execute other orders of the police issued on the basis of this law. Police orders with regard to
restriction of the provision of services to their recipients must be carried out no later than within
8 hours from the receipt of the police order;
5) assign a competent person or department responsible for the organisation and
assurance of cyber security and provide the National Cyber Security Centre with the contact
details of such person or department;
6) execute the orders of the National Cyber Security Centre set forth in Article 8 herein.
2. The provisions of this article shall not apply to small and very small undertakings as
defined in the Law on Small and Medium-sized Business Development which provide digital
services in the Republic of Lithuania and/or any other EU Member State.
Article 12. Special duties of cyber security entities
1. Managers of critical information infrastructure:
1) in accordance with the typical plan for cyber incident management in critical
information infrastructures, approve plans on cyber incident management in critical information
infrastructures and submit them to the National Cyber Security Centre;
2) notify digital service providers of negative impact on the operation of critical
information infrastructure which resulted from malfunctioning of communications and
information systems of digital service providers in accordance with the procedure established in
the National Cyber Incident Management Plan;
3) no less than once a calendar year test the functioning of measures intended for the
management of cyber incidents in critical information infrastructures and supply the results of
testing to the National Cyber Security System in accordance with the procedure established in
the description of organisational and technical cyber security requirements imposed on cyber
security entities;
4) provide conditions for the National Cyber Security Centre to implement and control
technical cyber security measures in critical information infrastructure and to put technical
measures into use with the aim to measure the resistance of critical information infrastructure to
cyber incidents.
2. Entities which control and/or manage the state’s information resources provide
conditions for the National Cyber Security Centre to implement and control technical cyber
security measures in the state’s information resources and to put technical measures into use with
the aim to measure the resistance of the state’s information resources to cyber incidents.
3. The providers of public communications networks and/or public digital
communications services publicly announce recommendations with regard to measures meant to