NIS2 in Estonia: the Cybersecurity Act in practice
Estonia transposed the NIS2 directive through the Cybersecurity Act (küberturvalisuse seadus, KüTS), and its new obligations apply since 1 January 2026. These pages explain the act section by section and show how to check that security measures actually work. Every claim points to a section of the act or regulation and to its current version.
Updated
What KüTS requires from a service provider
- Register with RIA: entities in scope since 1 January 2026 had until 31.03.2026 (KüTS § 3¹ lg 1, § 28¹ lg 1). Anyone not yet registered is late.
- Security measures and a risk analysis, applied on a permanent basis (KüTS § 7 lg 1–2).
- Incident reporting: initial notice within 24 hours, incident notification within 72 hours, final report within a month (KüTS § 8 lg 1, 4¹, 7).
- A responsible board member who approves the security measures and oversees their implementation (KüTS § 6¹ lg 1).
- Full compliance by 01.01.2029 at the latest (KüTS § 28¹ lg 3).
In this section
Essential and important entities
How KüTS splits service providers into two classes, what the size test decides, and how supervision and fines differ.
Baseline security measures (esmased turvameetmed)
Nine areas that apply to every service provider, and the small-entity exemption: under 50 staff and up to €10M need no E-ITS.
Penetration testing
How a web application penetration test shows whether the E-ITS DER.3 and baseline area 6 measures work.
Does the act apply to your organisation?
On the InScope page you can check in 15 minutes, free, whether KüTS applies to you. If it does, the EIS grant may pay for a cybersecurity roadmap written and signed by a certified author.