top of page

Estonia, the first e-state?

  • cesricontact
  • Aug 5
  • 15 min read

Digital technology as a lever of soft power and international influence


In just over three decades, Estonia has transformed its digital transformation into much more than mere administrative restructuring. The image of " e-Estonia ," a global benchmark in e-government, digital identity, and cybersecurity, has become a tool for diplomacy, economic attractiveness, and international visibility. The Estonian case highlights how a small nation has been able to convert its technological expertise into a tool of soft power and influence beyond its borders.

 

Highlighted by the American international relations theorist Joseph Nye in 1990 through his book " Bound to Lead [1] ", soft power [2] refers to the " ability to influence others through attraction and persuasion rather than coercion and purchase [3] ".


At first glance, Estonia might seem to have fewer cultural assets immediately identifiable to the general public than the major powers traditionally associated with soft power . However, its heritage, exemplified by the medieval Old Town of Tallinn and the international success of composer Arvo Pärt, contributes to its appeal [4] . As Leonid Karabeshkin and Raili Rusetski point out in their 2013 publication " Estonia's Soft Power " in the journal " Baltic Horizons ," these elements contribute to the country's influence [5] .


Furthermore, according to the authors, Estonian soft power also rests on the country's adherence to Western values of democracy and economic liberalism. [6] , but also on its commitment to environmental policies , such as the national strategy for sustainable development " Sustainable Estonia 21 " adopted by the country in 2005 [7] .


However, the main marker of its international identity now seems to lie elsewhere: in the image of a modern, innovative state that is almost entirely accessible online. Digital technology has thus become a powerful positioning tool for Tallinn. It attracts entrepreneurs, fosters a recognizable national brand , and offers Estonia a strategic place in international debates on digital governance and cybersecurity.

 

Beyond the qualification of "first e-state", the attribution of which would require a broader comparative analysis, the aim here is in particular to analyze how Estonia has transformed the digitization of public action into a real lever of soft power and international attractiveness, but also into an economic, diplomatic, strategic and sovereignty resource.

 

From a state in reconstruction to the showcase "e-Estonia"


The Estonian model has its roots in the constraints that accompanied the restoration of the country's independence in 1991. Following the collapse of the USSR and the disappearance of the Soviet administrative system, Estonia had to rapidly rebuild its institutions and implement new systems for identifying and registering its population [8] . This undertaking was all the more demanding given the country's small population, limited administrative base, and restricted public resources. Tallinn thus favored innovative solutions based on the interconnection of systems and close cooperation between public and private actors [9] .


Estonia's digital transformation is therefore not solely driven by a desire for modernization: it can also be interpreted as a response to the demographic, institutional and budgetary constraints that the new state was facing.


This orientation was also shaped by education. Announced in February 1996 by President Lennart Meri [10] , and implemented from 1997 onwards, the Tiger Leap program , or Tiigrihüpe , helped modernize the country's IT infrastructure, with a particular focus on the school system [11] . It notably enabled the gradual equipping of all Estonian schools with computers and internet connections [12] , thus promoting the early adoption of digital skills and practices . In parallel, Estonia's accession to NATO in March 2004, and then to the European Union on May 1 of the same year [13] , consolidated its Western political, economic, and strategic alignment.


In the administrative field, Estonia's gradual evolution towards an "e-state" has notably materialized in the deployment, starting in 2001, of X-Road , a true " backbone" of the Estonian interoperable digital state [14] . While each Estonian public authority is responsible for managing its own IT systems, X-Road allows these independent systems to exchange data securely, facilitating the establishment of an interoperable digital administration [15] For example, police services can access information from the tax administration, the health system or the commercial register, and vice versa [16] .

