Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties
Küberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 6-1 and 7
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 8 months, effective 1 January 2026.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential entity (ülioluline üksus) or an important entity (oluline üksus) drawn from the Cybersecurity Act's Section 3 entity and sector lists, which mirror NIS2's Annex I and Annex II; Section 2(2)'s digital-service-provider definition names a domain name system service provider, a top-level domain name registry operator, a domain name registration service provider, a cloud computing service provider, a data centre service provider, a content delivery network service provider, a managed service provider, a managed security service provider, an online marketplace operator, and an online search engine or social media platform provider, so a service in any of those lines is reached at the qualifying size threshold or above; the wider sector classes (energy, transport, banking, health, drinking water, central and local government public administration and the rest) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Apply, on an ongoing basis, appropriate and proportionate technical, operational and organisational security measures, built on your own risk analysis, to manage the risks to the system you use in your activities or to provide your service, to prevent or minimise a cyber incident's impact on your service's recipients and on other services, and to prevent, detect or resolve a cyber incident.
- Account for your own needs and security requirements, current European and international standards where relevant, the cost of the measures, their proportionality to your risk exposure and to the likelihood and severity of a cyber incident including its societal and economic impact, and a systemic, comprehensive approach that protects both the systems and their physical environment.
- Where you delegate management of your system to another person, or host it with another person, you remain responsible for ensuring that person applies the security measures.
- Designate at least one management board member (or, if you have only one, that member, or the equivalent office-holder if you have no board) to approve your security measures, monitor their implementation and answer for that duty, and have that person complete regular training to understand and assess cyber risk, its impact on your services, and how to manage it.
- The specific technical, methodological and, where relevant, sector-specific content these measures must have, including the Estonian Information Security Standard (E-ITS), comes from a Government or ministerial regulation issued under this duty, or from a European Commission implementing act under Directive (EU) 2022/2555 Article 21(5) where one applies to your service; that regulation's content is not described here.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A violation of Section 7(1), (2), (3), (5) or (7) by an essential or important entity is a 'väärtegu' (misdemeanour) under Section 18-2(1) (essential entity) or Section 18-3(1) (important entity), a form of quasi-criminal liability under Estonia's Penal Code procedural framework, prosecuted extrajudicially by RIA under Section 19(1) rather than tried as an ordinary crime, and time-barred after three years under Section 19(4). Only a fine (rahatrahv) is provided; no provision reviewed here attaches imprisonment to a Section 7 violation.
Penalty structure
Section 18-2(2) sets the ceiling for an essential entity that is a legal person at EUR 10,000,000 or 2 percent of its total worldwide annual turnover for the preceding financial year, whichever is greater; Section 18-3(2) sets the ceiling for an important entity that is a legal person at EUR 7,000,000 or 1.4 percent of that turnover, whichever is greater. Both sections also carry a lower fixed cap (EUR 10,000,000 for an essential entity, EUR 7,000,000 for an important entity) for a violation committed by a natural person under Section 18-2(1) and Section 18-3(1).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Riigi Infosüsteemi Amet (RIA), the Estonian Information System Authority, which the Cybersecurity Act's own Section 19(1) names as the extrajudicial adjudicator (kohtuväline menetleja) for a violation of Sections 18-2 through 18-5, including a violation of this Section 7 or Section 6-1 duty; Estonia's security authority (julgeolekuasutus) holds a parallel Article 8 competent-authority role for an entity within the Section 14 scope.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://www.ria.ee/uudised/uuest-aastast-laienes-kuberturvalisuse-seadus
- Guidance body
- Riigi Infosüsteemi Amet (RIA), the Estonian Information System Authority
- Open questions
- Does the Government or ministerial regulation issued under Section 7(5) to (7), including the Estonian Information Security Standard (E-ITS) and any sector-specific requirements it sets, impose obligations that go beyond the general risk-management duty Section 7 itself already states?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 7 requires an essential or important entity to apply, on an ongoing basis, appropriate and proportionate technical, operational and organisational security measures, based on its own risk analysis, to manage the risks to the system it uses in its activities or to provide its service, to prevent or minimise a cyber incident's impact on the recipients of its service and on other services, and to prevent, detect or resolve a cyber incident.
It must account for its own needs and security requirements, current European and international standards where relevant, the cost of the measures, their proportionality to its risk exposure and to the likelihood and severity of an incident including its societal and economic impact, and a systemic, comprehensive approach protecting both the systems and their physical environment.
A service provider that delegates system management to, or hosts its system with, another person remains responsible for ensuring that person applies the security measures.
The specific technical, methodological and sector-specific content of these measures, including the Estonian Information Security Standard (Eesti infoturbestandard, E-ITS), is set by a Government or ministerial regulation issued under Section 7, subsections 5 to 7, or by a European Commission implementing act under Directive (EU) 2022/2555 Article 21(5) where one applies to the service; that regulation's own content is not read here.
Section 6-1, also added by the 2025 amendment, requires a service provider to designate at least one management board member, or for a single-member board that member, or the equivalent office-holder for a provider with no board, who approves the security measures, monitors their implementation, is accountable for that duty, and completes regular training to understand and assess cyber risk.
Section 2(2) defines 'digitaalse teenuse osutaja' (digital service provider), an entity class reached by this duty, as an umbrella covering a domain name system service provider, a top-level domain name registry operator, a domain name registration service provider, a cloud computing service provider, a data centre service provider, a content delivery network service provider, a managed service provider, a managed security service provider, an operator of an online marketplace, and a provider of an online search engine or social media platform.
Section 3(2) names a central government public administration entity as an essential entity. Section 3(2) also names a local government public administration entity as an essential entity, so this duty reaches both public and private duty-bearers. Section 1(2) excludes state-secret and classified-foreign-information systems from the Act. Section 1(2) also excludes systems the Ministry of Defence needs for international military cooperation and national military defence preparation.
Estonia's security authority (julgeolekuasutus) holds the competent-authority role, instead of RIA, for an entity within the scope set out in Section 14. Both Section 7 and Section 6-1 entered into force on 1 January 2026 as part of Estonia's NIS2 transposition, amending the predecessor wording of Section 7 that had been in force since the Act's original 2018 enactment. A subject is given a three-year transition period to bring its activities into line with these requirements.
A vital-service provider under the Emergency Act instead follows a five-year deadline counted from its designation date. RIA's own account of the amendment states that from 2026 the number of Estonian undertakings subject to these requirements grew by about 3,000, to roughly 6,500.
When LexLint raises it
operates_social_platform
Read the law
Consolidated text
Riigi Teataja I, Küberturvalisuse seadus (KüTS), wording valid 1 January 2026 to 30 September 2026, carrying the amendments of RT I, 30.12.2025, 4 (Küberturvalisuse seaduse ja teiste seaduste muutmise seadus, in force 1 January 2026)