Skip to content

NIS 2 IN FINLAND

Kyberturvallisuuslaki (124/2025) — the national act transposing Directive (EU) 2022/2555 in Finland. Supervised by Liikenne- ja viestintävirasto Traficom (Traficom).

TRANSPOSED — IN FORCE

Key facts

In force
8 April 2025
National law
Kyberturvallisuuslaki (124/2025)
Primary supervisor
Liikenne- ja viestintävirasto Traficom (Traficom)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register through Traficom's NIS 2 portal within set deadlines after the law's entry into force; the NCSC-FI publishes sector-specific guidance.

Scope and national nuance

Finland's Kyberturvallisuuslaki entered into force in April 2025, with Traficom as the national supervisor and its embedded Kyberturvallisuuskeskus (NCSC-FI) operating as the national CSIRT. Sector regulators retain enforcement for energy, finance and health.

Sector supervisors

SectorAuthorityAcronym
Cyber Security Centre (national CSIRT)KyberturvallisuuskeskusNCSC-FI
EnergyEnergiavirastoEV
HealthSosiaali- ja terveysalan lupa- ja valvontavirastoValvira
Financial servicesFinanssivalvontaFIN-FSA

What is specific to Finland

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to Traficom’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →