Skip to main content

Grant for improving cybersecurity (NIS2)

We help organisations meet the NIS2 requirements and strengthen their cybersecurity

The grant is intended for businesses and organisations that are now subject to new cybersecurity requirements following an amendment to the Cybersecurity Act (in Estonian)
Applicants for the grant must belong to the target group for the grant and be registered with the Information System Authority.

The grant is awarded in two application rounds:
Call for applications for the grant for drawing up a cybersecurity roadmap
Call for applications for the grant for cybersecurity development and auditing
In both application rounds, grant applications may be submitted on an ongoing basis until the budget has been exhausted.

This is a support measure introduced by the Ministry of Justice and Digital Affairs, aimed at alleviating the financial costs associated with the transposition of the directive.

Maximum grant
120 000
Self-financing
50%
Total grant amount
2 640 000
Status
Open

Who is the grant intended for?

Funding may be applied for by a legal person who is, within the meaning of the Cybersecurity Act:

  • a service provider
  • a domain name registration service provider
  • and has fulfilled the obligation set out in section 41 of the Cybersecurity Act

If your organisation submitted a notification to the Estonian Information System Authority under Section 4¹ of the Cybersecurity Act after 1 January 2026, you are likely eligible for this support measure, provided that your organisation was not required to comply with the Act before that date.

What qualifies for the grant?

Funding is provided for three main activities:

  • drawing up a roadmap for improving cybersecurity
  • implementing development activities in accordance with the roadmap (including the development of the organisation and its processes to enhance the level of cybersecurity, drafting and implementing terms of reference for roadmap-based development activities, and procuring consultancy and technical expertise relating to ensuring cybersecurity)
  • auditing of roadmap-based development activities

What kinds of costs are supported by the grant?

The application round is intended for organisations that do not have a cybersecurity roadmap.

During the creation of the roadmap, business requirements and statutory requirements for cybersecurity are identified, a set of security measures compliant with these requirements is put together, an assessment of the organisation’s current cybersecurity status is carried out, and the actions required to improve cybersecurity are identified.

Please note! You can receive the grant for preparing a roadmap only once.

This application round is intended for organisations that have a cybersecurity roadmap that corresponds to the methodology (in Estonian).

The grant can be used to implement the development activities set out in the roadmap and to audit the results of those activities.
Funding for development activities and auditing may be applied for either in a single application or in separate, consecutive applications.

Please note! You cannot apply for the grant for development and auditing while drawing up the roadmap.

How large is the grant and what is the grant rate?

  • The grant for drawing up a roadmap is 5,000 euros per project – grant rate 100%
  • Implementation of development activities based on the roadmap: €10,000–100,000 per project – grant rate 50%
  • Auditing of development activities based on a roadmap, up to 20,000 euros per project – grant rate 50%

When awarding the grant, account is taken of any outstanding de minimis aid granted to the organisation over the last three years.
The grant can only be applied for if the organisation has a remaining balance within the relevant de minimis aid ceiling. The de minimis aid balance is calculated on a group basis.
Check your organisation’s de minimis aid balance

What will change in my organisation?

Cybersecurity will improve

Preparedness for cyber threats will increase

Services and systems will operate more reliably

Assistance for applicant

For quick communication, you can find the chatbot in the bottom right corner of the page.

Customer Service
+372 627 9700
[email protected]

Read more about the terms and conditions of the grant in the grant regulation:

Grant regulation(in Estonian)

Methodology for the Roadmap for Increasing Cybersecurity (in Estonian)

Sample cybersecurity roadmap (in Estonian)

Read more about applying grant in Estonian here

The application can be compiled and submitted in the online E-toetus environment.
Please select the correct call for applications:
Call for applications for the grant for drawing up a cybersecurity roadmap
Call for applications for the grant for cybersecurity development and auditing

Grant can be applied only in Estonian language.

All articles
Cybernetica enters third phase of ESA’s Minerva project with on-board spacecraft cybersecurity module

Cybernetica has begun the third phase of the Minerva project in partnership with the European Space Agency (ESA). Building on more than five years of collaborative research, this phase marks a pivotal transition: from ground-based machine learning exploration to a deployable, real-time cybersecurity system embedded directly into spacecraft. The Minerva Dynamic Threat Detection System is a dedicated cybersecurity module designed to sit at the critical security boundary between a spacecraft’s communication system and its on-board computer (OBC). The project runs under ESA’s General Support Technology Programme (GSTP) and is active until 2029. From research to hardware Cybernetica’s partnership with ESA

All articles
Ireland’s EU Presidency: Shaping Europe’s Competitiveness, Innovation and Investment

As Brussels prepares for the summer break, work across the European Union institutions continues at full speed. Decisions currently being shaped will influence Europe’s business, industrial and innovation landscape for years to come. Since 1 July 2026, Ireland has held the Presidency of the Council of the European Union. Over the next six months, Ireland will steer discussions on several strategic priorities that are highly relevant for Estonian businesses, including strengthening Europe’s competitiveness, accelerating innovation, increasing investment, developing the defence industry, and preparing the EU’s next long-term budget. Although each Presidency lasts only six months, it often sets the political

Estonia ranks 11th in the European Innovation Scoreboard 2026
All articles
Estonia ranks 11th in the European Innovation Scoreboard 2026

Estonia ranked 11th among EU member states in the newly released 2026 European Innovation Scoreboard and kept its place in the Strong Innovator group, with a summary innovation index equal to 108.6% of the EU average. In its press release, the European Commission said the EU’s overall innovation performance has risen by 11.6 percentage points since 2019 and by 1.7 points over the past year. For Estonia, the new country profile shows a system that continues to outperform the EU average, while still sitting slightly below the Strong Innovator group average of 113.9%. Estonia also ranked 15th across the EU and neighbouring countries covered by

All articles
INTERVIEW | Kristel Oitmaa now leads EIS’s Brussels office. How does she help Estonian companies make better use of European opportunities?

Kristel Oitmaa, the new head of Enterprise Estonia’s (EIS) Brussels office, helps Estonian companies better understand and use opportunities related to EU research and development — whether it is funding, strategic information, international cooperation, or access to key networks. In this interview, Kristel explains what the Brussels office actually does, what her role involves, and what Estonian companies can do to become more visible at the European level. While EIS export advisors focus on market entry, Kristel supports Estonian companies in navigating the European strategic landscape. She helps them use European opportunities in a more informed and effective way, ensuring

All articles
Startup Estonia takes Estonian deep tech startups to Singapore

This October, Estonian deep tech startups will head to Singapore as part of Startup Estonia’s Nordic Deep Tech Valley program to take part in the Nordic Singapore Innovation Days 2025 — a joint initiative with Finland and Sweden. According to Kati Pärn, Nordic Partnerships Lead at Startup Estonia, the event will connect Nordic startups with Singaporean corporations and investors to foster business opportunities and partnerships in green and sustainable innovation. “Our aim is to provide Estonian startups operating in the complex and highly competitive deep tech sector with a concrete opportunity to secure new investors, partners, and clients in Asian