EstoniaRiigi Teataja
Estonia replaces its information-security standard from 1 September
The new regulation preserves compatible existing security measures and allows pre-existing compliance documentation to remain valid for up to three years.
By Taxxa AI OyPublished 1 September 2026
Estonia’s new Eesti infoturbestandard regulation takes effect on 1 September 2026Riigiteataja, replacing the 2022 regulation of the same name
Riigiteataja. For organisations required to apply the standard, it sets out management, risk assessment, documentation and audit requirements, alongside transitional rules for measures and documents already in place.
The transition treats security measures and documentation separately. Measures implemented before the new regulation took effect remain valid until their implementation ends or they are updated, provided they do not conflict with the new regulationRiigiteataja. Documentation prepared beforehand to comply with the standard remains valid for up to three years from entry into force
Riigiteataja. If that documentation is updated under the prescribed procedure before the period expires, its validity follows that procedure.
The organisation’s management board is responsible for organising the information-security management system. It must allocate responsibilities and resources, establish the security policy and decide whether to accept risks arising from planned measures that are left unimplemented, taking their possible impact on business processes into account. The arrangements must give the board regular and timely information about risks, incidents, applicable requirements and progress on the security-measures plan.
The security policy must be reviewed, and amended where necessary, at least once each calendar year. The implementation plan must reflect the organisation’s security needs and risk assessment. Where a measure’s implementation deadline exceeds one year, that must be treated in risk management as an accepted risk. Dependencies on external supply chains also require assessment, with alternative measures or a change of external party considered where a risk cannot be accepted for information-security reasons.
For audit preparation, organisations must address deficiencies identified through internal assessment and accept risks resulting from unimplemented security measures by the start of the audit. Independent external audit evaluates whether the management system and measures meet the regulation’s requirements and protect the organisation’s business processes and objectives.
Organisations should first confirm their scope: this regulation points to Chapter 2 of Government Regulation No 121 for the obligation and extent of application. These requirements and transitional arrangements are set out in Regulation No 30 of 25 August 2026, “Eesti infoturbestandard”.
Review existing security measures and documentation against the new standard before planning the next audit.