NIS2 · National implementation

NIS2 in Estonia

Estonia transposed NIS2 by amending the Küberturvalisuse seadus (KüTS), in force since 1 January 2026.

National law
Küberturvalisuse seadus (KüTS, amended)
Cybersecurity Act, as amended
Status
In force
In force
1 January 2026
Authority
RIA

Supervision

The RIA (Riigi Infosüsteemi Amet, Information System Authority) is the national authority and CSIRT (CERT-EE). Entities register with RIA and report through its channels.

What is specific to Estonia

Estonia already ran one of the EU's most digitised baselines: the E-ITS (Estonian information security standard) is the reference framework, and KüTS-regulated entities demonstrate measures against it. The NIS2 amendment widens scope to the directive's sectors while keeping the E-ITS mechanics — so Estonian compliance is standard-driven in a way most member states' is not.

Official sources

Primary references: the national statute book at www.riigiteataja.ee and the national cybersecurity authority at www.ria.ee.

NIS2 in Estonia: frequently asked questions

Last reviewed:

Related reading

Definitions

All 27 EU member states