TaxxaCompany Logo

Menu

Company

About usCareersBlogContact usLinkedInYouTube

Product

FeaturesPricingFAQ

Legal

Cookie PolicyData Processing AgreementPrivacy PolicyTerms and Conditions
© 2026 Taxxa AI Oy. All rights reserved.
  1. News
  2. /Estonia
  3. /IT, Cybersecurity & Data

Estonia·Finantsinspektsioon

Estonia adopts TIBER-EE framework for threat-led penetration tests

Finantsinspektsioon's recommended TIBER-EE guide in force since 15 September 2026 sets the national playbook for DORA threat-led penetration testing, with voluntary use subject to prior coordination.

By Taxxa AI Oy · Published 24 September 2026

IT, Cybersecurity & Data

Finantsinspektsioon has issued a recommended guide, the TIBER-EE national implementation documentFI, which sets how the European threat intelligence-based ethical red-teaming framework (TIBER-EU) is applied in EstoniaFI. The guide was established by the Finantsinspektsioon board decision no. 1.1-7/143 of 15 September 2026FI and entered into force the same dayFI; the framework itself had been adopted for the Estonian financial sector by a board decision of 5 May 2025. It is published in Estonian and English alongside the board decision.

The guide explains the use of TIBER-EE for threat-led penetration testing (TLPT) under Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). Under DORA Article 26, financial entities identified by the competent authority must periodically carry out TLPT; in Estonia Finantsinspektsioon is the competent authority for the entities under its supervisionFI and acts as the TLPT authority for themFI, issuing an attestation when a test is completed in line with the applicable requirementsFI. Finantsinspektsioon does not take part in the operational conduct of a testFI: the tested entity carries it out together with its appointed providersFI, while the authority supervises, assures quality and coordinates cross-border, joint or pooled testsFI under the TLPT regulatory technical standards (Commission Delegated Regulation (EU) 2025/1190).

The guide is addressed to entities Finantsinspektsioon has identified as TLPT-obliged by supervisory decisionFI, to other Estonian financial entities wishing to run a TIBER-EE test voluntarilyFI, and to the third-party providers and others involvedFI. Obliged entities use TIBER-EE as the national framework for these testsFI; others may use it voluntarily provided this is coordinated with Finantsinspektsioon beforehandFI. Tests by significant credit institutions under direct European Central Bank supervision stay with the ECB as the TLPT authority under its TIBER-EU SSM implementation guide, which also issues their attestations; where the ECB assigns the Estonian cyber team a supervisory role in such a test, it acts under that guide.

National arrangements include a dedicated TLPT cyber team (TCT-EE) inside Finantsinspektsioon's IT supervision department for day-to-day programme managementFI, an optional generic threat landscape (GTL) input that does not replace the per-test threat-intelligence requirement, confidentiality and information-security rules including secure channels and need-to-know handling, and cooperation with the Information System Authority (RIA) on threat intelligence and technical expertise. The guide is recommendatory rather than lawFI and is applied on a comply-or-explain basisFI: an entity must be able to justify not applying a pointFI, while departures that break mandatory requirements can affect the attestationFI.

Legal basis: Finantsinspektsiooni seadus § 57 lõike 1 ja lõike 3, Finantsinspektsiooni juhatuse 15.09.2026 otsus nr 1.1-7/143FI, Regulation (EU) 2022/2554 (DORA) artikkel 26, and Commission Delegated Regulation (EU) 2025/1190 on TLPT.

Entities identified as TLPT-obliged should run their tests under the TIBER-EE national framework; others wishing to use TIBER-EE voluntarily should coordinate with Finantsinspektsioon (TLPT@fi.ee) first.

Sources

  1. TIBER-EE riiklik rakendusjuhend
  2. Finantsinspektsiooni soovitusliku juhendi „TIBER-EE riiklik rakendusjuhend“ välja andmine

Share with your network

More on this

  1. 1 Sept 2026

    Estonia replaces its information-security standard from 1 September

  2. 24 Sept 2026

    ATA carnets go electronic: pre-register trips and show QR codes at customs

  3. 23 Sept 2026

    Strong-alcohol stamp data moves from ALKOR into a company-run MAIS register

  4. 22 Sept 2026

    Split gift spirits keep duty-free status for one bottle

  5. 21 Sept 2026

    Crypto-asset CARF and DAC8 declaration forms enacted

Estonia news