NIS2 in Estonia — the amended Cybersecurity Act, RIA as single authority, and a three-year runway.
Estonia transposed NIS2 by amending its existing Cybersecurity Act rather than writing a new one — the Riigikogu passed the amendment on 10 December 2025 and it entered into force on 1 January 2026, after a Commission reasoned opinion over the delay. The structural choice matters: obligations that used to attach to specific services now apply organization-wide. The Information System Authority (RIA) is the single competent authority and point of contact, with CERT-EE operating inside it as the national CSIRT.
RIA projects roughly 6,500 entities in scope, up from about 3,500 under the old regime — the expansion lands on a country where digital government is the default, so an unusually large share of public administration meets the thresholds. The transition is deliberately long: entities registered by 1 April 2026, full compliance phased over three years to 1 January 2029, and vital-service designations running on a five-year track.
Who it applies to
Essential and important entities across the NIS2 sectors, now assessed organization-wide rather than per-service. Entities had to submit their activity data to RIA within three months of entry into force — by 1 April 2026 — through the self-registration portal RIA opened on 1 January. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.
The clock
Competent authority: RIA (Information System Authority). Transposition: Cybersecurity Act amendment (RT I, 30.12.2025, 4).
| When | What happens |
|---|---|
| 10 Dec 2025 | Riigikogu passes the Cybersecurity Act amendment |
| 1 Jan 2026 | Amendment enters into force · RIA self-registration portal opens |
| 1 Apr 2026 | Registration deadline — activity data submitted to RIA |
| 1 Jan 2029 | Full compliance after the three-year transition |
An amendment, not a new law — and a long transition
Most member states stood up new NIS2 legislation; Estonia folded the directive into the Cybersecurity Act it has run since 2018, and in doing so changed the unit of compliance: requirements that once applied per-service now apply to the whole organization. For entities already inside the old regime that is an expansion of scope, not a new rulebook — the same RIA relationship, the same CERT-EE reporting channels, broader coverage. The three-year transition to full compliance is among the most generous in the Union, but the registration clock was short: activity data was due to RIA by 1 April 2026, three months after entry into force. TruSecure holds both clocks — registration status as a dated record, and the phased measures mapped against the 2029 horizon — so the transition reads as a plan, not a deadline surprise.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Estonia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with RIA (activity data by 1 Apr 2026) | Entity profile · registration facts held as records |
| Meet the security-measures duty organization-wide | Control library · mapped from per-service to whole-organization scope |
| Report incidents to CERT-EE: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Show management-body oversight | Governance workspace · approvals and training records, dated |
| Phase measures to the 2029 horizon | Compliance plan · transition milestones tracked as dated facts |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- RIA registration
- filed 12 Feb 2026 · activity data accepted
- Scope basis
- organization-wide · amended Cybersecurity Act
- Controls evidenced
- 74/96 · 22 open, each with an owner and a date
- Incident reports
- 1 filed · CERT-EE, within statutory timeframes
- Export
- sealed · sha256:7f2a...91d4
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your position under the amended Act, the controls you already operate credited against organization-wide scope, and your phase plan mapped to the 2029 horizon. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Estonia by RIA (Information System Authority). TruSecure determines applicability against Estonia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.