Estonia transposed NIS2 by amending its existing Küberturvalisuse seadus (Cybersecurity Act, KüTS), first adopted 9 May 2018 (RT I, 22.05.2018, 1, in force 23 May 2018, with some provisions phased in on 1 January 2020 and 1 January 2022), rather than repealing it and enacting a new standalone law.
The amending Act, Küberturvalisuse seaduse ja teiste seaduste muutmise seadus (küberturvalisuse 2. direktiivi ülevõtmine) (Act Amending the Cybersecurity Act and Other Acts, Transposition of the Second Cybersecurity Directive), was adopted by the Riigikogu on 10 December 2025, proclaimed by the President of the Republic on 18 December 2025 (decision no. 640), published as RT I, 30.12.2025, 4, and entered into force on 1 January 2026 under its own Section 11, so the current consolidated KüTS reads as amended from that date; Riigi Teataja's own consolidated-text header records this wording as valid from 1 January 2026 to 30 September 2026, meaning a further amendment is scheduled to take effect immediately after, whose content is not read here.
Section 3 defines the entity classes: an 'ülioluline üksus' (essential entity) and an 'oluline üksus' (important entity), drawn from sector, size and criticality thresholds that mirror the NIS2 Annex I and Annex II lists, and expressly include a central government public administration entity and a local government public administration entity among essential entities, so the Act reaches both public and private duty-bearers.
Section 2(2) defines 'digitaalse teenuse osutaja' (digital service provider) as an umbrella covering a domain name system service provider, a top-level domain name registry operator, a domain name registration service provider, a cloud computing service provider, a data centre service provider, a content delivery network service provider, a managed service provider, a managed security service provider, an operator of an online marketplace, and a provider of an online search engine or social media platform.
Section 7 requires a service provider to apply, on an ongoing basis, appropriate and proportionate technical, operational and organisational security measures, built on its own risk analysis, to manage risk to its systems, prevent or minimise a cyber incident's impact, and prevent, detect or resolve a cyber incident, taking into account its needs and security requirements, current European and international standards, implementation cost, proportionality to its risk exposure and to the likelihood and severity of an incident, and a systemic approach protecting both the systems and their physical environment; a service provider that delegates system management or hosting to another person remains responsible for that person applying the measures.
The specific technical, methodological and, where relevant, sector-specific content of those measures, including the Estonian Information Security Standard (Eesti infoturbestandard, E-ITS), is left to a Government or ministerial regulation issued under Section 7(5) to (7), or to a European Commission implementing act under Directive (EU) 2022/2555 Article 21(5) where one applies; that regulation's own content is not read here.
Section 6-1, also added by the 2025 amendment, requires a service provider to designate at least one management board member (or, for a single-member board, that member, or the equivalent office-holder for a provider with no board) who approves the security measures, monitors their implementation, is accountable for that duty, and completes regular training to understand and assess cyber risk.
Section 8 sets a graduated notification clock to the Riigi Infosüsteemi Amet (RIA, the Estonian Information System Authority): an initial report without delay and no later than 24 hours after becoming aware of a cyber incident with, or reasonably expected to have, a significant effect on system security or service continuity; an incident report no later than 72 hours after becoming aware of a significant-impact incident, updating the initial report (a qualified trust service provider instead reports in a single 24-hour stage); an interim report on RIA's request; and a final report within one month of the incident report, treated as interim and followed by a fresh final report within one month of resolution if the incident is still unresolved.
Section 8(2) defines 'significant effect' by six alternative conditions (a risk-analysis severity rating of at least severe, exceeding the maximum permitted service outage, disrupting another provider's service continuity, requiring extraordinary measures from the risk analysis or continuity documentation, causing or risking significant damage, or being significant under a Commission implementing act on Article 23(11)), and Section 8(3) makes an incident always significant if it also disrupts the service in at least one other EU member state; Section 8(5) and (6) require notifying affected persons or the public where relevant, and let RIA itself inform the public, after consulting the provider, or require the provider to do so, where public awareness serves prevention, resolution or the public interest.
Section 8-1 lets a service provider, or any other person, voluntarily notify RIA of a cyber incident, vulnerability or threat below the mandatory threshold, including a vulnerability report submitted anonymously.
Section 5(3) designates RIA as the competent authority and single point of contact under Directive (EU) 2022/2555 Article 8, the authority for large-scale incidents and crises under Article 9, the national CSIRT under Article 10, the coordinated-vulnerability-disclosure coordinator under Article 12, and Estonia's participant in the CSIRTs network under Article 15; Section 5(4) gives Estonia's security authority (julgeolekuasutus) the Article 8 competent-authority role within the scope set out in Section 14, consistent with Section 1(2)'s exclusion of state-secret and classified-foreign-information systems and of systems the Ministry of Defence needs for international military cooperation and national military defence preparation.
Sections 18-2 and 18-3, both introduced by the 2025 amendment, make it a 'väärtegu' (a misdemeanour under Estonian penal-procedure law, prosecuted extrajudicially rather than a purely administrative fine) for an essential entity to violate the Section 7 or Section 8 duties described above, punishable for a legal person by a fine of up to EUR 10,000,000 or up to 2 percent of the entity's total worldwide annual turnover for the preceding financial year, whichever is greater, and for an important entity, punishable by a fine of up to EUR 7,000,000 or up to 1.4 percent of that turnover, whichever is greater; Section 19(1) names RIA as the extrajudicial adjudicator for these misdemeanours, Section 19(2) applies the Isikuandmete kaitse seaduse (Personal Data Protection Act) misdemeanour-procedure rules where a violation also involves personal-data-processing requirements, filed separately in the privacy topic together with Estonia's General Data Protection Regulation (GDPR) Articles 33-34 breach-notification document, and Section 19(4) sets a three-year limitation period.
RIA's own 2 January 2026 announcement states that from 2026 the number of Estonian undertakings subject to mandatory cybersecurity requirements grew by about 3,000, to roughly 6,500, newly reaching sectors such as airlines, rail, electricity, district heating, ports, credit institutions, cloud computing providers and hospitals, alongside size-qualifying food-processing, postal and waste-management undertakings; subjects get a three-year transition period to align their activities and must report their operational data to RIA within three months, except a vital-service provider under the Hädaolukorra seadus (Emergency Act), which instead follows a five-year deadline counted from its designation date.
No instrument reviewed here imposes a Estonia-specific product-security or market-placement duty on a manufacturer of a connected device independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and not restated here.
No general, sector-agnostic reasonable-security or information-security-programme statute was found; the closest general duty is GDPR Article 32's security-of-processing obligation, which sits in the privacy topic, as does Estonia's GDPR Articles 33-34 breach-notification document already in the corpus.