Eesti infoturbestandard — Estonian Information Security Standard
NIS2 says what you must achieve, never how you demonstrate it. Estonia answers with E-ITS. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
E-ITS conformity is a means of meeting the security obligations, not a discharge of every NIS2 duty: registration, governance and incident notification obligations stand on their own. Verify which version of the standard the supervisor currently expects before scoping an assessment.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is explicitly recognised as equivalent, which makes Estonia unusually straightforward for an internationally certified group.
What it is built on
E-ITS does not invent its own taxonomy. It sits on The Estonian national information security standard, developed from IT-Grundschutz methodology.
E-ITS is a full national information security standard rather than a graded assurance scheme. What makes it matter for NIS2 is its legal status: conformity with E-ITS — or with ISO/IEC 27001 as its recognised equivalent — is accepted as a means of meeting the security obligations. That puts Estonia in the small group of member states where the route to compliance is named in law rather than left to the market.
How it covers article 21(2)
Estonian law accepts conformity with E-ITS or with ISO/IEC 27001 as its recognised equivalent as a means of meeting the security obligations. The mapping is therefore the ISO/IEC 27001:2022 mapping, resolved from that framework rather than restated here.
This maps the ISO equivalent, not E-ITS module identifiers, which are not published as a stable public set. Where you are assessed against E-ITS itself, use this to scope and then reconcile against the standard in force.
| Art. 21(2) | Measure | E-ITS — ISO/IEC 27001:2022 Annex A control |
|---|---|---|
| (a) | Risk analysis and security policies | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 |
| (b) | Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 |
| (c) | Business continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 |
| (d) | Supply chain security | 5.19 5.20 5.21 5.22 5.23 |
| (e) | Security in acquisition, development and maintenance | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 |
| (f) | Assessing the effectiveness of the measures | 5.33 5.35 5.36 8.16 |
| (g) | Basic cyber hygiene and cybersecurity training | 5.37 6.3 8.7 |
| (h) | Cryptography and encryption | 8.24 |
| (i) | Human resources security, access control and asset management | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 |
| (j) | Multi-factor authentication and secured communications | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 |
What you already have, for the same measure
Nobody in scope starts from nothing. E-ITS is what your supervisor reads; NIST 800-53 is what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
ISO 27001 is not repeated here: E-ITS publishes no identifiers of its own and its mapping above is the ISO 27001 one. Showing it twice would make a duplication look like independent confirmation.
| Art. 21(2) | E-ITS | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) Risk analysis | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | 8.24 | SC |
| (i) HR, access, assets | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
We are not affiliated with Riigi Infosüsteemi Amet (RIA) — Information System Authority. E-ITS and related marks belong to their owners.