Grant for improving cybersecurity (NIS2)
We help organisations meet the NIS2 requirements and strengthen their cybersecurity
The grant is intended for businesses and organisations that are now subject to new cybersecurity requirements following an amendment to the Cybersecurity Act (in Estonian)
Applicants for the grant must belong to the target group for the grant and be registered with the Information System Authority.
The grant is awarded in two application rounds:
Call for applications for the grant for drawing up a cybersecurity roadmap
Call for applications for the grant for cybersecurity development and auditing
In both application rounds, grant applications may be submitted on an ongoing basis until the budget has been exhausted.
This is a support measure introduced by the Ministry of Justice and Digital Affairs, aimed at alleviating the financial costs associated with the transposition of the directive.
Who is the grant intended for?
Funding may be applied for by a legal person who is, within the meaning of the Cybersecurity Act:
- a service provider
- a domain name registration service provider
- and has fulfilled the obligation set out in section 41 of the Cybersecurity Act
If your organisation submitted a notification to the Estonian Information System Authority under Section 4¹ of the Cybersecurity Act after 1 January 2026, you are likely eligible for this support measure, provided that your organisation was not required to comply with the Act before that date.
What qualifies for the grant?
Funding is provided for three main activities:
- drawing up a roadmap for improving cybersecurity
- implementing development activities in accordance with the roadmap (including the development of the organisation and its processes to enhance the level of cybersecurity, drafting and implementing terms of reference for roadmap-based development activities, and procuring consultancy and technical expertise relating to ensuring cybersecurity)
- auditing of roadmap-based development activities
The application round is intended for organisations that do not have a cybersecurity roadmap.
During the creation of the roadmap, business requirements and statutory requirements for cybersecurity are identified, a set of security measures compliant with these requirements is put together, an assessment of the organisation’s current cybersecurity status is carried out, and the actions required to improve cybersecurity are identified.
Please note! You can receive the grant for preparing a roadmap only once.
This application round is intended for organisations that have a cybersecurity roadmap that corresponds to the methodology (in Estonian).
The grant can be used to implement the development activities set out in the roadmap and to audit the results of those activities.
Funding for development activities and auditing may be applied for either in a single application or in separate, consecutive applications.
Please note! You cannot apply for the grant for development and auditing while drawing up the roadmap.
How large is the grant and what is the grant rate?
- The grant for drawing up a roadmap is 5,000 euros per project – grant rate 100%
- Implementation of development activities based on the roadmap: €10,000–100,000 per project – grant rate 50%
- Auditing of development activities based on a roadmap, up to 20,000 euros per project – grant rate 50%
When awarding the grant, account is taken of any outstanding de minimis aid granted to the organisation over the last three years.
The grant can only be applied for if the organisation has a remaining balance within the relevant de minimis aid ceiling. The de minimis aid balance is calculated on a group basis.
Check your organisation’s de minimis aid balance
What will change in my organisation?
Cybersecurity will improve
Preparedness for cyber threats will increase
Services and systems will operate more reliably
Assistance for applicant
For quick communication, you can find the chatbot in the bottom right corner of the page.
Customer Service
+372 627 9700
[email protected]
Read more about the terms and conditions of the grant in the grant regulation:
Grant regulation(in Estonian)
Methodology for the Roadmap for Increasing Cybersecurity (in Estonian)
Sample cybersecurity roadmap (in Estonian)
Read more about applying grant in Estonian here
The application can be compiled and submitted in the online E-toetus environment.
Please select the correct call for applications:
Call for applications for the grant for drawing up a cybersecurity roadmap
Call for applications for the grant for cybersecurity development and auditing
Grant can be applied only in Estonian language.