NIS2 Estonia: Küberturvalisuse seadus 2026
Estonia transposed NIS2 by amending the Küberturvalisuse seadus (Cybersecurity Act, KüTS). The amending act was published as RT I, 30.12.2025, 4 and the new regime has applied since 1 January 2026. This page sets out the three-month notification duty, the three-year runway to full conformity, the 24h/72h reporting chain, and what the Riigi Infosüsteemi Amet (RIA) can actually impose - which in Estonia is a misdemeanour penalty and a repeatable levy, not an administrative fine.
1 Introduction: NIS2 Directive & the Estonian context
Estonia is one of the most digitally advanced EU Member States, known for its electronic governance framework and robust cybersecurity infrastructure. To align with NIS2, Estonia amended its existing Cybersecurity Act, expanding obligations and strengthening security governance for both public and private sectors.
The framework that matters is the one in force from 1 January 2026. Two features of it catch organisations out. First, the deadlines are relative - three months to notify RIA and three years to reach conformity, both counted from the day you meet the definition, so there is no single national compliance date. Second, Estonia's penalties are misdemeanour penalties, not administrative fines, which changes the procedure that applies to you.
2 NIS2 implementation in Estonia
Estonia implemented NIS2 by amending the Küberturvalisuse seadus - the Cybersecurity Act, abbreviated KüTS - which was originally passed on 9 May 2018. The NIS2 amending act was published as RT I, 30.12.2025, 4 and entered into force on 1 January 2026, rewriting 89 provisions of the Act.
The amendments broaden the regulated sectors, introduce the essential/important entity model, move the security measures from a service-by-service basis to the organisation as a whole, and reinforce the supervisory powers of the Riigi Infosüsteemi Amet (RIA).
Status
Transposed and in force since 1 January 2026. The consolidated text is stated to run only to 30 September 2026, so a further version is already scheduled.
Legal structure
One act. The Küberturvalisuse seadus carries scope, the security measures (Section 7), incident notification (Section 8), supervision (Section Section 14-17) and the penalties (Section Section 18² and 18³), with the notification data and procedure set by ministerial regulation.
Supervisory approach
RIA does nearly all of it - competent authority, single point of contact, CSIRT, large-scale crisis management and national coordinator for vulnerability disclosure. Complaints are reviewed by the Consumer Protection and Technical Regulatory Authority.
3 Who is in scope
Estonia applies the NIS2 essential/important model, with obligations corresponding to sector, service criticality, and organisational size thresholds.
Who is in scope?
- Entities in NIS2 Annex I sectors (energy, health, water, digital infrastructure, public administration, etc.).
- Entities in Annex II sectors (food, postal/courier services, manufacturing of critical goods, research, etc.).
- Medium and large enterprises meeting NIS2 thresholds.
- Entities covered regardless of size: DNS, TLD registries, trust-service providers, major cloud and data-centre operators.
Core obligations
- Implement risk-management measures aligned with NIS2 Annex I.
- Ensure monitoring, detection, and reporting of significant incidents to RIA/CSIRT.
- Develop and maintain cybersecurity documentation and incident-response plans.
- Implement supply-chain and third-party cybersecurity controls.
- Ensure management-level cybersecurity oversight and training.
Framework alignment
While not mandatory, using ISO/IEC 27001 or NIST CSF supports readiness and structured compliance.
4 Notifying RIA: the three-month duty
Estonia does not wait for you to be designated. Section 3¹(1) requires a service provider to notify RIA itself, and section 4¹ gives it three months from the day it first meets the characteristics of a service provider.
What you must submit
- Name and registry code.
- Address of the place of business and up-to-date contact details, including e-mail addresses, Internet Protocol address ranges and telephone numbers.
- The relevant Annex I or II sector and subsector.
- A list of the countries in which you provide services within the Directive's scope.
Keeping it current
Changes must be notified without delay and no later than two weeks after the change was made (Section 3¹(4)). RIA itself compiles the list every two years, so the currency of the register depends on you, not on it.
The list is not public
Section 3¹(3) marks the information as intended for internal use for the purposes of the Public Information Act. Being on the list is not a matter of public record - a question boards ask and few guides answer.
