Parendum Compliance

NIS2 Directive (EU) 2022/2555 · Estonian Cybersecurity Act

Are you in scope of NIS2, and how far are you from compliance?

A 10-minute scope check and gap assessment against the ten minimum measures of Art. 21, incident reporting under Art. 23 and management accountability under Art. 20. Written for Estonia's Cybersecurity Act (KüTS), usable across the EU.

Check scope and readinessFree score, no sign-up. Documents and tracking €39/month.

Why now

The law already applies

Estonia's amended Cybersecurity Act has applied since 1 January 2026. Entities in scope had to register with RIA by 1 April 2026, and incident reporting obligations run now.

Management is accountable

Boards must approve and oversee the measures and follow training, and can be held liable. Maximum fines reach at least €10M or 2% of worldwide turnover for essential entities.

Out of scope? Your customers aren't

In-scope organisations must manage their suppliers' security, so the requirements arrive anyway as questionnaires and contract clauses.

What subscribers get

Editable Word documents generated from your answers, regenerated whenever you reassess.

00

Gap assessment report

Likely classification (essential, important, supplier), a score per measure, every gap with its article and a roadmap.

01

Information security policy

Covers all ten Art. 21(2) measures, mapped to the other documents, ready for board approval.

02

Board resolution and briefing

The Art. 20 approval, the responsible board member (KüTS § 6¹) and a 90-minute training briefing.

03

Risk assessment register

Method plus pre-filled threats that match your answers.

04

Incident response and reporting

Significance test, 24h/72h/1-month report templates, contacts, incident log and a tabletop exercise.

05

Business continuity and backup plan

Recovery targets, 3-2-1 backup standard, restore testing and crisis management.

06

Supplier security kit

Policy, supplier register, assessment questions and model contract clauses including 24-hour incident notification.

07

Access, asset and people policy

Asset inventory, least privilege, MFA rollout, joiner-mover-leaver checklist.

08

Technical security policy

Patch deadlines, hardening, secure development, vulnerability disclosure, cryptography and logging.

09

Customer security statement

A one-page answer to customers' NIS2 supplier questionnaires that only claims what you actually have.

Questions

+How do I know if NIS2 applies to me?

Broadly: medium or large organisations (50+ staff, or turnover and balance sheet above €10M) in the sectors listed in Annexes I and II, plus some entities regardless of size (DNS, trust services, telecoms, public administration) and, in Estonia, some public bodies. The assessment starts with this check.

+Is this an audit or a certification?

No. It is a structured self-assessment with templates generated from your answers. It gets you to a documented, defensible position quickly. For an independent audit, E-ITS or ISO 27001 work, or a penetration test, Parendum offers those separately.

+Does it cover E-ITS?

The documents reference the Estonian information security standard where relevant and are structured so they can support an E-ITS or ISO/IEC 27001 implementation, but they are not a replacement for the E-ITS catalogue.

+We are outside Estonia. Is it still useful?

Yes. The kit follows the Directive; Estonia-specific points are marked. Check your national authority, portal and reporting forms.

+Who can subscribe?

Businesses. EU buyers outside Estonia need a valid VAT number (checked in VIES) and are invoiced under reverse charge; Estonian buyers pay 24% VAT.