Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident
Küberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 8 months, effective 1 January 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds the same essential and important entities as this jurisdiction's companion risk-management row, on the same Section 3 and Section 2(2) scope.
- Submit an initial report to RIA without delay and no later than 24 hours after becoming aware of a cyber incident that has, or could reasonably be expected to have, a significant effect on your system's security or your service's continuity, unless you are a security authority.
- A cyber incident has a significant effect if any of: it rates at least severe under your own risk analysis; it prevents you continuing your service beyond the maximum permitted outage in your service-level agreement or continuity requirements; it disrupts another provider's service continuity; resolving it requires extraordinary measures from your risk analysis or continuity documentation; it has caused or risks significant damage to you, another provider or your service's users; or a European Commission implementing act names it as significant. An incident that also disrupts your service in another EU member state is always significant.
- Follow with an incident report no later than 72 hours after becoming aware of the significant incident, updating the initial report, unless you are a qualified trust service provider, in which case you report in a single stage within 24 hours instead.
- Submit an interim report if RIA asks for one, and a final report within one month of the incident report, or, if the incident is still unresolved at that point, treat that report as interim and submit a further final report within one month of resolution.
- Where relevant, notify within a reasonable time any person the significant incident or a significant cyber threat may affect, or the public where you cannot notify affected persons individually; RIA may also itself inform the public after consulting you, or require you to, where public awareness serves prevention, resolution or the public interest.
- You may also voluntarily notify RIA of a cyber incident, a security vulnerability or a cyber threat that does not meet the mandatory threshold, including a vulnerability report submitted anonymously.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A violation of Section 8(1), (1-1), (4-1), (4-2), (4-3), (5), (7) or Section 8-1 by an essential or important entity is a 'väärtegu' (misdemeanour) under Section 18-2(1) (essential entity) or Section 18-3(1) (important entity), a form of quasi-criminal liability under Estonia's Penal Code procedural framework, prosecuted extrajudicially by RIA under Section 19(1) rather than tried as an ordinary crime, and time-barred after three years under Section 19(4). Only a fine (rahatrahv) is provided; no provision reviewed here attaches imprisonment to a Section 8 violation.
Penalty structure
Section 18-2(2) sets the ceiling for an essential entity that is a legal person at EUR 10,000,000 or 2 percent of its total worldwide annual turnover for the preceding financial year, whichever is greater; Section 18-3(2) sets the ceiling for an important entity that is a legal person at EUR 7,000,000 or 1.4 percent of that turnover, whichever is greater. Both sections also carry a lower fixed cap (EUR 10,000,000 for an essential entity, EUR 7,000,000 for an important entity) for a violation committed by a natural person under Section 18-2(1) and Section 18-3(1).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Riigi Infosüsteemi Amet (RIA), the Estonian Information System Authority, which the Cybersecurity Act's own Section 19(1) names as the extrajudicial adjudicator (kohtuväline menetleja) for a violation of Sections 18-2 through 18-5, including a violation of this Section 8 reporting duty, and which also receives the notifications as the national CSIRT.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://www.ria.ee/uudised/uuest-aastast-laienes-kuberturvalisuse-seadus
- Guidance body
- Riigi Infosüsteemi Amet (RIA), the Estonian Information System Authority
- Open questions
- Does the ministerial regulation on incident-notification data and procedure issued under Section 8(8), or a future European Commission implementing act under Directive (EU) 2022/2555 Article 23(11) on the incident-report or final-report format, narrow or expand the significance triggers Section 8(2) already states?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 8 requires an essential or important entity, other than a security authority, to submit an initial report to RIA (Riigi Infosüsteemi Amet, the Estonian Information System Authority) without delay and no later than 24 hours after becoming aware of a cyber incident with a significant effect on system security or service continuity, or one whose significant effect is not obvious but can reasonably be expected.
Section 8(2) defines 'significant effect' by six alternative conditions: the incident rates at least severe under the entity's own Section 7 risk analysis; it prevents continuing the service beyond the maximum permitted outage in a service-level agreement or continuity requirement; it disrupts another service provider's continuity; resolving it requires extraordinary measures identified in the risk analysis or continuity documentation; it has caused or risks significant damage to the entity, another provider or the service's users; or it is significant under a European Commission implementing act adopted under Directive (EU) 2022/2555 Article 23(11).
Section 8(3) makes an incident always significant where it also disrupts the service in at least one other EU member state. Section 8, subsection 4-1, requires an incident report no later than 72 hours after becoming aware of the significant incident, updating the initial report, except a qualified trust service provider, which instead reports within 24 hours in a single stage under Section 8, subsection 4-2. Section 8, subsection 4-3, requires an interim report on RIA's request.
Section 8(7) requires a final report within one month of the incident report, treated as interim and followed by a further final report within one month of resolution if the incident remains unresolved at that point. Section 8(5) requires the entity to notify, within a reasonable time, a person whom the significant incident or a significant cyber threat may affect, or the public where affected persons cannot be individually notified.
Section 8(6) lets RIA itself inform the public after consulting the entity, or require the entity to, where public awareness serves prevention, resolution of the incident, or the public interest generally. Section 8-1 lets a service provider, or any other person, voluntarily notify RIA of a cyber incident, security vulnerability or cyber threat below the mandatory threshold, including a vulnerability report submitted anonymously, processed under the same Sections 8 and 12 procedure.
Section 5(3) designates RIA as the competent authority and single point of contact under Directive (EU) 2022/2555 Article 8, the authority for large-scale incidents and crises under Article 9, the national CSIRT under Article 10, the coordinated-vulnerability-disclosure coordinator under Article 12, and Estonia's participant in the CSIRTs network under Article 15. All these duties entered into force on 1 January 2026 as part of Estonia's NIS2 transposition.
When LexLint raises it
operates_social_platform
Read the law
Consolidated text
Riigi Teataja I, Küberturvalisuse seadus (KüTS), wording valid 1 January 2026 to 30 September 2026, carrying the amendments of RT I, 30.12.2025, 4 (Küberturvalisuse seaduse ja teiste seaduste muutmise seadus, in force 1 January 2026)