RISI

NIS2 › NIS2 transposition tracker

Estonia · EE

Küberturvalisuse seaduse muutmise seadus (Act amending the Cybersecurity Act, KüTS)

← Back to tracker

Status
Transposed
In force from
2026-01-01
Implementing law
Küberturvalisuse seaduse muutmise seadus (Act amending the Cybersecurity Act, KüTS)
EU infringement procedure
Reasoned opinion
Competent authority
Riigi Infosüsteemi Amet (RIA) — Information System Authority Competent authority NIS2 page →
National CSIRT
CERT-EE (within RIA) CSIRT website →

Notable national choices

  • Transposed by amending the existing 2018 Cybersecurity Act rather than passing a new statute.
  • Generous three-year transition: registration from 1 April 2026, governance from 1 January 2027, full technical compliance from 1 January 2028.
  • Affects roughly 6,500 entities — a very large multiple of the pre-NIS2 scope for a population of 1.3 million.

Sources

Last verified: