Cette page a été traduite automatiquement. Original en anglais : Version anglaise

Il s'agit d'une obligation nationale en Estonie. Elle n'est pas traduite en Français ; la version originale anglaise est affichée.

En vigueurEstonieNIS2

Estonia NIS2: in-scope entities must register/notify RIA within 3 months of qualifying

il y a 161 jours (En vigueur)

Note sur la date : Entities that already met the essential/important-entity criteria when the amended Küberturvalisuse seadus took effect on 2026-01-01 had to submit registration data (name, registry code, address, contacts, IP ranges, sector) to RIA within 3 months, i.e. by 2026-03-31 (RIA's own notice flagged issues with its automated notification tooling around that date). Entities that become in-scope later must still self-register with RIA within 3 months of first meeting the criteria — an ongoing rule, not a one-off deadline.

Ce qui change

Companies newly brought into NIS2 scope by Estonia's amended Cybersecurity Act (effective 1 January 2026) had to register with the Information System Authority (RIA) within three months of the Act taking effect. Any company that later starts meeting the essential/important-entity criteria must still register with RIA within three months of qualifying.

Qui est concerné

Medium and large companies in NIS2 sectors that are or become in scope of Estonia's Cybersecurity Act, plus smaller entities RIA designates as critical or as sole providers of a service.

Tailles : moyenne, grande · Secteurs : Énergie, Transport / logistique, Finance / assurance, Santé, Logiciels / SaaS, Industrie manufacturière, Agriculture / agroalimentaire, Services professionnels · S'applique si : Nous opérons dans un secteur critique (NIS2); Nous dépendons de services cloud

Que faire

Check whether you meet NIS2 sector/size criteria under the Küberturvalisuse seadus. If you qualify now (registration was due 2026-03-31 for the initial batch) or later, submit registration data to RIA within 3 months, and have initial risk-management measures and the 24h/72h/1-month incident-reporting workflow ready.

Sanction

Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4%

Sources

Dernière vérification le 8 septembre 2026. À titre informatif uniquement, ne constitue pas un conseil juridique.

Autres échéances NIS2

il y a 250 jours
En vigueurEENIS2

Estonia NIS2: amended Cybersecurity Act applies to ~6,500 entities

The Küberturvalisuse seaduse ja teiste seaduste muutmise seadus (transposing NIS2) was passed by the Riigikogu on 10 December 2025, proclaimed by the President on 18 December 2025, published in Riigi Teataja on 30 December 2025, and entered into force on 1 January 2026, expanding scope from roughly 3,000 to about 6,500 regulated entities.

Medium and large Estonian companies in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure and ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus certain smaller providers designated by RIA.

il y a 144 jours
ConfirméeLTNIS2

Lithuania NIS2: in-scope cybersecurity subjects must implement organisational measures within 12 months of registration

The Kibernetinio saugumo įstatymas (Act No. XII-1428), as amended by NIS2-transposing Act No. XIV-2902 (adopted 2024-07-11, in force from 2024-10-18), establishes a Cybersecurity Subjects Registry run by NKSC. Independent legal-tracker analysis (nis-2-directive.com; v-formation.io) reports that entities identified/registered as cybersecurity subjects by 2025-04-17 must implement organisational cybersecurity requirements within 12 months (i.e. by 2026-04-17) and technical requirements within 24 months (by 2027-04-17); later-registered entities follow the same 12/24-month clock from their own registration date. This transitional schedule could NOT be independently confirmed against NKSC's own guidance in this run — nksc.lt, kam.lt and vdai.lrv.lt all returned HTTP 403 (Cloudflare bot-challenge) to automated tools. Verify your specific deadline directly with NKSC or in a browser before relying on the exact date.

Medium and large entities (plus some smaller entities NKSC designates as critical or as a sole service provider) in NIS2 sectors: energy, transport, banking/finance, health, digital infrastructure/software, manufacturing, agri-food, public administration and more.

23 jours
ConfirméeLVNIS2

Latvia NIS2 (National Cybersecurity Law): cybersecurity self-assessment report to NKDC

Corrected: the cybersecurity-manager notification and the FIRST self-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasības' (in force 2025-07-02, published Latvijas Vēstnesis 2025/123.1, point 8.3), only ICT critical-infrastructure owners/operators must resubmit the self-assessment report at least once a year (next due ~2026-10-01); other essential/important entities ('svarīgie pakalpojumu sniedzēji') must resubmit at least once every 3 years (next due ~2028). The exact per-subject deadline and form are set by Cabinet regulation, not the law itself (Nacionālās kiberdrošības likums, 43. pants).

Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms designated as ICT critical infrastructure or sole provider of a service.