 

This model has been continually refined over the years, and since December 2024, 100% of Estonian public services have been accessible online [17] . This ambition to build a fully digital state was already expressed in 2011 by the former President of the Republic of Estonia, Toomas Hendrik Ilves, quoted by Leonid Karabeshkin and Raili Rusetski:

 

Nevertheless, we believe in digital technology. We are proud to be pioneers in digital administration. And we are convinced that a citizen-centered, secure, and transparent approach to information and communication technologies (ICTs) in the public sector represents the future of good governance in the 21st century.” – Leonid Karabeshkin & Raili Rustetski, “Estonia’s Soft Power,” [18]

 

Leonid Karabeshkin and Raili Rusetski also highlight several emblematic devices that give substance to this narrative [19] :

 

  1. " e-Voting " [20] , or electronic voting. In 2005, Estonia became the first country in the world to offer online voting for municipal elections held throughout the national territory, and now Estonian citizens are able to vote remotely, in a few minutes, in local, national or European elections [21] .


  2. the " e-Cabinet" [ 22] : Starting in 2000, Estonia transformed its government model, largely shifting from a paper-based system to a digital one, the " e-Cabinet " [23] . This allows politicians to log in, via their electronic identity cards, from their laptops or smartphones, to access the agenda for upcoming sessions, or even to comment on certain topics before the meeting begins [24] . Ultimately, this process reduces paper consumption and also shortens government meetings, which now last approximately 30 minutes, compared to four hours previously [25] .


  3. " e-Health systems " [26] , or digital health systems. Since 2008, the Estonian National Health Information System (HIS) has enabled healthcare providers to connect nationwide and to store patients' digitized medical data on a centralized platform, protected by KSI technology. blockchain , helping to make the country " a world leader in digital health " [27] .

 

Analyzed separately, these services fall under the umbrella of administrative modernization. Together, they form a genuine political demonstration: that of a state capable of providing fast, secure, and interoperable services.

 

The influence of the Estonian model can also be measured by its circulation beyond the national territory.


Mart Noorma (à gauche), directeur du Cooperative Cyber Defence Centre of Excellence de l’OTAN, face aux auditeurs de la majeure Souveraineté numérique et cybersécurité de la session nationale de l’IHEDN.
Mart Noorma (à gauche), directeur du Cooperative Cyber Defence Centre of Excellence de l’OTAN, face aux auditeurs de la majeure Souveraineté numérique et cybersécurité de la session nationale de l’IHEDN.

In Ukraine , the secure data exchange system Trembita , which supports the development of digital public services, was developed based on the Estonian X-Road model [28] . In Benin , a national interoperability platform has also been deployed and is likewise inspired by X-Road [29] . In Armenia , Estonian expertise has contributed to better structuring digital administration: " the e-Governance Academy (eGA) developed the documentation, tools, and applications necessary for launching and implementing a single-source state information system " [30] .

 

These experiences illustrate a particular form of power. Estonia no longer simply exports an image of modernity, but also software, standards, administrative procedures, and principles for the secure flow of data. Its soft power thus relies less on a traditional communication campaign than on the concrete dissemination of an administrative model capable of inspiring and equipping other states.

 

Transforming vulnerability into diplomatic power centered on cybersecurity

 

This success, however, should not be presented as a linear progression. In 2007, Estonia was hit by a vast campaign of cyberattacks targeting, in particular, government websites , banks, and political parties [31] . These attacks had particularly serious consequences for the country because Estonia's economic and administrative functioning already relied heavily on digital tools: according to a CESA report, in 2007, "98% of the country's banking transactions were carried out via the Internet, as were 82% of tax returns " [32] .

 

While these attacks did not create e-Estonia , whose foundations predate them, they did reinforce the importance placed on resilience , data protection, and international cooperation. As a result, Estonia has improved its capabilities to protect against cyberattacks, strengthened its connected infrastructure, and gradually established itself as a recognized international player in cyber defense [33] .

 

The “ data embassy ” opened in Luxembourg is a concrete manifestation of this evolution: based on an agreement signed in 2017, it allows digital resources placed under Estonian control to be kept outside the national territory and for certain critical services to be maintained in the event of a crisis [34] .

 

As Leonid Karabeshkin and Raili Rusetski have shown, Estonia has also managed to transform its cyber expertise into a significant political asset , particularly through its specialization in cybersecurity within NATO [35] . This is evidenced by the creation of the NATO Centre of Excellence for Cooperative Cyber Defence (CCDCOE) [36] in Tallinn in 2008; or the establishment, also in the Estonian capital, of the European Union Agency for the Operational Management of Large-Scale Information Systems in the Area of Freedom, Security and Justice ( eu-LISA ) [37] . The latter, created in 2011 and operational since 1 December 2012, “ contributes to the efforts made by EU countries to make Europe more secure by providing them with technological support [38] .


