Estonia

← All Member States
Transposed, in force
NIS2 status
Transposed, in force
National law
Amendment to the Cybersecurity Act and other acts (Riigi Teataja, Dec 2025)
Competent authority
Riigi Infosüsteemi Amet (RIA)
CSIRT
CERT-EE (within RIA)
Last verified
2026-07-16

Estonia

✅ NIS2 transposed and in force.

NIS2 transposition

  • National law: Amendment to the Cybersecurity Act and other acts (Riigi Teataja, Dec 2025)
  • Status / entry into force: In force 2026-01-01

Competent authority & CSIRT

  • Competent authority: Riigi Infosüsteemi Amet (RIA)
  • CSIRT / incident response: CERT-EE (within RIA)
  • Registration: Per RIA / nis2.ee portal

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

Scope expanded from ~3,500 to 5,500–7,000 entities; three-year transition period for full compliance.

Sources