NIS2 Directive (EU) 2022/2555 · Estonian Cybersecurity Act
Are you in scope of NIS2, and how far are you from compliance?
A 10-minute scope check and gap assessment against the ten minimum measures of Art. 21, incident reporting under Art. 23 and management accountability under Art. 20. Written for Estonia's Cybersecurity Act (KüTS), usable across the EU.
Why now
The law already applies
Estonia's amended Cybersecurity Act has applied since 1 January 2026. Entities in scope had to register with RIA by 1 April 2026, and incident reporting obligations run now.
Management is accountable
Boards must approve and oversee the measures and follow training, and can be held liable. Maximum fines reach at least €10M or 2% of worldwide turnover for essential entities.
Out of scope? Your customers aren't
In-scope organisations must manage their suppliers' security, so the requirements arrive anyway as questionnaires and contract clauses.
What subscribers get
Editable Word documents generated from your answers, regenerated whenever you reassess.
00
Gap assessment report
Likely classification (essential, important, supplier), a score per measure, every gap with its article and a roadmap.
01
Information security policy
Covers all ten Art. 21(2) measures, mapped to the other documents, ready for board approval.
02
Board resolution and briefing
The Art. 20 approval, the responsible board member (KüTS § 6¹) and a 90-minute training briefing.
03
Risk assessment register
Method plus pre-filled threats that match your answers.
04
Incident response and reporting
Significance test, 24h/72h/1-month report templates, contacts, incident log and a tabletop exercise.
05
Business continuity and backup plan
Recovery targets, 3-2-1 backup standard, restore testing and crisis management.
06
Supplier security kit
Policy, supplier register, assessment questions and model contract clauses including 24-hour incident notification.
07
Access, asset and people policy
Asset inventory, least privilege, MFA rollout, joiner-mover-leaver checklist.
08
Technical security policy
Patch deadlines, hardening, secure development, vulnerability disclosure, cryptography and logging.
09
Customer security statement
A one-page answer to customers' NIS2 supplier questionnaires that only claims what you actually have.
Questions
+How do I know if NIS2 applies to me?
Broadly: medium or large organisations (50+ staff, or turnover and balance sheet above €10M) in the sectors listed in Annexes I and II, plus some entities regardless of size (DNS, trust services, telecoms, public administration) and, in Estonia, some public bodies. The assessment starts with this check.
+Is this an audit or a certification?
No. It is a structured self-assessment with templates generated from your answers. It gets you to a documented, defensible position quickly. For an independent audit, E-ITS or ISO 27001 work, or a penetration test, Parendum offers those separately.
+Does it cover E-ITS?
The documents reference the Estonian information security standard where relevant and are structured so they can support an E-ITS or ISO/IEC 27001 implementation, but they are not a replacement for the E-ITS catalogue.
+We are outside Estonia. Is it still useful?
Yes. The kit follows the Directive; Estonia-specific points are marked. Check your national authority, portal and reporting forms.
+Who can subscribe?
Businesses. EU buyers outside Estonia need a valid VAT number (checked in VIES) and are invoiced under reverse charge; Estonian buyers pay 24% VAT.