Skip to main content

NIS2 in Estonia: the Cybersecurity Act in practice

Estonia transposed the NIS2 directive through the Cybersecurity Act (küberturvalisuse seadus, KüTS), and its new obligations apply since 1 January 2026. These pages explain the act section by section and show how to check that security measures actually work. Every claim points to a section of the act or regulation and to its current version.

Updated

What KüTS requires from a service provider

  • Register with RIA: entities in scope since 1 January 2026 had until 31.03.2026 (KüTS § 3¹ lg 1, § 28¹ lg 1). Anyone not yet registered is late.
  • Security measures and a risk analysis, applied on a permanent basis (KüTS § 7 lg 1–2).
  • Incident reporting: initial notice within 24 hours, incident notification within 72 hours, final report within a month (KüTS § 8 lg 1, 4¹, 7).
  • A responsible board member who approves the security measures and oversees their implementation (KüTS § 6¹ lg 1).
  • Full compliance by 01.01.2029 at the latest (KüTS § 28¹ lg 3).

In this section

Does the act apply to your organisation?

On the InScope page you can check in 15 minutes, free, whether KüTS applies to you. If it does, the EIS grant may pay for a cybersecurity roadmap written and signed by a certified author.