The case for consolidation
The strongest argument for Estonia's digital state reform is that fragmentation is a real cost. Justice and Digital Minister Liisa Pakosta said the reform addresses "decades-long" problems in which each ministry built its own digital services, leaving uneven quality and accumulating technical debt (Ministry of Justice and Digital Affairs, 16 July 2026). Her earlier framing was about security: a unified cyber defence is stronger because agencies "will no longer spend money separately on similar activities" (ERR News). A country under persistent hostile cyber pressure has good reason to want fewer, better-defended IT shops. That is a serious case and it deserves a serious hearing.
What the government approved
The government approved the reform on July 16, 2026. According to the ministry, the number of state IT bodies falls from ten to six. The Information System Authority (RIA) takes over base services. The Centre of Registers and Information Systems (RIK) becomes the Digiriigi Keskus, or Digital State Center, which operates internationally as GovTech Estonia. A Digital Council (Diginõukogu) and a Chief IT Architect inside RIA will set architecture choices for the whole state. The ministry also says duplicate development is prohibited, so no new system may replicate an existing central solution. The stated aim is to avoid vendor lock-in (Ministry of Justice and Digital Affairs).
The savings are projected at about €11 million a year after three years. The government's own release says the reform also cuts roughly 200 IT civil-service positions, and that more development work will be outsourced to the private sector (Government Office). Put in perspective, ERR's reporting puts total state IT spending near €300 million a year, and the state IT workforce has grown from 1,064 in 2019 to 1,904 in 2026 (ERR). Against that base, €11 million is a rounding-error-scale saving, roughly 3.7% of spending.
Where X-Road fits
The news coverage of the reform does not mention X-Road, and the ministry summary I reviewed does not either. The connection is structural rather than announced. RIA already manages the Estonian X-tee data-exchange layer (RIA). RIA is the body gaining base services, the Chief IT Architect and a wider architecture mandate. So the reform concentrates more authority over the layer that connects Estonia's public and private information systems in one agency.
That layer is central to how the state works. e-Estonia describes X-Road as an open-source data-exchange solution handling about 2.2 billion transactions a year, with more than 3,000 e-services and 52,000 organisations as indirect users. It is used in over 20 countries (e-Estonia). RIA's own description stresses that traffic is encrypted and signed, and that access is authenticated and multi-level authorised, with logs processed at a high level (RIA).
The decentralised design has a policy consequence. X-Road worked because it let independent agencies and companies connect without handing their data to a central owner. Consolidating architecture authority does not break that. It does raise the stakes of getting the governance right.
Why savings are the wrong yardstick
The government's own deputy chancellor for digital government, Lauri Luht, said the goal is "not to simply reduce costs" but to use every euro more intelligently. Taimar Peterkop, a former RIA director, told ERR he doubts "real money savings will emerge" (ERR). Both can be right. If the reform is judged as a budget cut, it will look thin. If it is judged as a way to stop each ministry rebuilding the same registry, login or payment component, it could be worth far more than €11 million.
The risks are on the governance side, and three stand out:
- Single point of failure. Concentrating base services and architecture in one agency simplifies defence, but it also concentrates blame and attack value. Resilience needs to be designed in, not assumed.
- Architecture by committee or by fiat. A Chief IT Architect with authority to reject a ministry's system can prevent waste. Without published criteria and a route to challenge decisions, the same power can slow the small teams and private vendors that build useful things.
- Losing institutional knowledge. Cutting about 200 positions while outsourcing more development moves expertise out of the state. That is fine if procurement is open and standards are public. It is dangerous if it produces a new form of vendor dependence, the very outcome the reform says it wants to avoid.
What a proportionate version looks like
Estonia's own record points to the answer. X-Road is open source and jointly developed through the Nordic Institute for Interoperability Solutions with Finland and Iceland (RIA). That outside anchor is a real check on any single Estonian agency. The reform should keep it.
The Digital Council and Chief Architect should therefore publish their architecture decisions and reasoning, in the open, as a matter of routine. The "no duplicate development" rule should come with a fast exception process, so that a ministry with a genuinely different need is not forced onto a poor central product. RIA's expanded remit should also be tied to independent security audits whose summaries are public. None of this requires new legislation. It requires the government to treat transparency as part of the design.
Estonia has made a defensible bet that less duplication and a single architectural voice will serve citizens better than ten sets of IT decisions. The evidence for that bet will come from delivery, not from the €11 million headline. If the Digital Council stays open to challenge and the exchange layer stays open-source and interoperable, the country will keep what made its model worth copying. If the centre becomes the only voice in the room, it will lose it.