12) the producer or provider of maintenance or support services is not able to secure continued deliveries of
products or services, except due to force majeure.
(4) To ensure national security, a communications undertaking is obliged to notify the Consumer Protection and
Technical Regulatory Authority of the hardware and software used in the communications network.
(5) The extent of the notification obligation specified in subsection 4 of this section as well as the specific
requirements, the term for compliance with the obligation and the procedure for notification is established by a
regulation of the Government of the Republic.
(6) To ensure national security, a communications undertaking is obliged to apply for an authorisation for use of
hardware or software of a communications network (hereinafter authorisation for use of hardware or software)
from the Consumer Protection and Technical Regulatory Authority.
(7) The extent of the obligation to apply for an authorisation for use of hardware or software, the specific
requirements, the term and procedure of the proceedings and the specifications concerning the term of the
authorisation for use are established by a regulation of the Government of the Republic.
(8) Upon issuing the regulations specified in subsections 5 and 7 of this Act the Government of the Republic
takes account of the significance of the communications network, its hardware or software and communications
services provided in the network as well as the potential risks arising therefrom to the national security.
[RT I, 15.12.2021, 1 – entry into force 01.02.2022]
§ 874. Proceedings of authorisation for use of hardware or software
(1) Upon receipt of an application for the authorisation for use of hardware or software, the Consumer
Protection and Technical Regulatory Authority asks for opinions of security authorities and the Information
System Authority on whether the hardware or software specified in the application of the communications
undertaking for the authorisation for use of hardware or software poses a risk to national security. If the
hardware or software may pose a risk to national security according to the received opinion, the Consumer
Protection and Technical Regulatory Authority asks for an approval from the authority specified in the statutes
of the Security Committee of the Republic of Estonia (hereinafter administrative authority) before resolving the
application of the communications undertaking for the authorisation for use of the hardware or software.
(2) In the approval process specified in subsection 1 of this section the administrative authority assesses
whether the use of the hardware or software specified in the application for the authorisation for use of the
hardware or software poses a risk to national security. In the approval process the administrative authority
may propose to prohibit the use of the hardware or software specified in the application for the authorisation
for use of hardware or software or to establish conditions on their use. The conditions for use of hardware or
software may include, among other things, a time limit for use, use in certain parts or functions or with certain
configuration of the communications network.
(3) Considering the provisions of subsections 1 and 2 of this section, the Consumer Protection and Technical
Regulatory Authority decides on the approval, conditional approval or refusal to approve the application for the
authorisation for use of hardware or software.
(4) Where hardware or software does not pose a risk to national security, an authorisation for use is granted for
eight years. Where hardware or software poses a risk to national security, no authorisation for use is granted or a
conditional authorisation for use is granted.
[RT I, 15.12.2021, 1 – entry into force 01.02.2022]
§ 875. Auditing
(1) A communications undertaking on whom obligations have been imposed on the basis of § 873of this Act
orders a compliance audit about its activities at least every three years after the imposition of the obligation, for
assessment in the audit report whether the communications undertaking has performed the obligations imposed
on the basis of the same section.
(2) The person conducting the audit must be an independent auditor who holds a certified information systems
auditor certificate from ISACA or a similar certificate.
(3) The person conducting the audit submits the audit to the Consumer Protection and Technical Regulatory
Authority.
(4) The costs of conducting the audit are covered by the communications undertaking.
Electronic Communications Act
Page 51 / 89