Baseline security measures (esmased turvameetmed): who applies them and how to check they work
The baseline security measures (esmased turvameetmed) are cybersecurity measures in nine areas, listed in the annex to Government Regulation No 121 (VVm121 § 5¹). Every service provider under KüTS applies them permanently. With under 50 staff and a balance sheet or turnover up to €10M, they plus a risk analysis and documentation are enough (§ 3 lg 2¹ p 1).
Updated
Who applies only the baseline measures
Since 07.09.2026 a service provider with on average fewer than 50 staff in the financial year and an annual balance sheet or turnover up to €10M needs neither E-ITS nor an ISO/IEC 27001 certificate (VVm121 § 3 lg 2¹ p 1). Size is calculated under Recommendation 2003/361/EC:
- the public-ownership rule (Article 3(4) of the Recommendation’s annex) is not applied (VVm121 § 3 lg 2²);
- partner and linked enterprise figures are not added if the provider is independent of them in the systems it uses to provide its services (VVm121 § 3 lg 2³).
Such a provider also has no E-ITS audit, because the audit duty (VVm121 § 4 lg 1) covers only those who must apply E-ITS. Typical cases are a small processor of a public database, a small communications provider and a trust service provider, all in scope regardless of size. Some small public bodies have their own exemptions (VVm121 § 3 lg 2¹ p 2–6).
Larger providers apply E-ITS with an audit every three years, or ISO/IEC 27001 with a valid conformity certificate filed with RIA (VVm121 § 3 lg 1–2, § 4 lg 1). VVm121 does not apply to financial entities under DORA or to entities under the aviation security rules (§ 1 lg 2).
The nine areas, and how to check a measure works
The regulation lists the areas (VVm121 § 5¹ lg 1); the measures themselves are in the annex (opens in a new tab) (in Estonian). The check column is our suggestion, not a requirement of the regulation. As RIA puts it: “järelevalve huvi ei ole paber, vaid protsesside toimivus” (supervision is interested in how processes work, not in paper; RIA Cybersecurity Yearbook 2026).
| Area | A simple check |
|---|---|
| 1. Information security management | Is the risk analysis less than three years old, and has the responsible board member approved the security measures (KüTS § 6¹ lg 1)? |
| 2. User awareness, training and access rights | Take the most recent leaver and check that their accounts are closed in every system. Who has admin rights, and do they need them? |
| 3. Data security | Restore one real system from backup and time it. |
| 4. Managing external partners | Does the contract with each critical IT partner require notice of a significant incident within 24 hours (KüTS § 7 lg 3, § 8 lg 1¹)? |
| 5. Cyber incident management | Rehearse it: do you know who sends RIA the initial notice within 24 hours and what goes in it (KüTS § 8 lg 1, JDM Regulation No 7 § 1)? |
| 6. Protecting cloud services and web applications | Try to reach another user’s data and admin functions without permission. That is what a penetration test does. |
| 7. Protecting IT devices | Pick a random laptop from the inventory: is the disk encrypted and are updates installed? |
| 8. Protecting connections and the network | Scan your public IP addresses (the ones you reported to RIA, KüTS § 3¹ lg 1 p 2) and compare the open services with what should be open. |
| 9. Physical security | Who can reach the server and network equipment, and is that written down anywhere? |
According to RIA’s E-ITS portal, a measure may be replaced by an equivalent one, and skipped if it is not relevant or applicable and the organisation is aware of the risk this creates. The portal refers to the previous version of the annex. RIA has not confirmed that the same applies to the annex in force since 07.09.2026.
Risk analysis and documentation
The baseline measures do not replace the risk analysis. Every service provider under VVm121 maps its systems and documents its security measures and risk analysis (VVm121 § 5 lg 1). The risk analysis must contain at least (§ 5 lg 1¹):
- a list of risks to security and continuity;
- a description of impact, with severity levels for the consequences;
- a description of the risk-treatment measures.
Keep the documents for at least seven years and give them to RIA on request (§ 5 lg 2). Update the risk analysis without delay after a significant incident or a security-relevant system change, and at least every three years (§ 6 p 1–3).
The severity scale matters for incidents too: an incident has significant impact if, among other things, its severity is at least “raske” (severe) on your own risk-analysis scale (KüTS § 8 lg 2 p 1). Then RIA must be notified within 24 hours.
What changed in September 2026
- E-ITS 2026 (Minister of Justice and Digital Affairs Regulation No 30) took effect on 01.09.2026.
- The VVm121 amendment (RT I, 04.09.2026, 16) took effect on 07.09.2026: the new small-entity exemption (§ 3 lg 2¹ p 1), the baseline-measures provision (§ 5¹) and a new annex.
- If your checklist is based on an earlier annex, compare it with the current one (opens in a new tab).
Whether an organisation that runs E-ITS must also go through the baseline measures separately, or whether the E-ITS catalogue covers them, is not stated in the regulation and has not been confirmed by RIA.
Frequently asked questions
- Are the baseline security measures mandatory?
- Yes, for a KüTS service provider covered by VVm121 (VVm121 § 5¹). The regulation does not apply to financial entities under DORA or to entities under the aviation security rules (§ 1 lg 2).
- Does a small company need E-ITS?
- No, if it has on average fewer than 50 staff and a balance sheet or turnover up to €10M (VVm121 § 3 lg 2¹ p 1). The baseline measures, a risk analysis and documentation are then enough, and there is no E-ITS audit.
- What must the risk analysis contain?
- At least a list of risks, a description of impact with severity levels for the consequences, and the risk-treatment measures (VVm121 § 5 lg 1¹). Update it after a significant incident or change, and at least every three years (§ 6).
- Do staff of other group companies count?
- Partner and linked enterprise figures are not added if you are independent of them in the systems you use to provide your services (VVm121 § 3 lg 2³). If the systems are shared with the group, the group figures count.
- Can we skip a measure?
- According to RIA’s portal, yes, if the measure is not relevant and you are aware of the risk this creates. That explanation refers to the previous annex, and RIA has not confirmed that it applies to the annex in force since 07.09.2026. Write down the decision and the reason.
In what order should you tackle the measures?
If KüTS applies to you, the EIS grant may pay for a cybersecurity roadmap written and signed by a certified author: who does what, and in what order. On the InScope page you can check in 15 minutes, free, whether the act applies to you. For area 6, see the penetration testing page.