Lithuania NIS2 Fines Reach €10M: NKSC’s Enforcement Powers, Management Bans, and How to Appeal
Lithuania became the first Baltic state to stop buying Russian gas and oil in May 2022, and on 8–9 February 2025 it completed its synchronization with the Continental European electrical grid — permanently severing its energy infrastructure from Russia-controlled systems. Those same energy networks, now classified as critical national infrastructure, sit at the top of the National Cyber Security Centre’s (NKSC) enforcement priority list under the NIS2 Directive.
The Republic of Lithuania Law on Cyber Security entered into force on 18 October 2024, transposing Directive (EU) 2022/2555. By April 2025, the NKSC had registered 1,443 entities — a fraction of the 8,000–10,000 it is expected to identify. As those identification rounds continue, enforcement is already live: the NKSC can issue binding orders, appoint monitoring officers, and impose fines reaching €10,000,000 or 2% of worldwide annual turnover for essential entities under Article 34(4) of the directive.
This article maps the complete enforcement framework for organisations subject to Lithuania’s NIS2 regime: fine tiers, the 4-stage escalation path, management liability under Article 20, why energy operators face heightened scrutiny, grace periods for newly registered entities, and how to challenge an NKSC decision before Lithuania’s administrative courts. For background on which entities fall within scope, see Lithuania’s NIS2 implementation overview.
NKSC’s Mandate and Supervisory Model
The National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras) operates under the Lithuanian Ministry of National Defence — an institutional positioning that reflects Lithuania’s geopolitical context. Unlike cybersecurity agencies in many EU member states that sit within interior or economy ministries, the NKSC’s defence ministry home gives it a security-first enforcement culture. Independent legal analysis of Baltic NIS2 implementation consistently characterises Lithuania as the strictest enforcer of the three, described as “fast and strict” against Latvia’s slower pace and Estonia’s more balanced approach.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The supervisory model follows the NIS2 Directive’s tiered approach. Essential entities receive proactive ex ante oversight: the NKSC can inspect and audit regardless of whether an incident has occurred, and must subject essential entities to regular conformity assessments. Important entities face reactive ex post supervision, with scrutiny triggered by incidents, complaints, or credible information of non-compliance. This asymmetry matters when planning your compliance programme — essential entities cannot wait for a problem to surface before the regulator arrives.
The NKSC’s enforcement track record predates NIS2. In 2024 alone, it handled 3,874 cyber incidents — a 63% increase from 2,378 in 2023 — including three major incidents attributed to foreign state-backed groups conducting network intrusions for long-term espionage objectives. Social engineering attacks accounted for 59% of all incidents, up from 38% in 2023. This is not a newly minted regulator finding its footing; it is an agency with an established investigative capability now backed by substantially larger fining powers under NIS2.
Lithuania projects that 8,000–10,000 entities will eventually fall within the regulatory perimeter across the sectors defined in NIS2 Annex I (essential) and Annex II (important). The 1,443 currently registered represent only the first identification wave. Additional notification rounds are expected through 2025 and 2026, each starting the compliance clock for newly designated entities. For guidance on NIS2 entity registration requirements, the NKSC notification process applies the same 12-month organisational and 24-month technical implementation windows covered later in this article.
The Fine Tiers: €10M for Essential, €7M for Important Entities
Under Article 34(4) of Directive 2022/2555, essential entities face administrative fines up to €10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever figure is higher. Under Article 34(5), important entities face fines up to €7,000,000 or 1.4% of total worldwide annual turnover. The turnover percentage matters more than the nominal ceiling for any mid-sized multinational: a company with €500 million in global revenue faces a 2% exposure of €10 million, which sits exactly at the ceiling and provides no headroom.
Three details that most coverage of Lithuania NIS2 penalties omits:
Government entity caps. Public sector essential entities face maximum fines of €60,000; public sector important entities face €30,000. This cap reflects the principle that state bodies cannot easily exit the market and that corrective orders — not fines — are the primary pressure mechanism for public authorities. Both remain subject to mandatory public disclosure of infringements, which carries its own reputational consequences.
Procedural breach tier. Violations outside the core Article 21 security measures and Article 23 incident reporting — such as missed registration deadlines, incomplete documentation submissions to the KSIS cybersecurity information system, or non-response to NKSC information requests — attract fines in the €300,000–€2,000,000 range under Lithuania’s implementing regulations.
Periodic penalty payments. Article 34(6) authorises the NKSC to impose daily coercive penalty payments on entities that fail to implement a prior compliance decision. These daily payments accumulate until the infringement ceases and operate separately from, and in addition to, the one-time administrative fine. An entity can emerge from a single non-compliance episode carrying both daily penalties accrued during remediation and the final statutory fine.
This last point reflects a principle embedded in Article 34 of the directive: fines are imposed in addition to other measures under Articles 32 and 33, not as an alternative. An entity can simultaneously face a binding corrective order, a monitoring officer designation, daily coercive penalties, and a final administrative fine — all arising from the same underlying non-compliance.
When the NKSC determines the fine amount, it must weigh the factors specified in Article 32(7): the severity and duration of the violation; the number of users affected; whether the infringement was intentional or negligent; the degree of the entity’s cooperation with the authority; and any financial benefit derived from the breach. Prior violations count as aggravating factors — an entity with a warning in its enforcement record faces a harsher fine calculation than a first-time case with otherwise similar facts.
NKSC’s 4-Stage Enforcement Escalation Path
The NKSC rarely reaches for the maximum fine in the first instance. Lithuania’s Cybersecurity Act establishes a proportionate escalation path with four identifiable stages, consistent with the graduated approach in Articles 32 and 33 of the directive. Understanding this sequence allows organisations to identify their current enforcement status and respond before a case advances to the fine stage.
Stage 1 — Warning. The NKSC issues a formal warning identifying the specific provision violated and the remediation expected. No fine applies at this stage. Warnings are not advisory — they create the enforcement record that the authority will reference in all subsequent steps. Receiving a warning and treating it as bureaucratic correspondence is the single most common path to Stage 4.
Stage 2 — Binding Corrective Order. A legally binding instruction specifying what the entity must do, the documentation required, and the deadline for completion. The NKSC sets the deadline; it is not negotiated. Failure to meet a corrective order deadline is itself a new violation that accelerates the case to Stage 3.
Stage 3 — Daily Coercive Penalties. Per Article 34(6) of the directive, the NKSC may impose periodic penalty payments that compound daily until the original corrective order is fulfilled. These can run for weeks or months. The accruing total adds financial pressure while the formal fine proceeding is still open.
Stage 4 — Administrative Fine. The statutory €10M/2% or €7M/1.4% ceiling applies. At this point, the enforcement record from Stages 1–3 is weighed as an aggravating factor in calculating the final amount.
Two parallel enforcement tools can activate at any stage and are not sequenced within the four-stage path:
- Monitoring officer appointment. The NKSC designates a compliance monitoring officer to oversee the entity’s remediation. This is operationally disruptive and signals serious doubts about self-correction capacity.
- Certification or authorisation suspension. For entities whose operations depend on licences or authorisations, the NKSC can temporarily suspend these — a business disruption that typically accelerates remediation faster than any fine.
| Stage | Trigger | NKSC Tool | Escalates If |
|---|---|---|---|
| 1 | Non-compliance identified | Formal warning | Warning ignored or unaddressed |
| 2 | Warning unresolved | Binding corrective order | Deadline missed |
| 3 | Order unimplemented | Daily periodic penalties | Continued non-compliance |
| 4 | Persistent non-compliance | Administrative fine (€10M/€7M) | — |
Management Liability: When Directors Face Personal Consequences
Article 20 of the directive places governance obligations directly on management bodies, not on the entity’s IT function. Management bodies must formally approve the cybersecurity risk-management measures required under Article 21 and actively oversee their implementation — not delegate and forget. The article makes management “liable for infringements” of these obligations, and Lithuania’s Cybersecurity Act carries this provision into national law.
The enforcement mechanism that produces a personal consequence is Article 32(5)(b) of the directive: where enforcement against the entity itself has failed to produce compliance, the NKSC may impose a “temporary prohibition of a natural person from exercising managerial functions” at CEO or legal representative level. Lithuania’s implementing regulations extend this to a disqualification period of up to three years for repeated or systemic governance negligence.
The triggers for a management ban are concrete, not abstract. An organisation that cannot demonstrate its management body formally approved and documented Article 21 security measures; lacks evidence of management training completed within the required biennial cycle; obstructed or delayed an NKSC audit; or provided false or materially inaccurate information to the authority — each of these qualifies as a “serious infraction” under Article 32(7) and places management function prohibition on the enforcement table.
Management liability under Article 20 is independently enforceable. An organisation whose technical security controls are largely sound but lacks documented management body approval of those controls can still face an Article 20 enforcement action separately from any Article 21 fine. The two enforcement tracks run in parallel, not in sequence. In practice, this means the Board Resolution and documented governance sign-off carry enforcement significance that extends beyond audit-readiness formality — they are the specific evidence the NKSC checks when assessing whether a management ban is warranted.
For comparison, Lithuania’s approach to management liability is consistent with the graduated enforcement model Latvia adopted under its National Cybersecurity Law, which also introduced a director ban for repeated negligent breaches — though Latvia’s enforcement pace is currently slower than Lithuania’s.
Energy Sector: Lithuania’s Priority Enforcement Target
Lithuania’s energy transition created the type of high-stakes critical infrastructure that NIS2 was designed to protect. After ceasing all Russian gas and oil imports in May 2022 and completing the BRELL grid disconnect to join the Continental European synchronous area on 8–9 February 2025, Lithuania now operates energy infrastructure whose resilience carries strategic significance for all three Baltic states simultaneously.
Under NIS2 Annex I, electricity sector operators are essential entities. AB Amber Grid, Lithuania’s gas transmission system operator, falls within scope as critical energy infrastructure. District heating operators, LNG import terminal operators — including the Klaipėda FSRU terminal that has provided the Baltic states’ primary non-Russian gas supply since 2014 — and hydrogen infrastructure providers are classified as important entities if they meet the applicable size thresholds. Lithuania’s energy regulator VERT receives mandatory KPI reporting from these entities as part of the oversight framework.
The geopolitical framing is not incidental to enforcement. The same NKSC annual report that documents 3,874 cyber incidents in 2024 also attributes the three major incidents to foreign state-backed actors conducting network intrusions for espionage objectives, with Russia and Belarus-linked groups specifically identified in the disinformation and cyberattack activity. The energy sector sits at the intersection of known threat actor interest and new critical infrastructure vulnerability — a combination that makes it the clearest enforcement priority in Lithuania’s NIS2 programme.
For energy operators, the practical implication is that Lithuania’s ex ante proactive audit model for essential entities removes the assumption of “no problem until an incident occurs.” The NKSC can initiate a conformity assessment of an electricity or gas transmission operator without a prior complaint, reported incident, or specific trigger. OT/ICS environments — the operational technology and industrial control systems that run physical grid infrastructure — are explicitly within Lithuania’s NIS2 enforcement scope, alongside standard IT systems.
Grace Periods for Newly Registered Entities
Entities included in NKSC’s first identification round and notified around April 2025 benefit from phased compliance implementation deadlines:
- Organisational measures — cybersecurity manager appointment, policy documentation, training programmes, governance sign-off: must be implemented within 12 months of the notification date, giving a deadline of approximately 17 April 2026.
- Technical measures — access controls, encryption, vulnerability scanning, network monitoring, backup systems, incident response capability: must be implemented within 24 months of the notification date, giving a deadline of approximately 17 April 2027.
These grace periods do not suspend the NKSC’s inspection and audit authority. The NKSC can issue warnings and binding orders during the implementation window for matters that fall outside the permitted implementation timetable — including failing to register, obstructing an audit, or failing to report a significant incident within the Article 23 notification windows. The grace period covers the pace of implementation, not the obligation to cooperate with the regulator during that period.
Entities identified in later notification rounds start their 12/24-month compliance clock from their own notification date, not from April 2025. If your organisation has not yet received an NKSC notification but operates in a sector covered by NIS2 Annex I or Annex II, voluntary registration and early compliance preparation reduces exposure during subsequent identification rounds. The NIS2 scope guidance covers the size thresholds and sector definitions used to determine which entities fall within Lithuania’s regulatory perimeter.
