Skip to content

Compliance

Two legal texts, one operational calendar

NIS2 sets the European baseline. The Lithuanian Cybersecurity Law and its implementing Description turn that baseline into numbered requirements with hard deadlines — 90-day log retention, monthly log analysis, 24-hour signature deployment, six-monthly firewall review. This page converts the law into things the SOC does on a date.

EU baseline
Directive (EU) 2022/2555
National
Cybersecurity Law + Description
Authority
NKSC · CERT-LT
Log retention
≥ 90 calendar days

Legal footing

In Lithuanian law, the SOC is a group of named people

This is the most commonly misunderstood point, and it is worth getting exactly right. The National Cyber Incident Management Plan says that incident management at entity level is organised by performing a defined set of functions, and by the head of the entity appointing the persons who perform them — and it then names that appointed group the Saugumo operacijų centras, the Security Operations Centre.

So the law does not say “build a 24/7 facility”. It says: these functions must be performed, and you must appoint, by name, who performs them. The national centre’s own guidance lists establishing a SOC among the organisational duties, while its published questions and answers state that the framework does not explicitly mandate one. Both are reconciled by the appointment reading above.

The functions that definition attaches to are:

  • Methods of detecting cyber incidents, and their assessment
  • Organisation of incident management, and communication with interested parties
  • Responsibilities of the staff accountable for incident management
  • Evidence identification, collection, obtaining, reporting and preservation
  • Log administration and storage, with defined periodicities, and intrusion detection and prevention
  • Lessons-learned evaluation, and testing the plan’s effectiveness

There is also a segregation rule attached: the SOC must be independent of those responsible for the proper operation of the systems it monitors. And an outsourcing hook — where a provider delivers connected with incident management, the entity’s incident management plan must be agreed with that provider. An organisation cannot lawfully approve a plan its SOC provider has never seen.

InstrumentWhat it does
Kibernetinio saugumo įstatymas — the Cybersecurity LawRestated to transpose NIS2 and in force since 18 October 2024. Defines who is a cybersecurity subject, the duties, the roles that must be appointed, the reporting obligations, and the supervisory and sanctioning powers.
Kibernetinio saugumo reikalavimų aprašas (KSRA) — the Description of Cybersecurity RequirementsThe operative rulebook. The organisational and technical requirements themselves, including the log retention, monitoring, detection and account-hygiene obligations a SOC runs against.
National Cyber Incident Management PlanDefines what a large (significant) incident is in numeric terms, sets the national reporting path and content, and — importantly — is where the Security Operations Centre is defined.
Kibernetinio saugumo informacinė sistema (KSIS)The national cybersecurity information system. Registration in it is what makes the duties bite, and its incident platform is the reporting channel.
Four levels. Obligations, deadlines and filing duties attach at different ones, so it is worth being able to name each.

Duties begin at registration

A national divergence that matters more than it looks: an entity acquires the duties laid down for cybersecurity subjects only from the moment it is registered in the national cybersecurity information system. Every implementation runway is measured from that date, and it differs per entity. Ask for it at onboarding — it is the first date in your compliance calendar.

Entity tierWhat it meansConsequence
Essential entityGenerally large enterprises in the sectors of high criticality, plus specific entity types that qualify regardless of size.Proactive supervision — the authority does not have to wait for an incident. The heavier end of the requirement set applies, and the higher sanction ceiling.
Important entityMedium enterprises in the sectors of high criticality, and medium and large enterprises in the other critical sectors.Reactive supervision — action follows evidence of non-compliance. Broadly the same duties, with a lower sanction ceiling.
Out of scopeBelow the size thresholds and outside the entity types that qualify regardless of size.No direct duty — but you may still inherit requirements contractually, as a supplier to an entity that is in scope.
Classification decides which requirements bind and how deep the monitoring must go. Note that the national size thresholds are set by Lithuanian law rather than directly by the EU recommendation — verify the current figures before applying them.

Statutory roles

Four appointments, and the wall between them

The law names the roles and — unusually — states explicitly what they may not do. That prohibition is the most useful sentence in the whole framework for anyone who has ever been asked to both run the firewall and audit it.

Cybersecurity manager

Kibernetinio saugumo vadovas

Appointed by the head of the entity, and directly accountable to the head — not through the IT line.

