NIS2 › NIS2 transposition tracker
Estonia · EE
Küberturvalisuse seaduse muutmise seadus (Act amending the Cybersecurity Act, KüTS)
- Status
- Transposed
- In force from
- 2026-01-01
- Implementing law
- Küberturvalisuse seaduse muutmise seadus (Act amending the Cybersecurity Act, KüTS)
- EU infringement procedure
- Reasoned opinion
- Competent authority
- Riigi Infosüsteemi Amet (RIA) — Information System Authority Competent authority NIS2 page →
- National CSIRT
- CERT-EE (within RIA) CSIRT website →
Notable national choices
- Transposed by amending the existing 2018 Cybersecurity Act rather than passing a new statute.
- Generous three-year transition: registration from 1 April 2026, governance from 1 January 2027, full technical compliance from 1 January 2028.
- Affects roughly 6,500 entities — a very large multiple of the pre-NIS2 scope for a population of 1.3 million.
Sources
Last verified: