6 August 2026 Update - The transposition of NIS 2 in Estonia
Estonia completed the principal transposition of NIS 2 through the Cybersecurity Act Amendment Act, which entered into force on 1 July 2025, amending the existing Cybersecurity Act to implement the requirements of Directive (EU) 2022/2555.
As of 6 August 2026, the emphasis has shifted to identification and registration of essential and important entities, implementation of cybersecurity risk management measures, management accountability, operational compliance with the amended Cybersecurity Act, and supervisory oversight by the Information System Authority (RIA), including continued coordination between the national cybersecurity framework and Estonia's broader digital government and critical service resilience architecture.
12 March 2026 Update - The transposition of NIS 2 in Estonia
Estonia has now completed the legislative transposition of Directive (EU) 2022/2555 into its national legal order, although the process occurred after the deadline established by European Union law.
Estonia did not adopt a completely new cybersecurity statute for this purpose. It implemented the directive primarily through amendments to the existing Cybersecurity Act, expanding and modernising a regulatory framework that had already been relatively advanced in comparison with many other Member States.
The primary supervisory authority under the Estonian system is the Information System Authority (RIA), which performs the functions of national competent authority, cybersecurity regulator, and coordinator of incident response through the national CERT capability (CERT-EE). This institutional structure already provided Estonia with a comparatively mature cybersecurity governance framework before the adoption of the NIS 2 Directive.
The NIS 2 Directive required Member States to transpose its provisions into national law by 17 October 2024. Estonia did not meet this deadline. According to official explanations from Estonian authorities, the legislative process required additional time due to sector specific consultations and technical adjustments to the existing regulatory framework.
As a result of this delay, the European Commission initiated infringement procedures against several Member States, including Estonia, for failing to notify the full transposition of the directive within the prescribed timeframe. Despite the missed deadline, Estonia continued the legislative process and ultimately adopted the required amendments during the following year.
The Estonian government introduced a bill titled “Amendments to the Cybersecurity Act and Other Acts (Transposition of the NIS 2 Directive)”, which served as the principal legislative instrument for implementing the directive. The draft legislation was submitted to the Estonian Parliament as part of a broader reform intended to align the national cybersecurity framework with the expanded scope and regulatory architecture established by NIS 2.
The legislative reform significantly broadens the scope of the national cybersecurity regime and strengthens the supervisory powers of national authorities. One of the most notable effects of the reform is the expansion of the number of organizations subject to cybersecurity regulation. The explanatory materials accompanying the bill estimated that the number of regulated entities would increase from roughly 3,500 entities to approximately 6,500, reflecting the broader sectoral coverage mandated by the directive.
The legislative amendments were subsequently adopted, and the transposition of the directive into Estonian law was completed through amendments to the Cybersecurity Act.
The amendments implementing the NIS 2 Directive entered into force on 1 January 2026, marking the moment when Estonia formally aligned its national cybersecurity legislation with the directive.
The revised Estonian cybersecurity framework reflects the structural architecture introduced by the NIS 2 Directive. The law expands the regulatory perimeter to include a broader range of sectors, including energy, transport, health, digital infrastructure, and public administration.
Entities falling within the scope of the legislation are classified in accordance with the NIS 2 model of essential entities and important entities, and are required to implement comprehensive cybersecurity risk-management measures. These measures include organizational governance arrangements, incident detection and reporting capabilities, supply-chain security controls, vulnerability management processes, and business continuity planning.
The amended law also strengthens enforcement powers available to supervisory authorities, allowing them to conduct inspections, require corrective measures, and impose administrative penalties in cases of non-compliance.
Following the entry into force of the amendments, Estonia initiated the operational phase of implementation. Authorities must identify and register the entities that fall within the scope of the new cybersecurity framework. According to the implementation timeline developed by Estonian authorities, the number of regulated entities is expected to grow substantially, and organizations newly brought within scope must register and implement the required security controls over a phased transition period.
For many organizations that were not previously regulated under the earlier cybersecurity regime, compliance will require the establishment of structured cybersecurity governance processes, incident reporting procedures, and risk-management frameworks consistent with the directive’s requirements.
EU - Transposition, Member States