Duties

  • Responsible for implementing the entity's compliance with the security requirements and the incident reporting obligations
  • Organises the conformity assessment against the requirements, using the authority's audit methodology
  • Ensures the cybersecurity policy documents are prepared and periodically updated
  • Coordinates investigations of cyber incidents

Constraints

  • May not perform network or information system administration, nor any role involving the maintenance and management of hardware or software
  • Must meet impeccable-reputation requirements, have no relevant administrative penalty within the last year, and hold at least two years of experience in IT, cybersecurity or a related field
  • May also act as the security officer for a specific system, and may serve across several entities
  • The role may be outsourced to a supplier — but accountability for compliance does not transfer with it

Security officer

Saugos įgaliotinis

Appointed by the head, responsible for a specific network and information system's compliance.

Duties

  • Carries the same requirement- and reporting-compliance duties, scoped to one system
  • May cover several networks and information systems

Constraints

  • Subject to the same prohibition on system administration duties
  • Subject to the same eligibility requirements as the cybersecurity manager

Administrator

Administratorius

Appointed by the head to maintain the networks and information systems and ensure they operate.

Duties

  • Management of user access rights
  • Maintenance and configuration of systems, databases, applications, firewalls and intrusion detection systems

Constraints

  • Deliberately separated from the cybersecurity manager and security officer roles — this is the statutory segregation of duties

Security Operations Centre

Saugumo operacijų centras

The head appoints the persons who perform the incident-management and logging functions. That appointed group is what the law calls the Security Operations Centre.

Duties

  • Detection of cyber incidents and their assessment
  • Organisation of incident management and communication with interested parties
  • Evidence identification, collection, obtaining, reporting and preservation
  • Log administration and storage, intrusion detection and prevention
  • Lessons-learned evaluation, and testing of the plan's effectiveness

Constraints

  • Must be independent of those responsible for the proper operation of the systems it monitors

Is the SOC Officer the cybersecurity manager?

Not necessarily, and the site does not assume it. The kibernetinio saugumo vadovas is a statutory appointment with eligibility criteria, a direct reporting line to the head of the entity, and an express prohibition on holding system administration duties. The SOC is the appointed group performing the detection and incident-management functions.

One person can hold the statutory role and lead the SOC. Neither may also be the system administrator. If your SOC Officer is the cybersecurity manager, the eligibility criteria apply to them; if they are a SOC lead reporting into that role, they do not automatically.

Outsourcing is permitted — accountability is not

The law expressly allows procuring the cybersecurity manager and security officer functions from a supplier. What it does not allow is transferring accountability: the head of the entity must still ensure compliance and supervise it, and must ensure any authorised person has the means to exercise what was delegated.

National layer

Where the national rules go beyond NIS2

NIS2 is a directive, so the operative obligations are always the national ones. Most of the text is transposed near-verbatim — but not all of it, and the additions are the ones that catch people who read only the directive.

Duties begin at registration, not at self-identification

An entity acquires the duties laid down for cybersecurity subjects only from the moment it is registered in the national cybersecurity information system.

So whatAsk for the registration date at onboarding. Every implementation runway is measured from it, and it differs per entity.

Non-large incidents are reportable too

The national rules require reporting of cyber incidents that do not meet the large-incident criteria, on the same 72-hour basis. NIS2 mandates only significant incidents.

So whatDo not build your notification decision purely from the NIS2 significance test. The national threshold to report is lower.

Management training at least every two years

Members of the management body, the head, and any authorised person must complete cybersecurity training at least once every two years, and must ensure continuous employee education.

So whatThis is firmer than the NIS2 wording. Track it, and put the completion evidence in the report pack.

Independent audit at least every three years

A cybersecurity audit must be carried out at least once every three years under the authority's methodology, by an independent, appropriately certified auditor.

So whatDiary it. An audit that has never happened is one of the easiest findings for a supervisor to make.

The authority may place its own sensors in essential entities

To monitor essential entities and identify threats and incidents, the national centre deploys and manages technical cybersecurity measures inside those entities' systems. Essential entities must create the conditions for it. Important entities may request the same to help contain an incident.

So whatKnow whether this applies to you. It changes your architecture, your data-flow diagram and your privacy assessment — and it means someone else has visibility of your estate.

Policy documents need no pre-approval

There is no obligation to agree the cybersecurity policy documents with the authority in advance. What is required is filing the approval data, and producing the documents themselves within five working days if asked during an inspection.

So whatDo not wait for approval that will never come. Approve internally, file the metadata, and keep the documents retrievable at five working days' notice.

The head can, ultimately, be suspended by a court

On the authority's application, a court may temporarily suspend the head of an essential entity from office — but only for the most serious category of violation, and only after other enforcement measures have proven ineffective.

So whatThis is the sharp end of management-body accountability. It is also why your evidence trail is their protection, not just your defence.

Where you report

The national cyber incident management platform, a subsystem of the national cybersecurity information system. Incidents are reported by registering them there.

Fallback channels

  • A form completed in the platform
  • A form on the authority's website
  • The email address designated by the authority
  • By telephone

Fallbacks exist precisely because the incident itself may be what prevents automated reporting. Know them before you need them, and test that you can reach at least one.

What the initial assessment must state

  • Which service disruptions the entity suffered or may suffer — naming the services and the scope of the disruption
  • What financial losses were or may be suffered — stating the amount
  • Whether the incident affected or may affect other persons by causing material or non-material damage — and if so, naming them

Sanction ceilings

  • Essential entityUp to EUR 10 000 000 or 2% of total worldwide annual turnover — whichever is greater
  • Important entityUp to EUR 7 000 000 or 1.4% of total worldwide annual turnover — whichever is greater
  • Budgetary institution that is an essential entityA nationally specific cap expressed as a share of its budget rather than of turnover

NIS2 Article 21

Ten measure areas, and where the SOC lands in each

Article 21 requires appropriate and proportionate technical, operational and organisational measures across ten areas. The SOC does not own all ten — but it produces the evidence for most of them.

a

Policies on risk analysis and information system security

Supplies the threat picture the analysis is built on, and reports where monitored reality diverges from what the policy assumes.

SOC evidences

b

Incident handling

This is the SOC. Detection, triage, escalation, containment, eradication, recovery coordination and closure — with the timestamps that prove each.

SOC operates

c

Business continuity — backup management, disaster recovery, crisis management

Triggers the continuity plan from the incident side, monitors the health of duplicated equipment and links, and contributes evidence to the continuity test report.

SOC operates

d

Supply chain security, including direct suppliers and service providers

Monitors third-party access sessions and connectivity, and consumes supplier incident notifications. Supply chain compromise is its own incident group.

SOC operates

e

Security in acquisition, development and maintenance, including vulnerability handling and disclosure

Keeps attack signatures current to the published deadlines, monitors for exploitation of known vulnerabilities, and feeds observed exposure into the remediation queue.

SOC operates

f

Policies and procedures to assess the effectiveness of the risk-management measures

Runs the test: exercises, atomic tests, purple teaming, and honest reporting of what the detection stack did not catch. This is an obligation to test, not to document.

SOC operates

g

Basic cyber hygiene practices and cybersecurity training

Turns real incidents into training content, and reports the behaviours that keep generating incidents.

SOC evidences

h

Policies and procedures on the use of cryptography and, where appropriate, encryption

Onboards cryptographic key management audit records as a log source, and verifies that backup encryption keys are held separately from the backups.

SOC evidences

i

Human resources security, access control policies and asset management

Detects and reports what the policies are failing to enforce: privileged actions from non-privileged accounts, dormant accounts, shared accounts, activity from accounts that should have been revoked.

SOC operates

j

Multi-factor or continuous authentication, secured communications and emergency communications

Reports MFA coverage gaps from telemetry, and maintains an out-of-band communication path for use when the primary estate is untrusted.

SOC operates

Measure (f) is the one that catches people out

Article 21 requires policies and procedures to assess the effectiveness of the risk-management measures. Not their existence — their effectiveness. That is a testing obligation, and the SOC is where the test happens: exercises, atomic tests, purple teaming, and the honest reporting of what the detection stack failed to catch.

Article 23 · national Art. 18

The reporting timeline runs from awareness

Not from the alert. Not from confirmation. From the point at which the organisation became aware of a significant incident — which is why that timestamp deserves a mandatory field in your incident record and a written definition of who can set it. Lithuania transposes these stages near-verbatim, then adds obligations of its own.

24 hours

Early warning

Submitted without undue delay and in any event within 24 hours of becoming aware. It must indicate whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have a cross-border impact. Detail is not expected at this stage — speed is.

Art. 23(4)(a)

72 hours

Incident notification

Updates the early warning and gives an initial assessment of the incident, including its severity and impact and, where available, the indicators of compromise.

Art. 23(4)(b)

On request

Intermediate report

Relevant status updates, provided at the request of the CSIRT or the competent authority.

Art. 23(4)(c)

1 month

Final report

Due no later than one month after the incident notification. A detailed description of the incident, its severity and impact; the type of threat or root cause that likely triggered it; the mitigation measures applied and ongoing; and, where applicable, its cross-border impact.

Art. 23(4)(d)

If still ongoing

Progress report, then final

Where the incident is still ongoing when the final report falls due, a progress report is submitted at that point and the final report follows within one month of the incident being handled. The Lithuanian text phrases the trigger as one month from the day the incident was contained.

Art. 23(4)(e) · national Art. 18(4)(5)

24 hours

Trust service providers — accelerated

A derogation: a trust service provider must submit the incident notification within 24 hours of becoming aware of a significant incident affecting its trust services. In practice this collapses the early warning and the notification into a single 24-hour obligation.

Art. 23(4), second subparagraph

72 hours

Non-large incidents — national addition

Lithuania also requires reporting of incidents that do not meet the large-incident criteria, carrying the same information as the standard notification. NIS2 mandates only significant incidents, so this obligation is invisible if you read the directive alone.

National law — no NIS2 equivalent

24 hours where possible

Feedback owed back to you

The obligation runs both ways: the national response team should give initial feedback on the incident within 24 hours of the early warning and, on request, guidance on mitigation, further technical support, and — where the incident is suspected to be criminal — guidance on reporting it to law enforcement. Ask for it; it is a resource, not a courtesy.

Art. 23(5)

Notification clock

Enter the moment your organisation became aware of a significant incident. Awareness — not the first alert, not the start of the investigation — is what starts the statutory clock.

    An intermediate report may additionally be required at the authority’s request, and where an incident is still ongoing at the one-month mark the final report is due one month after it is handled. Trust service providers report within 24 hours rather than 72. The Lithuanian text contains a cross-reference that leaves the final-report start point arguable between the early warning and the notification — the safe operational assumption is the earlier of the two, which is what this clock uses. Verify against the consolidated national text before relying on any of it for a filing.

    Impact classification

    What decides whether a report is owed

    The national rules classify by numeric criteria. The model below is the one in operational use in Lithuanian SOC documentation — note the asymmetry, since under pressure it is exactly the kind of detail that gets inverted: high and medium impact each require two or more criteria to be met, while insignificant impact requires only one.

    Verify these thresholds against the current national plan

    This is the area where the national text has moved most. The current National Cyber Incident Management Plan defines a large incident as major service disruption plus at least one qualifying condition — disruption across Lithuania or in at least one other EU or NATO country, operation disrupted for two hours or more, or a threshold number of affected recipients. It also expresses the material damage threshold in basic social benefit units, whose value is set annually, rather than as a fixed euro figure.

    Treat the table below as a working classification model that has served real SOC operations, and confirm every number against the consolidated text in force before you rely on it for a filing.

    High impact

    2+ criteria

    Two or more criteria must be met

    • System disrupted for 2 hours or more
    • 1000 or more affected service recipients or workstations, or 25% or more
    • Service disrupted across the whole country and/or in one or more other EU countries
    • Confidentiality and/or integrity of information or of the system breached
    • Losses of EUR 500,000 or more

    What you oweA cyber incident investigation report is owed, and the notification must state the exact time at which that report will be provided.

    Medium impact

    2+ criteria

    Two or more criteria must be met

    • System disrupted for 1 hour or more but less than 2 hours
    • Fewer than 1000 affected service recipients or workstations, or under 25%
    • Service disrupted in part of the country's territory
    • Confidentiality and/or integrity of information or of the system breached
    • Losses of EUR 250,000 or more but under EUR 500,000

    What you oweA cyber incident investigation report is owed, on the same basis as a high-impact incident.

