NIS2
NIS2 in Estonia: what the amended Cybersecurity Act requires
Updated September 26, 2026
Estonia transposed NIS2 by amending its Cybersecurity Act (Küberturvalisuse seadus, KüTS). The amendments were published in Riigi Teataja at the end of 2025 and have applied since 1 January 2026. The Information System Authority (RIA) estimates that around 6,500 organisations are now in scope, roughly half of them for the first time.
Registration
Entities in scope must register with RIA, giving their name and registry code, contact details including public IP ranges, sector and the countries where they provide services. Organisations already in scope on 1 January 2026 had until 1 April 2026; organisations that come into scope later have three months. Changes must be reported within two weeks. Registration is done through eesti.ee.
The management board is responsible
At least one member of the management board must be designated as responsible for approving and supervising the cybersecurity measures, and must follow regular training. If nobody is designated, the responsibility lies with the whole board.
Security measures and E-ITS
The measures must be based on a risk analysis and cover the areas listed in Article 21 of the Directive: policies, incident handling, continuity and backups, supply chain security, secure development and vulnerability handling, effectiveness checks, training, cryptography, access control and asset management, and multi-factor authentication.
In Estonia the detailed baseline is the Estonian information security standard (E-ITS), unless the organisation holds a valid ISO/IEC 27001 certificate. Rules for smaller organisations have been eased since October 2025. Confirm with RIA which baseline applies to you, as the implementing regulations have been amended several times.
Incident reporting to RIA
Significant incidents are reported to RIA: an initial notice within 24 hours, an incident notification within 72 hours, and a final report within one month. The Estonian law also requires organisations that outsource or host their systems to make sure the provider tells them about incidents within 24 hours.
Deadlines
- 1 January 2026: the amended Act applies, including incident reporting.
- 1 April 2026: registration deadline for organisations already in scope.
- 1 January 2029: deadline for existing organisations to have the required security measures in place.
Where to start
If you have not registered, do that first. Then get management approval for a security policy and an incident reporting procedure, because reporting obligations apply now. Our NIS2 assessment is written for the Estonian Act and produces the board resolution, policy and reporting procedure pre-filled for your company.
Where does your company stand on NIS2?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.