(21) Upon assessing the impact of a cyber incident, a communications undertaking takes into account in
particular the following, where such information is available:
1) the estimated number of users affected by the cyber incident;
2) the duration of the cyber incident;
3) the geographical spread of the area affected by the cyber incident;
4) the extent to which the functioning of the networks and services are affected;
5) the extent of impact on economic and societal activities.
[RT I, 15.12.2021, 1 – entry into force 01.02.2022]
(3) If necessary, the Information System Authority reports the cyber incidents specified in subsection 2 of this
section to foreign supervision authorities and the European Network and Information Security Agency (ENISA).
If the Information System Authority finds that due to public interest it is justified to make the violation public, it
may inform the public thereof or require the communications undertaking to do it.
[RT I, 15.12.2021, 1 – entry into force 01.02.2022]
(4) The Estonian Information System Authority shall submit a summary report on the notices submitted
pursuant to subsection 2 of this section and on measures applied to the European Commission and ENISA once
per calendar year.
[RT I, 13.03.2014, 4 – entry into force 01.07.2014]
(5) The Estonian Information System Authority is entitled to require a communications undertaking to:
[RT I, 13.03.2014, 4 – entry into force 01.07.2014]
1) provide information needed to assess the security and integrity of their communications services and
networks, including security policies;
2) order a security audit carried out by a qualified independent body or a competent national authority and
make the results thereof available to the Estonian Information System Authority. The cost of the audit shall be
covered by the communications undertaking.
[RT I, 13.03.2014, 4 – entry into force 01.07.2014]
(6) Instead of the requirements provided in subsections 1–5 of this section, the requirements provided in and
established on the basis of §§ 7 and 8 of the Cybersecurity Act apply to the communications undertakings
providing vital services, cable distribution services consumed by no less than 10,000 end-users, or broadcasting
network services.
[RT I, 22.05.2018, 1 – entry into force 23.05.2018]
§ 873. Requirements for communications networks and services to ensure national security
(1) The hardware and software used in provision of communications services in a communications network
must not pose a risk to national security.
(2) The hardware and software used in provision of communications services in a communications network
may pose a risk to national security due to:
1) a high risk arising from its producer or provider of maintenance or support services (hereinafter high risk
hardware or software);
2) a risk arising from the technical characteristics or configuration of the hardware or software.
(3) Upon assessing high risk hardware or software, account is taken, among other things, of information on
whether:
1) the producer or provider of maintenance or support services has its registered office or head office
in a country (hereinafter country of domicile), which is not a member state of the European Union, the
North Atlantic Treaty Organisation (hereinafter NATO) or the Organisation for Economic Co-operation and
Development (hereinafter OECD);
2) the principles of democratic rule of law are not observed or human rights are not respected in the country of
domicile of the producer or provider of maintenance or support services;
3) the intellectual property, personal data or business secrets of persons of other countries are not protected in
the country of domicile of the producer or provider of maintenance or support services;
4) the country of domicile of the producer or provider of maintenance or support services exhibits aggressive
behaviour in cyberspace;
5) the member states of the European Union, NATO or OECD have attributed cyber-attacks to the country of
domicile of the producer or provider of maintenance or support services;
6) the producer or provider of maintenance or support services is subjected to the government or state authority
of the country of domicile or other foreign country that has no independent judicial control;
7) the country of domicile of the producer or provider of maintenance or support services or another foreign
country may oblige it to act in a manner posing a risk to the national security of Estonia;
8) the economic activities of the producer or provider of maintenance or support services are not based on
market-based competition or no adequate conditions have been created for this in the country of domicile;
9) the ownership structure, organisational structure or management structure of the producer or provider of
maintenance or support services is not transparent;
10) financing of the producer or provider of maintenance or support services is not transparent;
11) the products or services of the producer or provider of maintenance or support services include
vulnerabilities and no adequate security measures have been implemented to eliminate these;
Page 50 / 89
Electronic Communications Act