Skip to content

National Annex — Estonia (EE)

Status (July 2026): Adopted — verify. Community-maintained orientation, not legal advice — verify against the official gazette and authority guidance before relying on it. Corrections welcome (see CONTRIBUTING.md).

NIS2 implementation

Field Value
Implementing law Amendments to the Cybersecurity Act (küberturvalisuse seadus) transposing NIS2 — adopted 2025 (verify exact entry into force)
Competent authority Riigi Infosüsteemi Amet (RIA — Information System Authority)
National CSIRT / reporting CERT-EE (part of RIA)
Official starting point https://www.ria.ee

Country notes for your CDC

Estonia was in the May 2025 reasoned-opinion group; RIA guidance and the Estonian information security standard E-ITS are the practical baseline.

Standard checklist (all countries)

  • [ ] Applicability determined per legal entity and sector; recorded in the regulatory applicability register (GOVERN)
  • [ ] Entity registration completed with the national authority where required
  • [ ] Incident-reporting procedure drilled against the national channel and the 24 h early-warning clock (RESPOND)
  • [ ] Contact established with the national CSIRT before the first incident
  • [ ] Data protection authority contact and GDPR Art. 33 flow prepared (runs in parallel with NIS2 reporting)
  • [ ] National guidance/frameworks mapped to your control evidence (see note above)

Selector tag

ee-nat — tick "Estonia" in tools/regulatory-profile.html to include this country's references.

Open CDC Framework (CC BY 4.0).