New safeguards for Category D critical infrastructure, a revised test for critical IT service providers, and clarification of the beneficial ownership threshold

On 8 October 2026, the Latvian Parliament (Saeima) adopted amendments to the National Security Law (“NSL”). The amendments strengthen safeguards for critical infrastructure, refine the scope of companies that may be designated as significant to national security and clarify the participation threshold used when identifying beneficial owners under the national security regime.

New ownership and financing safeguards for Category D critical infrastructure

Under the current wording of the NSL, the ownership restrictions for persons affiliated with Russia or Belarus applied to Categories A, B and C, and to critical infrastructure of particular European significance. The amendments extend targeted safeguards to entities designated as part of Category D critical infrastructure.

Category D covers sectoral critical infrastructure whose destruction, reduced operating capacity or interruption of critical services during a declared state of emergency or war could materially endanger public and national security, such as, for example, production or retail of food products, heating or medical supplies. Persons affiliated with Russia or Belarus will be prohibited from acquiring a direct or indirect qualifying holding or decisive influence in an entity designated as part of Category D critical infrastructure. Such persons may also not be the entity’s beneficial owners or acquire indirect influence over it.

An entity designated as part of Category D critical infrastructure must also notify the competent sectoral ministry if it receives a loan exceeding 10% of its assets from:

  • a natural person who is a national of a foreign country other than an EU, EFTA, NATO or OECD member state; or
  • a legal entity whose beneficial owner is a national of such a third country.

This is a notification requirement rather than a prior approval requirement applicable to owners or possessors of category A, B, and C critical infrastructure. In practice, affected borrowers should verify the lender’s nationality and, where the lender is a legal entity, the nationality of its beneficial owner before entering into the financing.

Revised scope for critical IT service providers

The current provision covers entities that process datasets included in state critical infrastructure systems. The amended Section 37(12) NSL adopts a more functional test, covering providers of IT services material to the operation of critical infrastructure and providers of IT solutions used to process datasets included in critical infrastructure.

The amended provision does not automatically bring every critical-infrastructure IT supplier within the national security regime. A provider will be in scope only if the Cabinet of Ministers, acting on an opinion of a state security institution, individually designates it as a company, foundation, or association of significance to national security. Financial market participants remain excluded.

Clarification of the beneficial ownership test

The amendments clarify that, for the NSL purposes, beneficial ownership must be assessed by reference to the threshold for a qualifying holding. This concept generally captures a direct or indirect holding of 10% or more of the capital or voting rights, as well as other means of exercising significant influence.

Accordingly, a natural person holding 10% or more – directly or indirectly – in a company of significance to national security may need to be identified as its beneficial owner for this specific regime, even if the general anti-money laundering threshold of more than 25% is not met. The analysis is not purely numerical: control rights, shareholder arrangements and influence exercised through intermediate entities must also be considered.

What should businesses do?

  • Review ownership and control. Identify natural persons with a direct or indirect holding of 10% or more and assess any contractual or governance rights that may confer significant influence.
  • Review financing arrangements. Entities designated as part of Category D critical infrastructure should implement checks on the lender’s nationality and beneficial ownership and identify loans exceeding 10% of assets.
  • Assess IT service exposure. Providers supporting the operation of critical infrastructure or supplying solutions used to process critical-infrastructure datasets should assess whether their services may fall within the revised designation mechanism.
  • Screen transactions early. Share acquisitions, restructurings, changes in beneficial ownership and financing transactions involving critical infrastructure should be reviewed for Latvian national security implications at an early stage.
  • Document the assessment. Companies should retain a clear record of ownership calculations, control rights and the basis for concluding whether notification or approval is required.

How COBALT can help

COBALT advises investors, infrastructure operators, technology providers and financing parties on Latvian foreign investment screening and national security matters. Our team can assist with transaction structuring, ownership and control assessments, regulatory filings and engagement with the competent authorities.

Contact COBALT’s Specialist Counsel Mārtiņš Tarlaps.