5 The three-year conformity runway
Notifying RIA and complying with the Act are two different clocks, and the second is long. Estonia gives three years to bring activities into conformity - one of the most generous runways in the EU, and the result of an extension argued for during the Bill's passage.
| Duty | Deadline | Provision |
|---|---|---|
| Notify RIA under Section 3¹(1) | 3 months from meeting the characteristics of a service provider | Section 4¹(1) |
| Bring activities into conformity with the Act and its implementing rules | 3 years on the same trigger | Section 4¹(3) |
| The same, for entities already in scope on 1 January 2026 | 3 months (so 1 April 2026) and 3 years (so 1 January 2029) | Section 28¹(1) and (3) |
| Providers of a vital service | Not three years - the time limit is set under Section 38(13)(3) of the Emergency Act | Section 4¹(4), Section 28¹(4) |
6 Your management board's own duty
Section 6¹ puts a duty on the board itself, and the sanction for ignoring it is unusual: it does not fine you, it spreads the liability.
- Designate at least one member of the management board who approves the security measures, oversees their implementation and is responsible for them.
- Give RIA that person's name and contact details on request.
- That member must undergo regular training sufficient to understand and assess the risks, their impact on your services, and how they are managed (Section 6¹(2)).
- If you designate nobody, the obligations apply to every member of the board (Section 6¹(3)).
- Where the provider's legal form means there is no management board, the duties fall on whoever performs management functions; for a sole proprietor, on that person (Section 6¹(4)).
- The duty to designate does not apply where the provider has only one board member - there is nobody to choose between.
8 Incident reporting: 24h / 72h / one month
Section 8 sets the chain, and Estonia's trigger is lower than the Directive's baseline in two distinct ways - one about what you must presume, and one about what your suppliers must tell you.
| Stage | Deadline | Notes |
|---|---|---|
| Initial notification | 24 hours from becoming aware | Submitted to RIA. Security authorities notify through their own channel instead. |
| Incident notification | 72 hours from becoming aware | Updates the initial notification with a specified overview of the circumstances. |
| Trust service providers | 24 hours, not 72 | Section 8(4²) - the trust-service derogation, tighter rather than looser. |
| Interim report | At RIA's request, before the final report | Section 8(4³). |
| Final report | One month from the 72-hour notification | If the incident is unresolved at that point, the report counts as an interim report and a new final report is due one month after resolution. |
An incident is significant if any one of six tests in section 8(2) is met - and the first of them is your own risk assessment: impact "at least severe according to the severity of consequences determined in the system risk assessment" prepared under section 7(1)(1). The others cover breaching the maximum permitted disruption time, disrupting another provider's service, having to invoke extraordinary continuity measures, significant damage to you or your users, and the European Commission's implementing act. Section 8(3) adds that disruption in at least one more Member State is always significant.
Section 8(6) lets RIA inform the public of the incident itself, or require you to do so, after consulting you.
9 NIS2 timeline & key dates (Estonia)
10 Sector-specific notes for Estonia
- Energy: electricity and gas infrastructure classified as essential.
- Digital infrastructure: Estonia prioritises e-government and digital identity services.
- Finance: close supervision through joint oversight with financial regulators.
- Healthcare: hospitals and medical data processors face strict requirements.
- Public services: strong focus on continuity of digital public services (X-Road ecosystem).
- Vital services: providers of a vital service do not get the three-year runway - their deadline is set under section 38(13)(3) of the Emergency Act, and can be shorter.
- Cross-border electricity: sections 18⁴ and 18⁵ create separate offences for entities in this field and for their legal representatives personally - the only place in the Act where a named individual is a distinct offender.
- Trust services: the incident notification deadline is 24 hours, not 72 (section 8(4²)).
