NIS 2 — Finland
NIS 2 IN FINLAND
Kyberturvallisuuslaki (124/2025) — the national act transposing Directive (EU) 2022/2555 in Finland. Supervised by Liikenne- ja viestintävirasto Traficom (Traficom).
TRANSPOSED — IN FORCE
Key facts
In force
8 April 2025
National law
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register through Traficom's NIS 2 portal within set deadlines after the law's entry into force; the NCSC-FI publishes sector-specific guidance.
Scope and national nuance
Finland's Kyberturvallisuuslaki entered into force in April 2025, with Traficom as the national supervisor and its embedded Kyberturvallisuuskeskus (NCSC-FI) operating as the national CSIRT. Sector regulators retain enforcement for energy, finance and health.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Cyber Security Centre (national CSIRT) | Kyberturvallisuuskeskus | NCSC-FI |
| Energy | Energiavirasto | EV |
| Health | Sosiaali- ja terveysalan lupa- ja valvontavirasto | Valvira |
| Financial services | Finanssivalvonta | FIN-FSA |
What is specific to Finland
- Traficom is both the policy supervisor and the host of the Kyberturvallisuuskeskus (NCSC-FI) — covered entities have a single point of contact for both supervision and incident response.
- Finland's well-established public-private cyber-information-sharing model continues under the new law — covered entities can join sector-specific information-sharing communities operated through NCSC-FI.
- The law's drafting explicitly references CRA, DORA and the EU AI Act, with cross-references aimed at reducing the documentation burden where entities are covered by multiple regimes.
- The Kyberturvallisuuskeskus's Tietoturvamerkki labelling scheme for connected products remains available as a supporting evidence base for supply-chain security obligations.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to Traficom’s supervisory expectations.