NIS2
How to register with RIA under NIS2 (Estonia)
Updated September 27, 2026
Registration is the first obligation under Estonia's amended Cybersecurity Act (KüTS) and the quickest one to complete. It tells the Information System Authority (RIA) that your organisation is in scope and how to reach it. It takes little time if you have the data ready.
Who must register
Every organisation within the scope of the amended Act, whether as an essential or an important entity, must register with RIA. RIA estimates that around 6,500 organisations are in scope, roughly half of them for the first time, so many are going through this process now.
If you are not sure whether you are in scope, check that first: your sector, your size and a few size-independent exceptions decide it. Confirm borderline cases around the size thresholds with RIA or a lawyer, because the Act words the thresholds slightly differently from the EU definition.
What to prepare before you start
Collect the following before opening the form. Most delays come from the public IP ranges, which are often managed by an IT or hosting provider.
- Your organisation's name and registry code.
- Contact details for cybersecurity matters. Use a shared, monitored mailbox and name a deputy, so messages from RIA are not missed when someone is away.
- Your public IP address ranges, including those used by other offices or assigned to you by your internet or hosting provider.
- The sector your main activity belongs to.
- The countries where you provide services.
How to register
Registration is done through the state portal eesti.ee. The steps are short:
- Log in to eesti.ee and act on behalf of your organisation.
- Open the e-services section and choose the cybersecurity service.
- Enter the data you prepared and check the sector carefully before you submit.
- Keep a copy of the submission and note the date and who submitted it. Auditors and customers may ask for it.
Missed the 1 April 2026 deadline?
Organisations already in scope on 1 January 2026 had until 1 April 2026 to register (KüTS § 28¹). If you missed it, register now rather than waiting. The other obligations, including incident reporting to RIA, apply whether or not you have registered.
If your organisation came into scope later, for example because it grew past the size threshold or started an activity in a listed sector, you have three months from that point to register.
Keep the registration up to date
Changes to the registered data must be reported to RIA within two weeks. Typical triggers are a new IP range after a hosting move, a new contact person, a change of sector or starting services in another country. Make one person responsible for the registration record and ask them to check it whenever one of these changes.
Common mistakes
- Submitting incomplete IP ranges, for example forgetting ranges used by a second office or a hosting provider. Ask your providers before you start.
- Choosing the sector of a side activity or of a customer instead of your own main activity.
- Giving one employee's personal email address as the only contact.
- Treating registration as a one-off task and never reporting changes.
- Assuming that registration means compliance. It is only the first step; board responsibility, security measures and incident reporting follow.
Where to start
If you are unsure whether you need to register, our free NIS2 assessment checks your scope under the Estonian Act and scores your readiness. Subscribers also get the documents that should follow registration, pre-filled for their company: the information security policy, the board resolution and the incident reporting procedure.
Where does your company stand on NIS2?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.