12) the producer or provider of maintenance or support services is not able to secure continued deliveries of products or services, except due to force majeure. (4) To ensure national security, a communications undertaking is obliged to notify the Consumer Protection and Technical Regulatory Authority of the hardware and software used in the communications network. (5) The extent of the notification obligation specified in subsection 4 of this section as well as the specific requirements, the term for compliance with the obligation and the procedure for notification is established by a regulation of the Government of the Republic. (6) To ensure national security, a communications undertaking is obliged to apply for an authorisation for use of hardware or software of a communications network (hereinafter authorisation for use of hardware or software) from the Consumer Protection and Technical Regulatory Authority. (7) The extent of the obligation to apply for an authorisation for use of hardware or software, the specific requirements, the term and procedure of the proceedings and the specifications concerning the term of the authorisation for use are established by a regulation of the Government of the Republic. (8) Upon issuing the regulations specified in subsections 5 and 7 of this Act the Government of the Republic takes account of the significance of the communications network, its hardware or software and communications services provided in the network as well as the potential risks arising therefrom to the national security. [RT I, 15.12.2021, 1 – entry into force 01.02.2022] § 874. Proceedings of authorisation for use of hardware or software (1) Upon receipt of an application for the authorisation for use of hardware or software, the Consumer Protection and Technical Regulatory Authority asks for opinions of security authorities and the Information System Authority on whether the hardware or software specified in the application of the communications undertaking for the authorisation for use of hardware or software poses a risk to national security. If the hardware or software may pose a risk to national security according to the received opinion, the Consumer Protection and Technical Regulatory Authority asks for an approval from the authority specified in the statutes of the Security Committee of the Republic of Estonia (hereinafter administrative authority) before resolving the application of the communications undertaking for the authorisation for use of the hardware or software. (2) In the approval process specified in subsection 1 of this section the administrative authority assesses whether the use of the hardware or software specified in the application for the authorisation for use of the hardware or software poses a risk to national security. In the approval process the administrative authority may propose to prohibit the use of the hardware or software specified in the application for the authorisation for use of hardware or software or to establish conditions on their use. The conditions for use of hardware or software may include, among other things, a time limit for use, use in certain parts or functions or with certain configuration of the communications network. (3) Considering the provisions of subsections 1 and 2 of this section, the Consumer Protection and Technical Regulatory Authority decides on the approval, conditional approval or refusal to approve the application for the authorisation for use of hardware or software. (4) Where hardware or software does not pose a risk to national security, an authorisation for use is granted for eight years. Where hardware or software poses a risk to national security, no authorisation for use is granted or a conditional authorisation for use is granted. [RT I, 15.12.2021, 1 – entry into force 01.02.2022] § 875. Auditing (1) A communications undertaking on whom obligations have been imposed on the basis of § 873of this Act orders a compliance audit about its activities at least every three years after the imposition of the obligation, for assessment in the audit report whether the communications undertaking has performed the obligations imposed on the basis of the same section. (2) The person conducting the audit must be an independent auditor who holds a certified information systems auditor certificate from ISACA or a similar certificate. (3) The person conducting the audit submits the audit to the Consumer Protection and Technical Regulatory Authority. (4) The costs of conducting the audit are covered by the communications undertaking. Electronic Communications Act Page 51 / 89

Select target paragraph3