Important entity and essential entity (oluline ja ülioluline üksus): the KüTS differences
Essential (ülioluline) and important (oluline) entities are the two classes of service provider under Estonia’s Cybersecurity Act (KüTS). Sector and size decide the class (§ 3 lg 2–5). Both have the same duties: security measures, incident reporting, board accountability. Supervision and fines differ: up to €10M or 2% of turnover for essential, €7M or 1.4% for important.
Updated
The differences in one table
Regardless of size
- Essential entity
- DNS service provider, provider of a vital service under the Civil Crisis and National Defence Act, central and local government administration body, provider of critical, maritime radio or operational radio network services, qualified trust service provider, top-level domain name registry (§ 3 lg 2 p 1–7)
- Important entity
- Controller or processor of a public database (andmekogu), Arenguseire Keskus, legal person in public law, association of local authorities, family-doctor practice, RMK, non-qualified trust service provider (§ 3 lg 4 p 1–7)
Public electronic communications
- Essential entity
- At least 50 staff and balance sheet or turnover above €10M (§ 3 lg 2 p 8)
- Important entity
- Smaller (§ 3 lg 4 p 9)
Depending on size
- Essential entity
- A § 3 lg 3 activity, at least 250 staff, and balance sheet above €43M or turnover above €50M
- Important entity
- A § 3 lg 3 activity at medium size (§ 3 lg 4 p 8), or a § 3 lg 5 activity: at least 50 staff and balance sheet or turnover above €10M
Obligations
- Essential entity
- Registration with RIA, board accountability, security measures, incident reporting (§ 3¹, § 6¹, § 7, § 8)
- Important entity
- The same
Supervision
- Essential entity
- Full supervision (§ 14 lg 6 p 2)
- Important entity
- Follow-up only, when RIA has reason to believe the act is breached (§ 14 lg 6 p 3)
Monitoring officer
- Essential entity
- RIA can order one to be appointed (§ 16 lg 1¹ p 10)
- Important entity
- No
Temporary restrictions
- Essential entity
- Temporary suspension of a certificate or authorisation for the service and of a board member’s powers, until the problems are fixed (§ 16 lg 1⁴–1⁶)
- Important entity
- No
Fine for a legal person
- Essential entity
- Up to €10M or 2% of the previous year’s worldwide turnover, whichever is higher (§ 18² lg 2)
- Important entity
- Up to €7M or 1.4% (§ 18³ lg 2)
Penalty payment
- Essential entity
- Up to €70,000 per imposition, can be repeated (§ 17¹)
- Important entity
- The same
How to find your class
Unlike the NIS2 directive, KüTS has no sector annex. All entity types are listed in § 3 lg 2–5. Go through the questions in order. The first match is final.
- Are you an entity listed in § 3 lg 2 p 1–7 (DNS, vital service, public administration, critical communications, qualified trust services, the .ee registry)? Then you are an essential entity.
- Do you provide a public electronic communications network or service? Medium-sized or larger is essential (§ 3 lg 2 p 8), smaller is important (§ 3 lg 4 p 9).
- Are you active in a § 3 lg 3 sector and large? Then you are an essential entity. The sectors are energy, transport, banking, financial market infrastructure, manufacturing and R&D of medicines and medical devices, drinking and waste water, data centres, cloud computing, content delivery networks, internet exchange points, managed services, managed security services and space.
- Are you an entity listed in § 3 lg 4 p 1–7, such as the processor of a public database? Then you are an important entity regardless of size.
- Are you active in a § 3 lg 3 sector and medium-sized? Then you are an important entity (§ 3 lg 4 p 8).
- Are you active in a § 3 lg 5 sector and at least medium-sized? Then you are an important entity, even when large. The sectors are postal and courier services, waste management, chemicals, food wholesale and industrial production, medical devices, NACE C26–C30 manufacturing, online marketplaces, search engines, social networks and research organisations.
- If none applies, you are not a service provider. A domain name registration service provider must still register with RIA (§ 3¹ lg 1).
An entity can also be a natural person, so a sole trader (FIE) can be in scope (§ 2 p 39).
