Den här sidan är maskinöversatt. Engelskt original: Engelsk version

Detta är en nationell skyldighet i Estland. Den är inte översatt till Svenska; den engelska originaltexten visas.

I kraftEstlandNIS2

Estonia NIS2: in-scope entities must register/notify RIA within 3 months of qualifying

för 161 dagar sedan (I kraft)

Anmärkning om datumet: Entities that already met the essential/important-entity criteria when the amended Küberturvalisuse seadus took effect on 2026-01-01 had to submit registration data (name, registry code, address, contacts, IP ranges, sector) to RIA within 3 months, i.e. by 2026-03-31 (RIA's own notice flagged issues with its automated notification tooling around that date). Entities that become in-scope later must still self-register with RIA within 3 months of first meeting the criteria — an ongoing rule, not a one-off deadline.

Vad som ändras

Companies newly brought into NIS2 scope by Estonia's amended Cybersecurity Act (effective 1 January 2026) had to register with the Information System Authority (RIA) within three months of the Act taking effect. Any company that later starts meeting the essential/important-entity criteria must still register with RIA within three months of qualifying.

Vem som berörs

Medium and large companies in NIS2 sectors that are or become in scope of Estonia's Cybersecurity Act, plus smaller entities RIA designates as critical or as sole providers of a service.

Storlekar: medelstort företag, stort företag · Branscher: Energi, Transport / logistik, Finans / försäkring, Hälso- och sjukvård, Programvara / SaaS, Tillverkning, Jordbruk / livsmedel, Konsult- och tjänsteföretag · Gäller om: Vi är verksamma i en kritisk sektor (NIS2); Vi är beroende av molntjänster

Vad du ska göra

Check whether you meet NIS2 sector/size criteria under the Küberturvalisuse seadus. If you qualify now (registration was due 2026-03-31 for the initial batch) or later, submit registration data to RIA within 3 months, and have initial risk-management measures and the 24h/72h/1-month incident-reporting workflow ready.

Sanktion

Essential entities up to €10M or 2% of turnover; important entities up to €7M or 1.4%

Källor

Senast verifierad 8 september 2026. Endast information, inte juridisk rådgivning.

Fler tidsfrister för NIS2

för 250 dagar sedan
I kraftEENIS2

Estonia NIS2: amended Cybersecurity Act applies to ~6,500 entities

The Küberturvalisuse seaduse ja teiste seaduste muutmise seadus (transposing NIS2) was passed by the Riigikogu on 10 December 2025, proclaimed by the President on 18 December 2025, published in Riigi Teataja on 30 December 2025, and entered into force on 1 January 2026, expanding scope from roughly 3,000 to about 6,500 regulated entities.

Medium and large Estonian companies in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure and ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus certain smaller providers designated by RIA.

för 144 dagar sedan
BekräftadLTNIS2

Lithuania NIS2: in-scope cybersecurity subjects must implement organisational measures within 12 months of registration

The Kibernetinio saugumo įstatymas (Act No. XII-1428), as amended by NIS2-transposing Act No. XIV-2902 (adopted 2024-07-11, in force from 2024-10-18), establishes a Cybersecurity Subjects Registry run by NKSC. Independent legal-tracker analysis (nis-2-directive.com; v-formation.io) reports that entities identified/registered as cybersecurity subjects by 2025-04-17 must implement organisational cybersecurity requirements within 12 months (i.e. by 2026-04-17) and technical requirements within 24 months (by 2027-04-17); later-registered entities follow the same 12/24-month clock from their own registration date. This transitional schedule could NOT be independently confirmed against NKSC's own guidance in this run — nksc.lt, kam.lt and vdai.lrv.lt all returned HTTP 403 (Cloudflare bot-challenge) to automated tools. Verify your specific deadline directly with NKSC or in a browser before relying on the exact date.

Medium and large entities (plus some smaller entities NKSC designates as critical or as a sole service provider) in NIS2 sectors: energy, transport, banking/finance, health, digital infrastructure/software, manufacturing, agri-food, public administration and more.

23 dagar
BekräftadLVNIS2

Latvia NIS2 (National Cybersecurity Law): cybersecurity self-assessment report to NKDC

Corrected: the cybersecurity-manager notification and the FIRST self-assessment report were both due 2025-10-01 (confirmed on cyber.gov.lv). Recurrence is NOT uniformly annual: under MK noteikumi Nr. 397 'Minimālās kiberdrošības prasības' (in force 2025-07-02, published Latvijas Vēstnesis 2025/123.1, point 8.3), only ICT critical-infrastructure owners/operators must resubmit the self-assessment report at least once a year (next due ~2026-10-01); other essential/important entities ('svarīgie pakalpojumu sniedzēji') must resubmit at least once every 3 years (next due ~2028). The exact per-subject deadline and form are set by Cabinet regulation, not the law itself (Nacionālās kiberdrošības likums, 43. pants).

Medium and large companies registered in Latvia in NIS2 sectors (energy, transport, banking, health, water, digital infrastructure, ICT services, manufacturing of critical goods, food, chemicals, postal, waste, research), plus smaller firms designated as ICT critical infrastructure or sole provider of a service.