5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Estonia

The Estonian Cybersecurity Act and NIS2: what changed on 1 January 2026

Estonia's NIS2 transposition entered into force on 1 January 2026 and took the number of covered entities from roughly 3,500 to about 6,500. Twice as many organisations are now under the supervision of the Estonian Information System Authority — and a significant proportion of them do not know it. The second change is sharper: the management board must itself approve the cyber risk management measures, monitor their implementation and complete mandatory training. One thing Estonia did not do is adopt the directive's optional management ban, and that omission changes where the personal exposure sits.

Also available in Eesti

How Barzel applies here Start free with BarzelVault

What changed on 1 January 2026?

Estonia transposed NIS2 by the Cybersecurity Act and Other Acts Amendment Act (küberturvalisuse seaduse ja teiste seaduste muutmise seadus), which amended the existing Cybersecurity Act (küberturvalisuse seadus, KüTS). It entered into force on 1 January 2026.

The transposition was late. The EU deadline was 17 October 2024 — Estonia arrived roughly 14 months afterwards. The practical consequence matters more than the arithmetic: many companies spent two years treating NIS2 as something that was coming, and a number of them still handle it as a future question. The obligations apply today. The supervisory authority is the Estonian Information System Authority (Riigi Infosüsteemi Amet, RIA).

Which entities are caught, and is a foreign parent's Estonian entity in scope?

Covered entities fall into two categories — essential and important. The expansion reaches, among others:

  • aviation and rail;
  • utilities;
  • hospitals;
  • banking;
  • cloud services;
  • ports;
  • waste management;
  • postal services;
  • parts of the food industry.

A waste management company, a port operator or a food producer does not usually think of itself as critical infrastructure. In the terms of the Act it is — and being covered does not depend on the organisation having reached that conclusion itself.

CategoryMaximum fine
Essential entitiesup to 10 million euros or 2% of worldwide annual turnover
Important entitiesup to 7 million euros or 1.4% of worldwide annual turnover

For a group, note what the turnover measure is calculated on. The fine ceiling is expressed as a percentage of worldwide annual turnover, which for a subsidiary of a large multinational is a very different number from the local revenue that would otherwise anchor a risk assessment. The obligation is local; the exposure is not. That asymmetry is the reason a small Estonian operating company deserves attention it would not get on revenue alone.

Scope itself attaches to the entity that provides the service in Estonia. A group relationship does not extend it: an Estonian subsidiary is tested on what it does in Estonia, and a foreign parent is not brought into KüTS by owning it. The reverse also holds — a parent's own compliance programme elsewhere does not discharge the Estonian entity's duties.

Did Estonia adopt the NIS2 management ban?

No. Estonia did not implement the directive's optional measure permitting a temporary prohibition on an individual exercising management functions. This is a real and practical difference from several EU states, and it is worth knowing if the group operates in more than one jurisdiction — not least because the ban is the sanction that changes how a board treats the subject.

CountryInstrumentIn forceBoard dutyManagement banSanctions
Estonia KüTS amendment 01.01.2026 approve measures and monitor implementation; mandatory training No — not adopted €10m / 2%; €7m / 1.4%; personal recourse under Commercial Code s 315(2)
Denmark NIS 2-loven 01.07.2025 management body approves the measures and supervises implementation; training duty Yes — for væsentlige enheder the authority may temporarily prohibit an individual from exercising management functions fines
Belgium NIS2 law of 26 April 2024 18.10.2024 approval and supervision duty on the management body Yes — the CCB may temporarily prohibit individuals from exercising management functions in essential entities fines
Germany new BSIG 06.12.2025 section 38: the Geschäftsleitung must implement the measures and monitor implementation No liability to the entity under company law
Slovakia NIS2 transposition 01.01.2025 duties on the governing body No štatutárny orgán — personal fine up to 5,000 euros
Norway digitalsikkerhetsloven 01.10.2025 — — NIS2 is not incorporated into the EEA Agreement and does not apply; the Act in force implements NIS1

Two things are true of the Estonian row at once: the duty exists, and the personal prohibition sanction does not. Liability therefore travels through company law rather than through an administrative ban. Where a breach of the duty causes loss to the company, section 315(2) of the Commercial Code (äriseadustik) opens the route to a personal recourse claim against the board member. The fine lands on the entity — and can itself be the loss the company then seeks to recover from its own board. The German solution is structurally similar; Norway is not in this framework at all.