11 Penalties & fines
Two things about Estonian penalties are routinely got wrong. They are misdemeanour penalties, not administrative fines - sections 18² and 18³ are drafted as offences and section 19 assigns extra-judicial proceedings. And they attach to a closed list of duties, not to the Act as a whole.
| Provision | Who | Maximum |
|---|---|---|
| Section 18²(1) | Essential entity | up to EUR 10,000,000 |
| Section 18²(2) | The same act by a legal person | up to EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher |
| Section 18³(1) | Important entity | up to EUR 7,000,000 |
| Section 18³(2) | The same act by a legal person | up to EUR 7,000,000 or 1.4%, whichever is higher |
| Section 18⁴ and Section 18⁵ | Entities in cross-border electricity, and their legal representatives | Separate offence categories, including personal liability for the representative |
| Section 18¹ | Any entity | A separate offence for breaching Regulation (EU) 2019/881 (the Cybersecurity Act) |
12 Supervision & the non-compliance levy
For a continuing breach the headline fine is rarely the operative provision. Section 17¹ is.
EUR 70,000, repeatable
On failure to comply with a compliance notice, the upper limit of the non-compliance levy is EUR 70,000 for each imposition, under the rules in the Substitutional Performance and Non-Compliance Levies Act. It can be imposed again, which is what makes it effective against an entity that simply does not act.
State and administrative supervision
Sections 14 to 17 split supervision into state supervision and administrative supervision, with special measures in section 15 and, in section 16, specific powers for countering an immediate serious threat.
Complaints and cross-border work
Section 17² gives the Consumer Protection and Technical Regulatory Authority the complaint-review role; section 17³ provides mutual assistance where an entity operates in more than one Member State; section 17⁶ covers peer review under Article 19 of the Directive.
13 Voluntary notification & vulnerability disclosure
Not every route to RIA is compulsory, and two of the voluntary ones are worth using.
- Voluntary notification (Section 8¹). RIA may receive notifications outside the mandatory regime - the channel Denmark and Lithuania also provide, and a way to put an incident on the record without conceding that the significance threshold was met.
- Coordinated vulnerability disclosure. Section 5(3)(4) makes RIA the national coordinator for the purposes of Article 12(1) of the Directive, so there is a defined route for reporting a vulnerability in someone else's product or service.
- Information-sharing arrangements (Section 17⁵). The Act expressly contemplates service providers and others entering cybersecurity information-sharing arrangements between themselves.
- The cyber incident registry (Section 13). Incidents notified to RIA are recorded in a statutory registry.
14 How Estonia differs from the Directive
Six features of the Estonian regime are not obvious from reading NIS2, and each changes what a compliance programme has to do.
- The penalties are misdemeanour penalties, not administrative fines - a different procedure, with extra-judicial proceedings under section 19.
- The runway is three years, among the most generous in the EU, and it is relative - counted from when you meet the definition, not from a national date.
- The EUR 70,000 non-compliance levy is repeatable per imposition, and is the provision that actually applies pressure on a continuing breach.
- You report on reasonable presumption of significant impact, not on established impact - and your own risk assessment defines the threshold.
- Your outsourcing provider owes you a 24-hour notification, and ensuring that is your statutory responsibility.
- Failing to designate a responsible board member spreads the duty to the whole board rather than attracting a penalty of its own.
15 How to prepare for NIS2 in Estonia
- Confirm scope, then notify: if you meet the characteristics of a service provider, section 3¹(1) requires you to tell RIA within three months - and for anyone already in scope on 1 January 2026 that deadline was 1 April 2026.
- Designate your board member: section 6¹ requires one named member of the management board to approve the security measures and take responsibility for them - and if you designate nobody, the duty falls on all of them.
- Work back from your own three-year date: conformity is due three years from when you met the definition, so establish that date before building the plan.
- Perform a gap assessment: Compare your current cybersecurity controls against NIS2-aligned obligations and prioritise remediation measures.
- Build the chain into your incident plan: 24 hours, 72 hours, interim on request, final report one month later - and remember you report on reasonable presumption of significant impact, with your own risk assessment setting the threshold.
- Put the 24-hour pass-through in your supplier contracts: section 8(1¹) makes you responsible for ensuring that whoever manages or hosts your systems notifies you within 24 hours. That has to be written into the contract before an incident.
- Align with a recognised framework: Align with an ISMS (e.g., ISO 27001) for structured governance.
- Train leadership & staff: Provide management and staff training on cybersecurity responsibilities.