    Insignificant impact

    1+ criterion

    At least one criterion must be met

    • System disrupted for under 1 hour
    • Fewer than 100 affected service recipients or workstations, or under 5%
    • The service is being provided, but is disrupted
    • Losses under EUR 250,000

    What you oweNo investigation report. Aggregated counts per group are submitted on the first working day of each calendar month.

    Qualifiers to tick where known

    • The adverse impact was caused by disruptions in the networks and information systems of digital service providers.
    • The incident may have features of criminal activity.
    • The incident may be related to a personal data security breach.

    The third one is a trigger, not a note: a possible personal data breach brings the data protection reporting route alongside the cybersecurity one, on its own clock.

    Classification

    The incident taxonomy, in full

    Six groups. This vocabulary does double duty — it is what you enter on the notification form, and it is the definition of what your SOC has undertaken to detect. Treat those as one thing: what you can classify is what you have promised to catch.

    No.GroupSub-groupDefinition
    1Malicious software / codeSoftware, or part of software, that assists in unlawfully connecting to a network and information system, taking it over and controlling it, disrupting or altering its operation, destroying, damaging, deleting or altering digital data, removing or restricting the ability to use it, or unlawfully appropriating non-public digital data.
    1.1Malicious software / codeAdvanced persistent threat (APT)Advanced malicious software.
    1.2Malicious software / codeWiper / ransomwareProgram code that encrypts or destroys the data of the network and information system, or demands a ransom.
    1.3Malicious software / codeIntruder-controlled system componentsParts of the network and information system that are actively controlled by intruders.
    1.4Malicious software / codeMalware distributionDistribution of malicious software.
    2Information gatheringReconnaissance or other suspicious activity aimed at observing and collecting information, discovering weak points, and carrying out threatening actions.
    3Intrusion attemptsAn attempt to intrude, or to disrupt the operation of the network and information system, by exploiting known vulnerabilities or by guessing passwords (brute force).
    3.1Intrusion attemptsZero-day exploitationOne or more previously unknown vulnerabilities are exploited.
    3.2Intrusion attemptsReconnaissance or other malicious activityReconnaissance of the network and information system or other malicious activity — port scanning, password guessing, malware distribution and similar.
    3.3Intrusion attemptsKnown vulnerability exploitationKnown and publicly published vulnerabilities are exploited.
    4IntrusionsA successful intrusion and/or unauthorised use of the network and information system, of application software, or of a service.
    4.1IntrusionsActions against the system or its security measuresActions against the system or its security measures; appropriation of information; destruction; damage that disrupts uninterrupted service provision, affects the reliability of processed information, distorts content, or reduces user trust.
    4.2IntrusionsUnauthorised access obtainedUnauthorised access is obtained to the network and information system, to application software, or to a service.
    5Service disruption, availability breachesActions that disrupt the operation of the network and information system or the services provided (DoS, DDoS); damage to the system or a part of it that disrupts the system and/or its services.
    5.1Service disruption, availability breachesInterruption or downtime breachInterruption of the services provided, or exceeding of the maximum permissible service downtime.
    5.2Service disruption, availability breachesDegradation of continuous provisionDisruption of uninterrupted service provision that may affect the availability of processed information and/or of the services provided.
    6Supply chain attacksThe infrastructure of third parties providing services to the manager and/or processor of the network and information system is exploited in order to gain or exert influence over the service recipient's infrastructure.
    Group 3 covers attempts; group 4 covers success. The dividing line is whether unauthorised access was actually obtained. Group 6 is the only group defined by the origin of the compromise rather than its technique.

    Coverage, in law

    The log events you are required to capture

    This list is more useful than any vendor's recommended data sources: it is the legal floor of your visibility. Hold it as a catalogue with one row per event class per system, and a collection status against each. That catalogue is your compliance evidence.

    Four fields, or it is not onboarded

    • Event date and precise time
    • Event type — information, error, security message, system message, warning
    • Identification data of the user, administrator and/or device involved
    • Event description

    Use these as parser acceptance criteria. A source that cannot map all four is a source you cannot investigate with — and cannot attribute from.

    RefEvent classWhat the SOC does with it
    1.1Powering on, off or rebooting of system components — servers, virtual servers, firewalls, routers, switches and other components identified as importantInfrastructure device collection; flag device classes that cannot emit the event
    1.2User and administrator authentication eventsBrute force, password spraying, anomalous authentication, impossible travel
    1.3Account creation and changes to access rightsIdentity-store change detection; feeds the account hygiene reporting
    1.4Actions performed by administratorsPrivileged activity monitoring on a separate alerting and retention tier
    1.5Scheduled task events created and executed in operating systemsPersistence detection
    1.6Group policy changesConfiguration drift detection
    1.7Firewall rule changesCorrelate against change records — a rule change with no approved change is an alert
    1.8Enabling and disabling of the log collection functionLog-source health and 'collector silent' alerting
    1.9Operating system time and date changesTime-integrity alerting; protects the evidential value of every other log
    1.10Enabling and disabling of security systems (antivirus, intrusion detection)Defence-evasion detection; endpoint agent health
    1.11Process or service events in operating systemsCore endpoint telemetry underpinning most of the detection library
    1.12Authentication events of endpoint devicesDevice-level authentication monitoring; rogue-device correlation
    1.13Viewing, deleting, creating or modifying log recordsAnti-tamper alerting on the log store itself

    The compliance calendar

    Every recurring obligation, with its clock

    This is the table to put on the wall. Anything marked as SOC-operated is yours to run; the rest is yours to chase, because when it is not done the finding still lands in your report.

    CadenceObligationOwnerSource
    ContinuousCentrally managed real-time malware detection and monitoring across servers and workstations.SOCTechnical requirement 41
    ContinuousMonitoring of free memory and disk space, load and resource use, with notification of responsible persons at threshold values.SOCTechnical requirement 43
    ContinuousMonitoring of the technical condition of duplicated critical equipment, network nodes and communication lines.SOCTechnical requirement 20
    Immediately — max 1 working dayAutomated alert to the cybersecurity manager and/or security officer when audit data capture stops.SOCTechnical requirement 6
    Within 24 hoursDeploy the newest attack signatures after the manufacturer publishes them.SOCTechnical requirement 22
    Within 72 hoursDeploy the newest attack signatures where the entity has decided to test deployment and impact first.SOCTechnical requirement 22
    ImmediatelyRemediate a vulnerability assessed as highly significant to the operation of the systems.Entity / ITDescription para. 45.7
    MonthlyAn authorised person analyses log data, and reports deviations to the cybersecurity manager and/or security officer.SOCTechnical requirement 11
    Monthly (first working day)Submit aggregated counts of insignificant-impact incidents per group to the authority.SOCNational incident reporting rules
    After 2 months unusedSuspend administrator rights.Entity / ITTechnical requirement 63
    After 3 months unusedSuspend user rights.Entity / ITTechnical requirement 62
    Every 6 monthsDetailed analysis of firewall rules.Entity / ITTechnical requirement 15
    Every 6 monthsFull vulnerability scan of the network and information system.Entity / ITDescription para. 45.8
    AnnuallyRisk assessment — and additionally on material organisational change and after a major cyber incident.Entity / ITDescription para. 9
    AnnuallyCompliance assessment against the Law, the Description and the entity's own policy documents, producing an approved report and a remediation plan for any non-conformities.Entity / ITDescription paras. 48.1, 48.2
    AnnuallyAll employees complete cyber hygiene training.Entity / ITDescription para. 52
    Every 3 yearsCybersecurity audit.Entity / ITCybersecurity Law Art. 14(8); Description para. 48.3
    Retention — min. 90 calendar daysLog records retained; deletion or alteration before expiry is prohibited. Accounts may only be deleted after this period has passed.SOCTechnical requirements 7, 8, 65
    Within 5 working daysFile approvals and respond to authority document requests through the national cybersecurity information system.Entity / ITDescription paras. 5, 6, 13, 15, 29, 30, 50
    12 months from registrationImplement the organisational cybersecurity requirements of the Description.Entity / ITDescription para. 71
    24 months from registrationImplement the technical cybersecurity requirements (the numbered requirement set).SOCDescription para. 72
    Source references are to the Lithuanian Description of Cybersecurity Requirements and its numbered technical requirements. Verify each against the current consolidated text before relying on it.