NIS2

E-ITS or ISO 27001: choosing your NIS2 baseline in Estonia

Updated September 27, 2026

NIS2 requires appropriate, risk-based security measures but does not name a framework. Estonia does: under the amended Cybersecurity Act (KüTS) and its implementing regulations, the baseline is the Estonian information security standard, E-ITS, with a valid ISO/IEC 27001 certificate as the alternative.

What E-ITS is

E-ITS (Eesti infoturbestandard) is the Estonian information security standard. It is based on Germany's BSI IT-Grundschutz and is organised as a catalogue of modules and measures for typical processes, systems and environments, selected on the basis of a risk analysis.

The catalogue is free to use at eits.ria.ee. It is detailed and prescriptive, which helps organisations that want to know exactly what to do, but working through it takes time.

When ISO/IEC 27001 takes the place of E-ITS

An organisation that holds a valid ISO/IEC 27001 certificate does not have to apply E-ITS as its baseline. The key word is valid: the certificate must be current, and its scope should cover the services and systems that bring you under NIS2. Being aligned with ISO/IEC 27001 without a certificate is not the same thing.

ISO/IEC 27001 is an international management system standard. It requires a risk assessment, a documented choice of controls and a maintained information security management system, with regular audits by an external certification body.

Smaller organisations: basic measures

The rules for smaller organisations were eased from October 2025. Depending on your situation, you may be allowed to apply basic measures instead of the full E-ITS baseline.

The implementing regulations have been amended several times, so confirm with RIA which baseline applies to you before you plan the work.

How to decide

  • You already hold ISO/IEC 27001 covering your NIS2 services: keep the certificate valid and check that it covers every Article 21 area.
  • Customers or foreign partners ask for ISO/IEC 27001: certification may be worth it, because the same work answers both RIA and your customers.
  • You are a smaller organisation without a certificate: ask RIA whether basic measures apply to you, and start from the E-ITS catalogue.
  • You do not need a certificate and want the lowest external cost: E-ITS is free, but budget internal time to implement and document it.
  • Whichever route you choose, record the decision and the reason in your information security policy and have the management board approve it.

How both map to the Article 21 areas

Both frameworks can cover the ten minimum measures in Article 21(2) of NIS2. Whichever you choose, check that each area has concrete measures and evidence behind it:

  • (a) Risk analysis and information system security policies.
  • (b) Incident handling.
  • (c) Business continuity, backup management, disaster recovery and crisis management.
  • (d) Supply chain security.
  • (e) Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
  • (f) Policies to assess the effectiveness of the measures.
  • (g) Basic cyber hygiene and cybersecurity training.
  • (h) Cryptography and, where appropriate, encryption.
  • (i) Human resources security, access control and asset management.
  • (j) Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications.

Where to start

Our free NIS2 assessment checks whether you are in scope under the Estonian Act and scores your readiness for each Article 21 area, whichever baseline you follow. Subscribers get the information security policy, board resolution and incident procedure pre-filled for their company, structured so they can support an E-ITS or ISO/IEC 27001 implementation.

Where does your company stand on NIS2?

Free assessment, about 10 minutes, score for every area of the law.

Start the free assessment

This guide is general information, not legal advice.

E-ITS or ISO 27001: choosing your NIS2 baseline in Estonia | Parendum