) €10,000,000 or 2% of global annual turnover
Important entity (private) €7,000,000 or 1.4% of global annual turnover
Essential entity (public sector) €60,000
Important entity (public sector) €30,000

The public sector caps are a deliberate Lithuanian policy choice — NIS2 itself sets no separate ceiling for government entities. Public authorities facing reduced financial penalties still receive corrective orders and mandatory compliance reporting obligations. NKSC can also publish infringement findings, which carries reputational exposure even where fines are modest.

Non-financial sanctions include temporary suspension of certifications and temporary prohibition of named executives from management functions, which can extend to 3 years for repeated or negligent breaches. This is a sanction with direct personal exposure for board members, not just IT departments. For a detailed breakdown of what board-level accountability means in practice, see the article on board directors and NIS2 accountability.

What Entities Should Do First

Three roles face different immediate priorities:

Compliance officers and legal teams: Check nksc.lt/kssregistras/ to confirm entity registration status. If listed, appoint a cybersecurity manager and security officer under Article 15 LCA without delay — these are prerequisite positions for KSIS submissions and must be in place before the April 2026 organisational measures deadline. Document the appointments and their reporting lines formally.

CISOs and IT security managers: Run a gap assessment against Lithuania’s 12 requirement areas using Government Resolution No. 945 as the benchmark document. The 24-month technical measures window runs to April 2027, but effective implementation of requirements 6 (supply chain), 7 (systems acquisition and maintenance), and 12 (access control and MFA) typically requires 9–18 months in organisations without mature security programmes. Start scoping before the organisational deadline creates pressure.

Board members and executive teams: Lithuania’s implementation holds management bodies directly accountable under NIS2 Article 20 and Article 15 of the LCA. The 3-year executive disqualification sanction for repeated or negligent breaches means board-level cybersecurity oversight decisions should be documented and minuted explicitly — implied delegation to the IT function will not constitute a defence.

Frequently Asked Questions

Is NKSC the same as CERT.LT?

Functionally, yes. CERT.LT is the incident-response function operating within NKSC. Significant incident notifications go to CERT.LT (cert@cert.lt); compliance supervision — audits, binding instructions, and financial penalties — is handled by NKSC as the designated NIS2 competent authority. Externally they are the same institution.

Does RRT supervise NIS2 compliance for Lithuanian telecoms companies?

No. RRT regulates electronic communications markets under its own mandate: spectrum, service quality, and consumer protection. For NIS2 cybersecurity obligations, telecoms operators and all other Annex I and Annex II entities report to NKSC. RRT’s continuing EECC-derived obligations apply in parallel but are legally separate from NIS2 cybersecurity requirements.

How do I find out if my company is in the essential or important entity register?

Check nksc.lt/kssregistras/ using your company registration number. NKSC issued electronic notifications around 17 April 2025. If your organisation qualifies by sector and size but has not received a notification, contact NKSC directly — absence of notification does not confirm you are out of scope.

What is KSIS, and how does it differ from the entity register?

The entity register (kssregistras.lt) is a public read-only database showing which organisations are designated essential or important. KSIS (Kibernetinio saugumo informacinė sistema) is the separate, closed compliance platform where registered entities submit internal documentation — risk assessments, continuity test results, audit reports — within 5 days of document completion. The two systems serve distinct functions and require different access credentials.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive Implementation in Lithuania — European Commission Digital Strategy
  2. NIS2 Directive Article 8 — Competent Authorities and Single Points of Contact — nis-2-directive.com
  3. NIS2 Directive Article 10 — CSIRTs — nis-2-directive.com
  4. NIS2 Transposition in Lithuania: What Does the Lithuanian Cybersecurity Act Require? — Advisera
  5. NIS2 Lithuania — what you need to know! — NIS2Certification.eu
  6. NIS2 in Lithuania — Overview of Decision on Cybersecurity Requirements — Advisera
  7. NIS2 directive regulations and implementation in Lithuania — Copla
  8. Lithuania — EU NIS2 Directive — Eversheds Sutherland
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: