| Dokumendiregister | Riigi Infosüsteemi Amet |
| Viit | 1.1-21/262019 |
| Registreeritud | 20.01.2026 |
| Sünkroonitud | 21.01.2026 |
| Liik | Väljaminev kiri |
| Funktsioon | 1.1 Asutuse tegevuse korraldamine |
| Sari | 1.1-21 Õigusalane kirjavahetus ja muu dokumentatsioon |
| Toimik | 1.1-21/2025 |
| Juurdepääsupiirang | Avalik |
| Juurdepääsupiirang | |
| Adressaat | SupportHost OÜ |
| Saabumis/saatmisviis | SupportHost OÜ |
| Vastutaja | Sander Pelisaar (RIA, PDA Oigus) |
| Originaal | Ava uues aknas |
Dear Mr. Messina,
Thank you for your enquiry. I apologize for the delay in responding.
Best regards,
Sander Pelisaar
Legal Adviser
+372 5366 7126
Information System Authority of Estonia
Legal Department
Pärnu maantee 139a, Tallinn 15169
Saatja: Ivan - SupportHost <[email protected]>
Saatmisaeg: reede, 16. jaanuar 2026 00:38
Adressaat: Riigi Infosüsteemi Amet <[email protected]>
Koopia: cert üld <[email protected]>
Teema: NIS2 Directive Applicability Query - Estonian Hosting Company (SupportHost OÜ)
[email protected] ei saada teile sageli meilisõnumeid. Lugege teavet selle kohta, miks see on oluline |
E-kiri saadeti väljastpoolt RIA-t. Kui Sa ei tunne saatjat, siis ära ava linke ega manuseid!
Dear RIA Cybersecurity Team,
I am writing to seek official clarification regarding the applicability of the NIS2 Directive requirements to our Estonian company under the recently amended Cybersecurity Act.
Company Information:
Business Activities: We provide web hosting services (shared hosting) and domain registration services to approximately 6,000 clients across various sectors (small businesses, professionals, agencies, e-commerce). Our servers are physically located in Germany and the Netherlands.
Current Compliance Status: We obtained ISO/IEC 27001 certification approximately one month ago (November 2024).
Questions:
Based on the recent amendments to the Cybersecurity Act (particularly the September 2025 regulation establishing thresholds of 50 employees and €10 million revenue for E-ITS exemption), I would appreciate your clarification on the following points:
Background for Question: We want to ensure full compliance with Estonian cybersecurity regulations and provide accurate information to our clients. Additionally, as we plan to grow our business toward €300K monthly revenue in the next few years, we want to understand at what point we would become subject to NIS2 requirements.
Could you please provide written confirmation of our obligations (or exemption) under the current Estonian implementation of the NIS2 Directive? This will help us plan our compliance strategy appropriately.
I am available for any follow-up questions or to provide additional information if needed.
Thank you for your assistance.
Best regards,
Ivan Messina
Founder & Owner SupportHost OÜ
Registry Code: 16285499
Email: [email protected]
| Nimi | K.p. | Δ | Viit | Tüüp | Org | Osapooled |
|---|