The affected Estonian ID cards use 2048-bit RSA keys. If you look at the Ars Technica link then they are quoted:
the worst case for a 2048-bit one would require no more than 17 days and $40,300 using a 1,000-instance machine on Amazon Web Service ... On average, it would require half the cost and time to factorize the affected keys.
I assume this is calculated based on the standard EC2 prices ($40300/key with 17 days and 1k machines). If you'd use EC2 spot instances (or the relevant Google or Microsoft services - or any other of the vastly cheaper alternatives) then the cost comes down to about €5k (and 8 days with 1k low-tier EC2 machines) for a single key pair (on average, worst case is 2x that much).
I'm not the one to judge if that's cheap or expensive enough to not worry about anybody ever breaking a key. I just have to point out that this key is equivalent to a real signature and documents signed with it (also cast votes etc) are legally binding. In case of a breached private key, there's no (known) way to prove if it was you who signed some documents or an attacker.