In forceEstoniaNIS2

Estonia NIS2: amended Cybersecurity Act applies to ~6,500 entities

249 days ago (In force)

What changes

Estonia's amended Küberturvalisuse seadus transposing NIS2 entered into force on 1 January 2026, roughly doubling the number of regulated organisations. In-scope entities must register with the Information System Authority (RIA), apply risk-management measures and report significant incidents.

Who is affected

Medium and large Estonian companies in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure and ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus certain smaller providers designated by RIA.

Sizes: medium, large · Sectors: Energy, Transport / logistics, Finance / insurance, Health, Software / SaaS, Manufacturing, Agriculture / food, Professional services · Applies if: We operate in a critical sector (NIS2); We rely on cloud services

What to do

Check the sector and size criteria in the Act and register with RIA if in scope. Implement the Estonian baseline security standard (E-ITS) or an equivalent, assign management responsibility, and set up 24h/72h incident reporting to CERT-EE.

Penalty

Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4%

Sources

Last verified 7 September 2026. Informational only, not legal advice.

More NIS2 deadlines

24 days
ConfirmedLVNIS2

Latvia NIS2 (National Cybersecurity Law): annual self-assessment report for essential and important entities

Law in force since 2024-09-01; registration deadline was 2025-04-01, first cybersecurity manager notification and self-assessment report 2025-10-01; annual report by 1 October each year per NKDC guidance – confirm exact date with cyber.gov.lv

Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms that are the sole provider of a service or own critical ICT infrastructure.