Skip to main content
NIS2 · ESTONIA

NIS2 in Estonia — the amended Cybersecurity Act, RIA as single authority, and a three-year runway.

Estonia transposed NIS2 by amending its existing Cybersecurity Act rather than writing a new one — the Riigikogu passed the amendment on 10 December 2025 and it entered into force on 1 January 2026, after a Commission reasoned opinion over the delay. The structural choice matters: obligations that used to attach to specific services now apply organization-wide. The Information System Authority (RIA) is the single competent authority and point of contact, with CERT-EE operating inside it as the national CSIRT.

RIA projects roughly 6,500 entities in scope, up from about 3,500 under the old regime — the expansion lands on a country where digital government is the default, so an unusually large share of public administration meets the thresholds. The transition is deliberately long: entities registered by 1 April 2026, full compliance phased over three years to 1 January 2029, and vital-service designations running on a five-year track.

Who it applies to

Essential and important entities across the NIS2 sectors, now assessed organization-wide rather than per-service. Entities had to submit their activity data to RIA within three months of entry into force — by 1 April 2026 — through the self-registration portal RIA opened on 1 January. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.

The clock

Competent authority: RIA (Information System Authority). Transposition: Cybersecurity Act amendment (RT I, 30.12.2025, 4).

NIS2 in Estonia · timeline
WhenWhat happens
10 Dec 2025Riigikogu passes the Cybersecurity Act amendment
1 Jan 2026Amendment enters into force · RIA self-registration portal opens
1 Apr 2026Registration deadline — activity data submitted to RIA
1 Jan 2029Full compliance after the three-year transition

An amendment, not a new law — and a long transition

Most member states stood up new NIS2 legislation; Estonia folded the directive into the Cybersecurity Act it has run since 2018, and in doing so changed the unit of compliance: requirements that once applied per-service now apply to the whole organization. For entities already inside the old regime that is an expansion of scope, not a new rulebook — the same RIA relationship, the same CERT-EE reporting channels, broader coverage. The three-year transition to full compliance is among the most generous in the Union, but the registration clock was short: activity data was due to RIA by 1 April 2026, three months after entry into force. TruSecure holds both clocks — registration status as a dated record, and the phased measures mapped against the 2029 horizon — so the transition reads as a plan, not a deadline surprise.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Estonia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Estonia requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with RIA (activity data by 1 Apr 2026)Entity profile · registration facts held as records
Meet the security-measures duty organization-wideControl library · mapped from per-service to whole-organization scope
Report incidents to CERT-EE: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Show management-body oversightGovernance workspace · approvals and training records, dated
Phase measures to the 2029 horizonCompliance plan · transition milestones tracked as dated facts

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Estonia NIS2 readiness file · excerptSample data
RIA registration
filed 12 Feb 2026 · activity data accepted
Scope basis
organization-wide · amended Cybersecurity Act
Controls evidenced
74/96 · 22 open, each with an owner and a date
Incident reports
1 filed · CERT-EE, within statutory timeframes
Export
sealed · sha256:7f2a...91d4

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your position under the amended Act, the controls you already operate credited against organization-wide scope, and your phase plan mapped to the 2029 horizon. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Estonia by RIA (Information System Authority). TruSecure determines applicability against Estonia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Why does NIS2 cover so much of Estonia's public sector?
Estonia's digital-government model means a larger share of public administration meets NIS2 essential/important entity thresholds relative to population than in most member states — TruSecure's applicability engine reflects that footprint directly.