How to Appeal an NKSC Decision
NKSC enforcement decisions — binding corrective orders, fine impositions, monitoring officer designations, certification suspensions, and management function prohibitions — are administrative acts subject to judicial review under Lithuania’s general administrative procedure law. The appeal path operates in two stages.
Step 1: Regional Administrative Court. For most NKSC matters, the relevant court is the Vilnius Administrative Court. The entity must file its challenge within 30 days from the date the decision is pronounced or formally notified. The court reviews the NKSC’s legal basis for the decision, compliance with procedural requirements, and whether the measure is proportionate to the violation. A procedural defect in how the NKSC conducted its investigation can be grounds for quashing an otherwise substantively justified decision — which is why maintaining detailed records of all NKSC communications, audit interactions, and compliance steps matters from the first warning onward.
Step 2: Supreme Administrative Court of Lithuania. If the Regional Court upholds the NKSC’s decision, the entity may appeal to the Supreme Administrative Court within 30 days of the regional court’s ruling. The Supreme Administrative Court’s decision is final — no further judicial appeal route exists within the Lithuanian court system.
Three practical points for entities considering an appeal:
- Challenge the binding corrective order at Stage 2, not the initial warning. Warnings are not administrative decisions subject to immediate judicial challenge; binding orders are the first formally appealable act in the escalation sequence.
- Appealing a fine does not automatically suspend the underlying corrective order. Simultaneously complying with the corrective order while the appeal is pending prevents daily coercive penalties from continuing to accrue during what can be a multi-month court process.
- The 30-day appeal window is strict. Missing it forfeits the right to judicial challenge. Engaging qualified Lithuanian administrative law counsel immediately on receipt of an NKSC enforcement decision is the only reliable way to preserve appeal rights within the window.
Frequently Asked Questions
Does Lithuania’s NIS2 fine apply to the Lithuanian subsidiary or to the group’s global turnover?
The fine ceiling references “total worldwide annual turnover” of the entity subject to the obligation — meaning the legal entity registered and active in Lithuania, not its parent group’s consolidated revenue, unless the parent entity itself is the designated regulated entity. For corporate groups with a Lithuanian subsidiary, the 2% or 1.4% applies to that subsidiary’s worldwide turnover in the preceding financial year.
Can the NKSC fine us during the 12-month or 24-month grace period?
Yes, for obligations that fall outside the implementation timetable. The grace periods apply to deploying specific technical and organisational measures. The NKSC can still issue warnings and binding orders during those windows for obstructing an audit, failing to report a significant incident within Article 23 timelines, or failing to register following a notification. The grace period covers the pace of implementation, not immunity from enforcement during that period.
What if our organisation is subject to both DORA and NIS2?
Lithuanian financial entities regulated under DORA (Regulation (EU) 2022/2554) are supervised by the Bank of Lithuania and the Financial Market Supervisory Authority rather than NKSC for NIS2 obligations within DORA’s scope. NKSC retains jurisdiction over residual NIS2 obligations not fully addressed by DORA — primarily supply chain security requirements under Article 21(2)(d) and physical security measures under Article 21(2)(f). Entities in scope for both regimes should document which supervisor owns which obligation to avoid enforcement gaps.
For a comparative view of how fines and enforcement differ in the neighbouring Baltic state, see the Estonia NIS2 penalties and enforcement guide.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS 2 Directive Article 32 — Supervisory and Enforcement Measures for Essential Entities
- NIS 2 Directive Article 34 — Administrative Fines
- NIS 2 Directive Article 33 — Supervisory and Enforcement Measures for Important Entities
- NIS 2 Directive Article 20 — Governance
- Advisera: NIS2 Transposition in Lithuania: What Does the Lithuanian Cybersecurity Act Require?
- NIS2 Lithuania — what you need to know! (nis2certification.eu)
- Copla: NIS2 Directive Regulations and Implementation in Lithuania
- The Baltic Times: NIS2 in the Baltics: How Lithuania, Latvia, and Estonia Differ
- LRT: Cybersecurity Report Records More Attacks Against Lithuania (2024 data)
- Wikipedia: Energy in Lithuania
- Wikipedia: Supreme Administrative Court of Lithuania
- Legiscope: NIS2 Penalties: What Happens If You Don’t Comply
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