Why is the training duty the provision that bites?

The Act imposes two distinct obligations on the management board:

  1. Approval and monitoring. The board must approve the cyber risk management measures and monitor their implementation.
  2. Training. Board members are subject to a mandatory training requirement.

The training duty is what makes the provision work. As long as training was voluntary, a board member could rely on not having the relevant competence. Once it is mandatory, that protection disappears: the law assumes the competence has been acquired, and a breach is assessed on that assumption.

The duty cannot be fully delegated. The practical work may sit with an information security officer, an IT function or a service provider; approval and monitoring stay with the board.

What must a group security function outside Estonia do differently?

Four differences are worth designing for.

Group approval does not discharge the Estonian board. Where a parent's board or a group risk committee approves a global information security policy, that is not the approval the Estonian Act requires. The juhatus — the management board of the Estonian entity — must approve the measures for that entity. A group whose evidence consists only of a parent-level resolution has a gap in Estonia even where the substance is identical.

The training obligation is personal, and board seats are often held by group staff. In many multinationals the Estonian board seats are filled by finance or country managers who also sit elsewhere. The training requirement attaches to them as individuals in that capacity. Track completion by person and by entity, not by policy.

The recourse route changes who cares. Because Estonia has no management ban, the personal consequence arrives as a claim by the company against its directors under section 315(2) rather than as a regulatory prohibition. That is a D&O question and an indemnity question as much as a security one, and it is worth raising with the people who own those arrangements.

The RIA submission is entity-level. The data submitted describes the Estonian entity's activity. A group inventory maintained centrally will not usually be in the right shape for it, and the exercise of putting it in the right shape is where the missing systems surface.

What does approve and monitor mean when systems act on their own?

Approval presupposes that the board can say what the organisation's systems are permitted to do. For access management and backup that is intelligible. It becomes harder when part of the daily work is done by systems acting independently: integrations with write permissions in financial systems, automated workflows that initiate payments or change master data, and AI agents that interpret input and act on it. Where there is no human at each step, three things have to be in place.

Which operations are permitted — and who decided the boundary?

An integration's permissions are usually inherited from the user under which it was once configured. There is no limit by amount, counterparty or operation type. The set of permitted operations has therefore formed by itself: nobody decided it, and consequently nobody has approved it. Board approval presupposes a boundary about which one can say who set it and when.

Does the control run before the operation or after it?

Monitoring and logging say what happened. They do not prevent it happening. Where an operation has a financial or legal consequence, the question is whether there is a control before execution — a rule that rejects the operation, or a step requiring human confirmation above a threshold. An alert sent afterwards is not monitoring of implementation; it is registration of a consequence. The general form of this problem is set out under approving AI actions.

Will the trail still exist in six months?

Application logs rotate. If the documentation of an automated system's activity exists only in log files with a 30-day retention, then at the moment of a supervisory enquiry or an incident investigation it does not exist. The same principle is treated at length in the AI agent audit trail article.

And one nuance present in the wording of the Act that disappears in practice: monitoring is continuous; approval is not a one-off. A document signed at one meeting does not satisfy the provision if the systems then change and nobody reviews them.

Why is the three-month deadline really an inventory deadline?

Covered entities must submit data about their activity to RIA within three months. Operators of critical infrastructure have a five-year transition period running from designation.

Three months sounds like an administrative formality. It is not. An organisation cannot describe its systems without a list of them — and most do not have a complete view of which integrations, service accounts and automated workflows actually perform operations in their environment. The missing inventory is usually discovered at exactly this deadline. In practice, therefore, the three months are a discovery deadline rather than a reporting one.

Where does the AI Act stand in Estonia?

The cybersecurity obligations are in force. AI regulation is not in the same position, and the sequence matters for a group deciding where to spend the next two quarters.

There is no national AI Act implementing law in force in Estonia. The Consumer Protection and Technical Regulatory Authority (TTJA) states on its own site that it will in future take the role of market surveillance authority for AI systems — a stated intention, not a completed statutory designation. Digital and AI policy sits with the Ministry of Justice and Digital Affairs.

