NIS2 Country Guide

NIS2 Estonia: Küberturvalisuse seadus 2026

Estonia transposed NIS2 by amending the Küberturvalisuse seadus (Cybersecurity Act, KüTS). The amending act was published as RT I, 30.12.2025, 4 and the new regime has applied since 1 January 2026. This page sets out the three-month notification duty, the three-year runway to full conformity, the 24h/72h reporting chain, and what the Riigi Infosüsteemi Amet (RIA) can actually impose - which in Estonia is a misdemeanour penalty and a repeatable levy, not an administrative fine.

Estonia In force: 1 January 2026 Text in force to: 30 Sept 2026 Regulator: RIA Last updated: 13 August 2026

1 Introduction: NIS2 Directive & the Estonian context

Estonia is one of the most digitally advanced EU Member States, known for its electronic governance framework and robust cybersecurity infrastructure. To align with NIS2, Estonia amended its existing Cybersecurity Act, expanding obligations and strengthening security governance for both public and private sectors.

The framework that matters is the one in force from 1 January 2026. Two features of it catch organisations out. First, the deadlines are relative - three months to notify RIA and three years to reach conformity, both counted from the day you meet the definition, so there is no single national compliance date. Second, Estonia's penalties are misdemeanour penalties, not administrative fines, which changes the procedure that applies to you.

Currency: the consolidated text this page is written from is stated by Riigi Teataja to be in force 1 January 2026 to 30 September 2026 - so a further version already takes effect on 1 October 2026. We say what the current text says, and flag that it has an expiry.
New to NIS2? Start with our guides: What is NIS2? and NIS vs NIS2.

2 NIS2 implementation in Estonia

Estonia implemented NIS2 by amending the Küberturvalisuse seadus - the Cybersecurity Act, abbreviated KüTS - which was originally passed on 9 May 2018. The NIS2 amending act was published as RT I, 30.12.2025, 4 and entered into force on 1 January 2026, rewriting 89 provisions of the Act.

The amendments broaden the regulated sectors, introduce the essential/important entity model, move the security measures from a service-by-service basis to the organisation as a whole, and reinforce the supervisory powers of the Riigi Infosüsteemi Amet (RIA).

On the English text. Riigi Teataja publishes an official English translation of the KüTS (published 28 January 2026 for the version in force from 1 January 2026), and it is the best English source there is. It also states plainly that translations have no legal force and cannot be used in official proceedings - the Estonian text governs.

Status

Transposed and in force since 1 January 2026. The consolidated text is stated to run only to 30 September 2026, so a further version is already scheduled.

Legal structure

One act. The Küberturvalisuse seadus carries scope, the security measures (Section 7), incident notification (Section 8), supervision (Section Section 14-17) and the penalties (Section Section 18² and 18³), with the notification data and procedure set by ministerial regulation.

Supervisory approach

RIA does nearly all of it - competent authority, single point of contact, CSIRT, large-scale crisis management and national coordinator for vulnerability disclosure. Complaints are reviewed by the Consumer Protection and Technical Regulatory Authority.

3 Who is in scope

Estonia applies the NIS2 essential/important model, with obligations corresponding to sector, service criticality, and organisational size thresholds.

Who is in scope?

  • Entities in NIS2 Annex I sectors (energy, health, water, digital infrastructure, public administration, etc.).
  • Entities in Annex II sectors (food, postal/courier services, manufacturing of critical goods, research, etc.).
  • Medium and large enterprises meeting NIS2 thresholds.
  • Entities covered regardless of size: DNS, TLD registries, trust-service providers, major cloud and data-centre operators.

Core obligations

  • Implement risk-management measures aligned with NIS2 Annex I.
  • Ensure monitoring, detection, and reporting of significant incidents to RIA/CSIRT.
  • Develop and maintain cybersecurity documentation and incident-response plans.
  • Implement supply-chain and third-party cybersecurity controls.
  • Ensure management-level cybersecurity oversight and training.

Framework alignment

While not mandatory, using ISO/IEC 27001 or NIST CSF supports readiness and structured compliance.

We print no entity count. Published guides put the Estonian scope at 5,500-7,000 or at about 6,500 entities. Neither figure is traceable to RIA, and we would rather state nothing than a number that gets quoted back at us. What the Act does say is that RIA compiles its list every two years (Section 3¹(2)) and reports the counts to the European Commission.

4 Notifying RIA: the three-month duty

Estonia does not wait for you to be designated. Section 3¹(1) requires a service provider to notify RIA itself, and section 4¹ gives it three months from the day it first meets the characteristics of a service provider.

What you must submit

  • Name and registry code.
  • Address of the place of business and up-to-date contact details, including e-mail addresses, Internet Protocol address ranges and telephone numbers.
  • The relevant Annex I or II sector and subsector.
  • A list of the countries in which you provide services within the Directive's scope.