 

Tallinn Manuals and Locked Shields Exercise


Hosting these institutions allows Estonia to convert its technological reputation into a capacity for gathering, but also into normative influence . Published in 2013, and then significantly expanded in 2017 with the Tallinn Manual 2.0 , the Tallinn Manual analyzes how existing rules of international law can be applied to cyber operations [39] . While the first edition focused primarily on the most serious cyber operations, the 2017 version extended the analysis to operations conducted even in peacetime [40] .


This doctrinal work is neither a legally binding text nor the expression of the official position of NATO, a State, an international organization, or even the CCDCOE [41] . Nevertheless, it has become an influential resource for legal advisors and public policy experts working on cyber issues [42] . It has thus permanently linked the name of Tallinn to debates concerning sovereignty , State responsibility, and, more broadly, conflicts in cyberspace.


This centrality is reinforced by the annual Locked Shields exercise , organized in Tallinn by the CCDCOE since 2010 [43] . Its 2026 edition, which took place from April 13 to 24, 2026 [44] , brought together more than 4,000 participants from 41 countries who were able to train in protecting critical infrastructure and military systems against real-time cyberattacks [45] . According to a publication by the French Cyber Defense Command (COMCYBER), " Locked Shields is the largest and most complex international cyber defense exercise in real-world conditions [46] ."


Tallinn is therefore no longer content with simply hosting specialized institutions: with the Tallinn Manuals, it is helping to clarify the legal framework for cyber operations and, with Locked Shields , to provide concrete training for States to face large-scale cyberattacks together.


Cyber Coalition 2025 - répétition générale face aux menaces russes et chinoises - challenges.fr
Cyber Coalition 2025 - répétition générale face aux menaces russes et chinoises - challenges.fr

 

E-residency: projecting the State beyond its territory

 

Launched in 2014, the " e-Residency" program This could be considered one of the most emblematic expressions of Estonian policy. It gives foreign nationals access to certain Estonian digital services through a digital identity, notably allowing them to create a business " in less than a day." [...] E-residency also allows you to apply for a bank account and to sign and encrypt documents.


All of this is possible online from any country in the world. With this unique status, the Estonian state seeks, and succeeds, in democratizing access to entrepreneurship [47] . E-residency, however, does not confer citizenship, the right to reside, or automatic tax residency: it provides access to a digital administrative and entrepreneurial environment .

 

On July 16, 2026, the official Estonian "e-Residency" website listed over 142,000 e-residents and over 43,000 companies created by them [48] . In 2025 alone, these entrepreneurs and their companies were projected to generate nearly €125 million in direct revenue for the state. [49] : image policy is therefore coupled with a measurable economic benefit.

 

According to Anna Blue ( “Evaluating Estonian E-residency as a tool of soft power ”), this e-residency initiative would demonstrate how “ small states ” can strengthen their soft power by attracting, for example, entrepreneurs from around the world as well as freelancers [50] , making Estonia desirable as a modern state that provides opportunities .


This interpretation could nevertheless be complemented by a more critical approach. Piia Tammpuu and Anu Masso, for example, analyze e-residency as a form of commodification of national space. [51] .


Moreover, this openness produces risks proportional to its visibility . In a report published in 2020, the Estonian Court of Auditors considered that the checks carried out before and after the granting of e-resident status did not always allow sufficient verification of criminal records or bans on carrying out business activities imposed abroad [52] .


These limitations do not call into question the entire program, but they show that the digital extension of the State also increases its reputational exposure : as highlighted in the report, fraud committed by an actor presenting himself as an e-resident could affect Estonia's international credibility [53] .

 

Finally, it is important to note that the strength of the Estonian model does not rest solely on the performance of the administration. The international successes of companies associated with the Estonian technology ecosystem, such as Skype , Bolt , and Wise , have helped to make the narrative of a " start-up nation " seem plausible.


These companies are explicitly mobilized in Estonian institutional communication as manifestations of a national culture of innovation and entrepreneurship [54] . Private successes and public infrastructures thus reinforce each other: the former give international visibility to Estonian know-how, while the latter offer this entrepreneurial narrative a coherent institutional framework.

 

A niche soft power , powerful but fragile

 

Estonia's success, however, has several limitations. First, it is primarily a technical and institutional form of soft power . It effectively reaches public decision-makers, the business community, cybersecurity specialists, and innovation stakeholders, but less directly impacts global public opinion than powerful traditional cultural vectors such as cinema, music, or sports.


In this context, data from the Global Soft Power Index 2025 highlight a paradox: Estonia's overall awareness remains slightly below the average for UN member states, while those familiar with the country have a particularly favorable image of it [55] . According to this analysis, Tallinn thus benefits from a strong, but still concentrated, reputation .

 

Furthermore, this influence rests on trust . A digital administration remains attractive only if it effectively protects data, guarantees users' rights, and demonstrates its ability to withstand crises. The cryptographic vulnerability discovered in 2017 in the chips of approximately 800,000 Estonian identity cards constituted, in this respect, a particularly significant test [56] .


This vulnerability, known as ROCA ( Return of the Coppersmith Attack ), could theoretically have allowed attackers to steal the victim's digital identity or sign documents on their behalf, among other things [57] . However, exploiting the vulnerability remained complex and costly, and according to the Estonian Information System Authority (RIA), no cases of successful exploitation of Estonian identity cards had been identified at the time the relevant certificates were revoked [58] .


Furthermore, Estonia's response helped to limit the consequences of the crisis. The authorities communicated publicly about the vulnerability , developed a procedure for renewing certificates remotely, and suspended certificates that had not been updated [59] . According to the report published by the RIA, digital services remained accessible, the number of transactions carried out using identity cards did not experience a lasting decline in the days and weeks that followed, and trust in electronic identity was not eroded [60] .


This episode reveals that digital trust is not based solely on the absence of any vulnerability, but also on the ability of institutions to detect a failure, to explain it transparently and to correct it without causing systemic paralysis.

 

Finally, digital technology does not replace traditional security instruments. Located on NATO's eastern flank and sharing a border with Russia, Estonia cannot ensure its sovereignty solely through the appeal of its model.


Its technological soft power complements its integration within the European Union and the Atlantic Alliance: it strengthens its partnerships, visibility, and strategic utility, without, however, constituting an independent military guarantee. The Estonian government, however, seems fully aware of this limitation. In April 2025, it approved additional funding of €2.8 billion over four years to increase defense spending, previously set at around 3.4% of GDP , to an average of 5.4% until 2029 [61] . Estonia's experience in this area is therefore based less on a substitution of soft power for hard power than on their complementarity.


 

The Estonian case demonstrates, if proof were still needed, that international influence does not depend solely on the size of a territory or its population. It can also be based on a clearly identified specialization and a state's ability to have its expertise recognized beyond its borders. In the digital sphere, Tallinn has thus succeeded in becoming a sought-after partner, a testing ground , and a meeting point for numerous international players.


This success, however, relies less on technological performance alone than on the credibility of the system implemented. Data protection, infrastructure resilience, and user trust directly determine the sustainability of this influence. Any lasting failure risks damaging a reputation built on security and efficiency.

 

More than just a "first e-state," Estonia has emerged as one of the countries that has best converted the digitization of public action into a resource of influence . Its uniqueness lies not only in the performance of its services, but also in its ability to disseminate its infrastructure, to associate the name of Tallinn with international standards and practices, and even to transform its administrative experience into a model adaptable to other states.

 

Ultimately , Estonia provides a striking example of how a relatively small state can, despite initial constraints, build a strategic specialization and then transform that specialization into a diplomatic, economic, and geopolitical asset . By exporting interoperability platforms, standards, expertise, administrative practices, and, more generally, its image as an e-state, Tallinn is developing genuine soft power on an international scale. But this influence extends beyond mere international reach: it also increases Estonia's weight in debates on digital governance and cybersecurity, while simultaneously strengthening its economic attractiveness and strategic value within international organizations.

 



[1] Joseph S. Nye, “Bound To Lead: The Changing Nature Of American Power,” 1990.

[2] According to Joseph Nye, a state's power does not stem solely from its hard power , namely its military or economic capabilities, among others, but also from its soft power , which can be understood as its ability to be attractive. This influence can be based on culture, political values, the quality of institutions, or, more generally, a country's international image. Examples include gastronomy for France, Hollywood films for the United States, and the manga industry for Japan.

[3] Gilles Paris, “The death of Joseph S. Nye, American theorist of international relations " Le Monde , May 9, 2025.

[4] Leonid Karabeshkin & Raili Rusetski, “Estonia’s Soft Power”, Baltic Horizons , EuroAcademy Tallinn, 2013, p.48.

[5] Ibid.

[6] Ibid. , p. 47.

[7] Ibid ., p. 48.

[8] Ana Milena Aguilar Rivera and Kristjan Vassil, “Estonia: A Successfully Integrated Population-Registration and Identity Management System. Delivering Public Services Effectively”, World Bank , November 2015.

[9] Ibid.

[10] Estonian Ministry of Education and Research, “Technology Compass for Education discussed the future of distance learning”, 23 February 2021: https://hm.ee/en/news/technology-compass-education-discussed-future-distance-learning

[11] Education Estonia, “How it all began? From Tiger Leap to digital society”: https://www.educationestonia.org/tiger-leap/

[12] Ana Milena Aguilar Rivera and Kristjan Vassil, “Estonia: A Successfully Integrated Population-Registration and Identity Management System. Delivering Public Services Effectively”, World Bank , November 2015.

[13] French Ministry for Europe and Foreign Affairs, “Estonia”: https://www.diplomatie.gouv.fr/fr/information-par-pays/estonie/presentation-de-l-estonie

[14] e-Estonia, “X-road – Interoperability services”: https://e-estonia.com/solutions/interoperability-services/x-road/

[15] Ibid.

[16] Ibid.

[17] e-Estonia, “Estonia: 100% digital government services, with divorce as the final step”: https://e-estonia.com/estonia-100-digital-government-services/

[18] Leonid Karabeshkin & Raili Rusetski, “Estonia’s Soft Power”, Baltic Horizons , EuroAcademy Tallinn, 2013, p.49.

[19] Ibid.

[20] Ibid.

[21] e-Estonia, “Enter e-Estonia: e-governance”: https://e-estonia.com/enter-e-governance/

[22] Leonid Karabeshkin & Raili Rusetski, “Estonia’s Soft Power”, Baltic Horizons , EuroAcademy Tallinn, 2013, p.49.

[23] e-Estonia, “Enter e-Estonia: e-governance”: https://e-estonia.com/enter-e-governance/

[24] Ibid.

[25] Ibid.

[26] Leonid Karabeshkin & Raili Rusetski, “Estonia’s Soft Power”, Baltic Horizons , EuroAcademy Tallinn, 2013, p.49.

[28] e-Governance Academy, “First e-service of Trembita system has been launched”, December 18, 2017: https://ega.ee/first-e-service-of-trembita-system-has-been-launched/

[29] Kevin Ngoma-Yembi, Eliakim Dohou, Rodrigue Castro Gbedomon and Frejus Thoto, “Digital Public Infrastructures in Benin: Mapping and Exploratory Analysis of the Impact on Socio-Economic Development”, ACED , September 2025: https://acedafrica.org/publication/les-infrastructures-publiques-numeriques-au-benin-cartographie-et-analyse-exploratoire-de-limpact-sur-le-developpement-socio-economique/

[30] e-Governance Academy, “Strengthening e-governance management in Armenia”: https://ega.ee/project/strengthening-e-governance-management-in-armenia/

[31] Caroline Pélissier, “Estonia: an ambitious cyber defence strategy”, CESA Note , no. 53, 2016: https://www.irsem.fr/storage/file_manager_files/2025/03/n53estonie.pdf

[32] Ibid.

[33] Ibid.

[35] Leonid Karabeshkin & Raili Rusetski, “Estonia’s Soft Power”, Baltic Horizons , EuroAcademy Tallinn, 2013, p.49.