At EU level the deadlines moved. The AI Act, as amended by Regulation (EU) 2026/1744, in force 27 July 2026:

  • Annex III high-risk systems — deferred to 2 December 2027;
  • Annex I high-risk systems — deferred to 2 August 2028;
  • the transparency obligations were not deferred — they have applied since 2 August 2026.

The sequence is therefore clear. The cybersecurity obligations bind first: the KüTS requirements apply already, while the AI Act's high-risk requirements are years away and Estonia has not yet designated an AI market surveillance authority. A company that waits for AI regulation to settle before putting its governance in order is waiting for the wrong deadline.

The same caution applies elsewhere, where something planned is presented as being in force. On e-invoicing there is no general B2B obligation in Estonia: since 1 July 2025 a buyer has a right to require an e-invoice where it is registered in the commercial register as an e-invoice recipient, and the 2027 obligation is a ministry intention to draft (December 2024), not a law.

In practice

BarzelVault applies policy and approval thresholds before an operation executes and issues a signed audit receipt for each one, which is the part of approve-and-monitor that monitoring alone cannot supply. BarzelOps runs governed cross-system workflows with durable state, approval checkpoints and tenant isolation.

How Barzel applies here

Frequently asked questions

When did NIS2 take effect in Estonia?

The Cybersecurity Act and Other Acts Amendment Act entered into force on 1 January 2026, roughly 14 months after the EU deadline of 17 October 2024.

How many entities are covered?

About 6,500, up from roughly 3,500. The supervisory authority is RIA. Maximum fines are €10m or 2% of worldwide turnover for essential entities and €7m or 1.4% for important entities.

Did Estonia adopt the management ban?

No. Estonia did not implement the directive's optional temporary prohibition on exercising management functions. Denmark and Belgium use that measure for essential entities; Estonia routes personal exposure through Commercial Code section 315(2) instead.

Can the board delegate the duty?

Not fully. The practical work may be given to others, but approval and monitoring of implementation remain with the management board, and the training requirement is personal to each member.

What is the three-month deadline?

A covered entity must submit data about its activity to RIA within three months. Operators of critical infrastructure have a five-year transition period from designation.

Is there an Estonian AI Act implementing law?

None in force. TTJA has stated an intention to take the market surveillance role in future; policy sits with the Ministry of Justice and Digital Affairs.

Related reading

In practice

Contain the incident first, prove what happened second — inside the reporting window.

Reporting clocks run in hours, and management liability turns on whether controls were implemented and supervised, not merely approved. Barzel isolates credentials, cuts an agent off in one action and keeps signed receipts of what ran — the material a notification and a board report are written from.

In forceEstonian Cybersecurity Act (NIS2) in force since 1 January 2026

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Küberturvalisuse seaduse ja teiste seaduste muutmise seadus, in force 1 January 2026; küberturvalisuse seadus (KüTS) — riigiteataja.ee. Left as plain text: the register is script-gated and carries several superseded consolidated redactions, so the text in force could not be identified with certainty.
  2. Riigi Infosüsteemi Amet, Uuest aastast laienes küberturvalisuse seadus — scope of the expansion and the data submission deadline.
  3. Äriseadustik (Commercial Code) section 315 — riigiteataja.ee. Left as plain text for the same reason.
  4. Directive (EU) 2022/2555 (NIS2), transposition deadline 17 October 2024.
  5. Denmark: LOV nr 434 af 06/05/2025 (NIS 2-loven), in force 1 July 2025.
  6. Belgium: the NIS2 law of 26 April 2024, in force 18 October 2024; Centre for Cybersecurity Belgium.
  7. Germany: BSIG section 38, NIS2UmsuCG version, in force 6 December 2025.
  8. Norway: Lov om digital sikkerhet (digitalsikkerhetsloven), in force 1 October 2025 (NIS1).
  9. Regulation (EU) 2026/1744, in force 27 July 2026.
  10. Tarbijakaitse ja Tehnilise Järelevalve Amet (TTJA), information on market surveillance of AI systems; Ministry of Justice and Digital Affairs.
  11. Rahandusministeerium, E-arveldamine muutub paindlikumaks — the Estonian e-invoicing position referred to above.

This article is for information and does not constitute legal or tax advice. The Estonian text of the instruments cited is the binding one. Position as at 3 September 2026.