Keeping it current

Changes must be notified without delay and no later than two weeks after the change was made (Section 3¹(4)). RIA itself compiles the list every two years, so the currency of the register depends on you, not on it.

The list is not public

Section 3¹(3) marks the information as intended for internal use for the purposes of the Public Information Act. Being on the list is not a matter of public record - a question boards ask and few guides answer.

For those already in scope on 1 January 2026, section 28¹(1) ran the same three months from entry into force - so that deadline fell on 1 April 2026. If you met the definition then and have not notified RIA, the duty is overdue, not waiting.

5 The three-year conformity runway

Notifying RIA and complying with the Act are two different clocks, and the second is long. Estonia gives three years to bring activities into conformity - one of the most generous runways in the EU, and the result of an extension argued for during the Bill's passage.

Duty Deadline Provision
Notify RIA under Section 3¹(1) 3 months from meeting the characteristics of a service provider Section 4¹(1)
Bring activities into conformity with the Act and its implementing rules 3 years on the same trigger Section 4¹(3)
The same, for entities already in scope on 1 January 2026 3 months (so 1 April 2026) and 3 years (so 1 January 2029) Section 28¹(1) and (3)
Providers of a vital service Not three years - the time limit is set under Section 38(13)(3) of the Emergency Act Section 4¹(4), Section 28¹(4)
The clocks are relative, not calendar. An organisation that first meets the definition in 2027 gets its own three months and its own three years. There is no single national compliance date for Estonia, which is why any guide printing one is describing the transitional cohort only.

6 Your management board's own duty

Section 6¹ puts a duty on the board itself, and the sanction for ignoring it is unusual: it does not fine you, it spreads the liability.

  • Designate at least one member of the management board who approves the security measures, oversees their implementation and is responsible for them.
  • Give RIA that person's name and contact details on request.
  • That member must undergo regular training sufficient to understand and assess the risks, their impact on your services, and how they are managed (Section 6¹(2)).
  • If you designate nobody, the obligations apply to every member of the board (Section 6¹(3)).
  • Where the provider's legal form means there is no management board, the duties fall on whoever performs management functions; for a sole proprietor, on that person (Section 6¹(4)).
  • The duty to designate does not apply where the provider has only one board member - there is nobody to choose between.

7 Authorities, CSIRT & who supervises you

Estonia is the most centralised model on this site: section 5(3) gives RIA the competent authority, single point of contact, CSIRT, crisis-management and vulnerability-disclosure roles all at once. The Act names its other bodies precisely, so the vague "various authorities" line that circulates does not survive it.

Role Authority Notes
Competent authority, Single Point of Contact, CSIRT, crisis management and coordinator for coordinated vulnerability disclosure Riigi Infosüsteemi Amet (RIA) Section 5(3) assigns RIA all five roles - Articles 8(1), 8(3), 9(1), 10(1) and 12(1) of the Directive - plus participation in the CSIRT network. CERT-EE is RIA's incident-response unit, not a separately designated body, which is why the Act names only RIA.
Complaint review Consumer Protection and Technical Regulatory Authority Section 17² sets the term for reviewing complaints. A second named body, and one no published guide mentions.
Competent authority for its own domain A security authority Section 5(4): performs the Article 8(1) tasks to the extent provided in section 14. Security authorities also notify incidents through their own channel (Section 8(10)).
Certification and conformity assessment National cybersecurity certification authority; conformity assessment bodies Sections 13¹ and 13², operating under Regulation (EU) 2019/881 - breach of which is a separate offence under section 18¹.

8 Incident reporting: 24h / 72h / one month

Section 8 sets the chain, and Estonia's trigger is lower than the Directive's baseline in two distinct ways - one about what you must presume, and one about what your suppliers must tell you.

Stage Deadline Notes
Initial notification 24 hours from becoming aware Submitted to RIA. Security authorities notify through their own channel instead.
Incident notification 72 hours from becoming aware Updates the initial notification with a specified overview of the circumstances.
Trust service providers 24 hours, not 72 Section 8(4²) - the trust-service derogation, tighter rather than looser.
Interim report At RIA's request, before the final report Section 8(4³).
Final report One month from the 72-hour notification If the incident is unresolved at that point, the report counts as an interim report and a new final report is due one month after resolution.
You report on reasonable presumption, not on certainty. Section 8(1)(2) extends the 24-hour duty to an incident whose significant impact "is not obvious but can be reasonably presumed". Waiting for confirmation of impact is not a defence to the clock.
If you outsource, the clock passes through to your supplier. Section 8(1¹): where you authorise another person to manage your system or host it with them, you are responsible for ensuring that person notifies you within 24 hours of becoming aware. That is a contractual obligation you have to have written down before an incident, not after.

An incident is significant if any one of six tests in section 8(2) is met - and the first of them is your own risk assessment: impact "at least severe according to the severity of consequences determined in the system risk assessment" prepared under section 7(1)(1). The others cover breaching the maximum permitted disruption time, disrupting another provider's service, having to invoke extraordinary continuity measures, significant damage to you or your users, and the European Commission's implementing act. Section 8(3) adds that disruption in at least one more Member State is always significant.

Section 8(6) lets RIA inform the public of the incident itself, or require you to do so, after consulting you.

9 NIS2 timeline & key dates (Estonia)

27 Dec 2022 — Directive (EU) 2022/2555 (NIS2) is published in the Official Journal of the European Union.
17 Oct 2024 — EU deadline for Member States to transpose NIS2 into national law (Estonia did not meet this deadline).
2023–2024 — Drafting and consultation on amendments to the Estonian Cybersecurity Act in preparation for NIS2 alignment.
Dec 2025 — The Riigikogu passes the amendments to the Küberturvalisuse seadus; published as RT I, 30.12.2025, 4.
1 Jan 2026 — The amended Küberturvalisuse seadus enters into force, rewriting 89 provisions.
28 Jan 2026 — Riigi Teataja publishes the official English translation of the version in force.
1 Apr 2026 — Three-month deadline for entities already in scope to notify RIA under section 3¹(1) (section 28¹(1)).
30 Sept 2026 — The consolidated text in force today is stated to run only to this date; a further version takes effect 1 October 2026.
1 Jan 2029 — Three-year deadline for the transitional cohort to bring activities into full conformity (section 28¹(3)).
Rolling, per entity — anyone first meeting the definition later gets their own three months and three years.

10 Sector-specific notes for Estonia

  • Energy: electricity and gas infrastructure classified as essential.
  • Digital infrastructure: Estonia prioritises e-government and digital identity services.
  • Finance: close supervision through joint oversight with financial regulators.
  • Healthcare: hospitals and medical data processors face strict requirements.
  • Public services: strong focus on continuity of digital public services (X-Road ecosystem).
  • Vital services: providers of a vital service do not get the three-year runway - their deadline is set under section 38(13)(3) of the Emergency Act, and can be shorter.
  • Cross-border electricity: sections 18⁴ and 18⁵ create separate offences for entities in this field and for their legal representatives personally - the only place in the Act where a named individual is a distinct offender.
  • Trust services: the incident notification deadline is 24 hours, not 72 (section 8(4²)).

11 Penalties & fines

Two things about Estonian penalties are routinely got wrong. They are misdemeanour penalties, not administrative fines - sections 18² and 18³ are drafted as offences and section 19 assigns extra-judicial proceedings. And they attach to a closed list of duties, not to the Act as a whole.

Provision Who Maximum
Section 18²(1) Essential entity up to EUR 10,000,000
Section 18²(2) The same act by a legal person up to EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher
Section 18³(1) Important entity up to EUR 7,000,000
Section 18³(2) The same act by a legal person up to EUR 7,000,000 or 1.4%, whichever is higher
Section 18⁴ and Section 18⁵ Entities in cross-border electricity, and their legal representatives Separate offence categories, including personal liability for the representative
Section 18¹ Any entity A separate offence for breaching Regulation (EU) 2019/881 (the Cybersecurity Act)
The fine reaches a closed list, and it is short. Sections 18² and 18³ bite only on breaches of section 7(1), (2), (3), (5) or (7) - the security measures - and section 8(1), (1¹), (4¹), (4²), (4³), (5), (7) or (8¹) - the notification duties. Much of the Act carries no fine at all, which is worth knowing before treating every provision as equally exposed.

12 Supervision & the non-compliance levy

For a continuing breach the headline fine is rarely the operative provision. Section 17¹ is.

EUR 70,000, repeatable

On failure to comply with a compliance notice, the upper limit of the non-compliance levy is EUR 70,000 for each imposition, under the rules in the Substitutional Performance and Non-Compliance Levies Act. It can be imposed again, which is what makes it effective against an entity that simply does not act.

State and administrative supervision

Sections 14 to 17 split supervision into state supervision and administrative supervision, with special measures in section 15 and, in section 16, specific powers for countering an immediate serious threat.

Complaints and cross-border work

Section 17² gives the Consumer Protection and Technical Regulatory Authority the complaint-review role; section 17³ provides mutual assistance where an entity operates in more than one Member State; section 17⁶ covers peer review under Article 19 of the Directive.

13 Voluntary notification & vulnerability disclosure

Not every route to RIA is compulsory, and two of the voluntary ones are worth using.

  • Voluntary notification (Section 8¹). RIA may receive notifications outside the mandatory regime - the channel Denmark and Lithuania also provide, and a way to put an incident on the record without conceding that the significance threshold was met.
  • Coordinated vulnerability disclosure. Section 5(3)(4) makes RIA the national coordinator for the purposes of Article 12(1) of the Directive, so there is a defined route for reporting a vulnerability in someone else's product or service.
  • Information-sharing arrangements (Section 17⁵). The Act expressly contemplates service providers and others entering cybersecurity information-sharing arrangements between themselves.
  • The cyber incident registry (Section 13). Incidents notified to RIA are recorded in a statutory registry.

14 How Estonia differs from the Directive

Six features of the Estonian regime are not obvious from reading NIS2, and each changes what a compliance programme has to do.

  • The penalties are misdemeanour penalties, not administrative fines - a different procedure, with extra-judicial proceedings under section 19.
  • The runway is three years, among the most generous in the EU, and it is relative - counted from when you meet the definition, not from a national date.
  • The EUR 70,000 non-compliance levy is repeatable per imposition, and is the provision that actually applies pressure on a continuing breach.
  • You report on reasonable presumption of significant impact, not on established impact - and your own risk assessment defines the threshold.
  • Your outsourcing provider owes you a 24-hour notification, and ensuring that is your statutory responsibility.
  • Failing to designate a responsible board member spreads the duty to the whole board rather than attracting a penalty of its own.
What we deliberately do not state. We print no entity count, and we do not say what the version taking effect on 1 October 2026 will change - the current consolidation does not contain it, and we will not guess at a text we have not read.

15 How to prepare for NIS2 in Estonia

  1. Confirm scope, then notify: if you meet the characteristics of a service provider, section 3¹(1) requires you to tell RIA within three months - and for anyone already in scope on 1 January 2026 that deadline was 1 April 2026.
  2. Designate your board member: section 6¹ requires one named member of the management board to approve the security measures and take responsibility for them - and if you designate nobody, the duty falls on all of them.
  3. Work back from your own three-year date: conformity is due three years from when you met the definition, so establish that date before building the plan.
  4. Perform a gap assessment: Compare your current cybersecurity controls against NIS2-aligned obligations and prioritise remediation measures.
  5. Build the chain into your incident plan: 24 hours, 72 hours, interim on request, final report one month later - and remember you report on reasonable presumption of significant impact, with your own risk assessment setting the threshold.
  6. Put the 24-hour pass-through in your supplier contracts: section 8(1¹) makes you responsible for ensuring that whoever manages or hosts your systems notifies you within 24 hours. That has to be written into the contract before an incident.
  7. Align with a recognised framework: Align with an ISMS (e.g., ISO 27001) for structured governance.
  8. Train leadership & staff: Provide management and staff training on cybersecurity responsibilities.

16 Official links & resources

17 FAQ: NIS2 in Estonia

Has Estonia fully transposed NIS2?
Yes. The amendments to the Küberturvalisuse seadus were published as RT I, 30.12.2025, 4 and entered into force on 1 January 2026. Note that Riigi Teataja states the current consolidated text runs only to 30 September 2026, so a further version is already scheduled.
Who is the competent authority?
The Riigi Infosüsteemi Amet (RIA). Section 5(3) makes it the competent authority, the single point of contact, the CSIRT, the body for large-scale incidents and crises, and the national coordinator for vulnerability disclosure. Complaints are reviewed by the Consumer Protection and Technical Regulatory Authority.
Are ISO certifications mandatory?
No, but ISO 27001 is strongly recommended for structured compliance.
Do entities need to register?
Yes - it is a duty, not a possibility. Section 3¹(1) requires a service provider to submit its name and registry code, contact details including IP address ranges, its Annex I/II sector and the countries it serves. Section 4¹ gives three months from meeting the definition; for entities already in scope on 1 January 2026 the deadline was 1 April 2026. Changes must be notified within two weeks.
How long do we have to comply?
Three years from the day you first meet the characteristics of a service provider (section 4¹(3)) - so 1 January 2029 for entities already in scope when the Act took effect. Providers of a vital service are the exception: their time limit is set under section 38(13)(3) of the Emergency Act instead.
What is the maximum fine?
Up to EUR 10,000,000 or 2% of worldwide annual turnover for an essential entity that is a legal person, and EUR 7,000,000 or 1.4% for an important entity, whichever is higher in each case. Two qualifications matter: these are misdemeanour penalties, not administrative fines, and they attach only to breaches of a closed list of subsections of sections 7 and 8. Separately, failing to comply with a compliance notice attracts a non-compliance levy of up to EUR 70,000 per imposition, which can be repeated.
Information provided for general guidance and verified against the official English translation of the Küberturvalisuse seadus as consolidated in force from 1 January 2026; the Estonian text governs. Always consult the Act, RIA publications and legal counsel for definitive NIS2 compliance requirements.