[36] Note that this Centre is not part of the NATO command structure ( NATO , 30 July 2024: https://www.nato.int/fr/what-we-do/deterrence-and-defence/cyber-defence )

[37] Leonid Karabeshkin & Raili Rusetski, “Estonia’s Soft Power”, Baltic Horizons , EuroAcademy Tallinn, 2013, p.49.

[38] European Union, “European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA)”: https://european-union.europa.eu/institutions-law-budget/institutions-and-bodies/search-all-eu-institutions-and-bodies/european-union-agency-operational-management-large-scale-it-systems-area-freedom-security-and_fr

[39] Michael N. Schmitt (dir.), “Tallinn Manual on the International Law Applicable to Cyber Warfare”, Cambridge University Press, 2013.

[40] CCDCOE, “Tallinn Manual 2.0 Paves the Way for State Action in Cyber Space”: https://ccdcoe.org/news/2017/tallinn-manual-2-0-paves-the-way-for-state-action-in-cyber-space/

[41] CCDCOE, “The Tallinn Manual”: https://ccdcoe.org/research/tallinn-manual/

[42] Ibid.

[43] CCDCOE, “World's largest cyber defense exercise Locked Shields kicks off in Tallinn”: https://ccdcoe.org/news/2023/worlds-largest-cyber-defense-exercise-locked-shields-kicks-off-in-tallinn/

[44] COMCYBER, “Exercise Locked Shields 2026: French and international cyberwarriors are ready to go!”, https://www.defense.gouv.fr/comcyber/actualites/exercice-locked-shields-2026-cest-parti-cybercombattants-francais-internationaux

[45] CCDCOE, “Locked Shields 2026 united the power of 41 nations to defend cyberspace”: https://ccdcoe.org/news/2026/locked-shields-2026-united-the-power-of-41-nations-to-defend-cyberspace/

[46] COMCYBER, “Exercise Locked Shields 2026: French and international cyberwarriors are ready to go!”, https://www.defense.gouv.fr/comcyber/actualites/exercice-locked-shields-2026-cest-parti-cybercombattants-francais-internationaux

[47] Virginie Hoarau, “Estonian Chronicles (4): ‘The e-residency, a weapon of massive soft power’”, CJD , January 2020: https://www.cjd.net/ressources/points-de-vue/chroniques-estoniennes-le-residency-arme-de-soft-power-massive-5-9/

[48] e-Residency, “e-⁠Residency in numbers”: https://www.e-resident.gov.ee/fr/dashboard/

[49] e-Residency, “estonian e-residents generated a record €125 million of state revenue in 2025”: https://www.e-resident.gov.ee/fr/blog/posts/e-residents-generated-record-state-revenue-2025/

[50] Anna Blue, “Evaluating Estonian E-residency as a tool of soft power”. Place Branding and Public Diplomacy , 2021.

[51] Piia Tammpuu and Anu Masso, “'Welcome to the virtual state': Estonian e-residency and the digitalized state as a commodity,” European Journal of Cultural Studies , January 2018.

[52] National Audit Office of Estonia , “Effectiveness of the e-Residency Program. Do the Revenues of the e-Residency Program Exceed the Expenses, and Are the Participants in the Program Law-Abiding? », July 23, 2020: https://www.riigikontroll.ee/sites/default/files/arhivaalid/2507/RKTR_2507_2-1.4_2253_009-1.pdf

[53] Ibid.

[55] Kata Varblane, “Estonia: Leveraging innovation, truth, and global branding for greater Soft Power,” Brand Finance , February 20, 2025.

[56] Estonian Information System Authority , “ROCA Vulnerability and eID: Lessons Learned”, 2018: https://www.ria.ee/sites/default/files/documents/2022-11/Roca-vulnerability-and-eID-lessons-learned-2018.pdf

[57] Ibid.

[58] Ibid.

[59] Ibid.

[60] Ibid.

[61] Malek Fouda and Somaya Aqad, with EBU, “Estonia: Government approves supplementary budget to raise defence spending to 5.4% of GDP”, Euronews , April 26, 2025.

 
 
 

Comments


bottom of page