The size test: staff and money
A medium-sized entity has at least 50 staff and an annual balance sheet or turnover above €10M. A large one has at least 250 staff and a balance sheet above €43M or turnover above €50M (§ 3 lg 2 p 8, lg 3, lg 4 p 8, lg 5). Both conditions must be met. The explanatory memorandum to bill 739 SE confirms it: “Mõlemad tingimused peavad olema täidetud” (both conditions must be met).
- With at least 50 staff but turnover and balance sheet up to €10M, an entity is not medium-sized under KüTS. The same holds with more than €10M but fewer than 50 staff.
- The figures follow the medium-sized enterprise definition in Commission Recommendation 2003/361/EC. The whole organisation counts, not only the NIS2 activity.
- Public ownership does not make an enterprise large: Article 3(4) of the Recommendation’s annex is not applied (§ 3 lg 6).
- Partner and linked enterprise figures are not added if the entity is independent of them in the systems it uses to provide its services (§ 3 lg 7). A small subsidiary on the group’s shared IT platform can therefore count as large.
The NIS2 directive treats an enterprise as medium-sized as soon as it has 50 staff, or when both turnover and balance sheet exceed €10M. The KüTS test is narrower. Another member state’s law may assess the same company differently.
What both classes share
The class does not change what you must do. Both must register with RIA (§ 3¹ lg 1), designate a responsible board member (§ 6¹ lg 1), apply security measures and draw up a risk analysis (§ 7 lg 1–2), and report a significant incident within 24 hours (§ 8 lg 1). The board-member designation does not apply when the board has one member (§ 6¹ lg 1).
The security route depends on size, not class. A service provider with under 50 staff and a balance sheet or turnover up to €10M applies the baseline security measures and needs no E-ITS (VVm121 § 3 lg 2¹ p 1). A small processor of a public database is an important entity, yet has no E-ITS audit.
Fines and who gets them
Misdemeanour fines apply to breaches of § 7 lg 1, 2, 3, 5 and 7 and § 8 lg 1, 1¹, 4¹, 4², 4³, 5, 7 and 8¹: § 18² for essential entities, § 18³ for important ones. The caps equal those in NIS2 Article 34.
Registration (§ 3¹) and the board duties (§ 6¹) are not covered by the fine provisions. RIA enforces them with an order (ettekirjutus) and penalty payments (§ 16 lg 1¹ p 5, § 17¹).
§ 18² lg 1 and § 18³ lg 1 also set a fine for a natural person of up to €10M or €7M. KüTS does not define who the natural-person offender is (a board member, a sole trader or a responsible employee), and RIA has not confirmed it.
Frequently asked questions
- Does an important entity have fewer obligations than an essential one?
- No. Both must register with RIA, designate a responsible board member, apply security measures and report incidents (KüTS § 3¹, § 6¹, § 7, § 8). Supervision, RIA’s measures and the maximum fine differ.
- Can a small company be an important entity?
- Yes. The entities in § 3 lg 4 p 1–7 and 9 are important regardless of size, for example the processor of a public database, a family-doctor practice, a trust service provider and a smaller communications provider.
- Will RIA tell us which class we are in?
- It does not have to. Registration is your own duty (KüTS § 3¹ lg 1) and RIA does not write to companies one by one. Whether RIA can set your class by an administrative act in a dispute is not stated clearly in the act and has not been confirmed by RIA.
- Can RIA remove a board member?
- Only in an essential entity and only temporarily: if a warning and an order do not work, RIA can suspend a board member’s powers until the problems are fixed (KüTS § 16 lg 1⁴–1⁶). It cannot do this to an important entity.
- What if we are active in several sectors?
- KüTS has no general rule for entities active in several sectors. On our reading the higher class applies, because § 3 lg 4 p 8 covers only an entity that is not essential. RIA has not confirmed this, so ask RIA if in doubt.
Not sure where you fit in the table?
Check on the InScope page, in 15 minutes and free, whether KüTS applies to you. If it does, the EIS grant may pay for a cybersecurity roadmap that puts your obligations in order: who does what, and when.