NIS2 Finland: Cybersecurity Act 124/2025
Finland transposed NIS2 through the Cybersecurity Act (kyberturvallisuuslaki 124/2025), in force since 8 April 2025 and amended four times since. Seven separate authorities supervise it, and two of them were created on 1 January 2026. This page sets out who your supervisor is, what you must file and when, and what the fine regime actually reaches.
Introduction
Finland transposed NIS2 through the Cybersecurity Act (kyberturvallisuuslaki, 124/2025), which entered into force on 8 April 2025. The Act has been amended four times since, most recently by three acts that took effect on 1 January 2026.
The single most useful thing to know about the Finnish regime is that there is no single regulator. Section 26 of the Act splits supervision across seven authorities, each covering named points of Annexes I and II. Traficom’s Kyberturvallisuuskeskus is the CSIRT and the single point of contact for the whole country, but it supervises only its own sectors, and it is not where most entities register. Filing with the wrong authority is the most common avoidable mistake in this market.
NIS2 implementation in Finland
The Cybersecurity Act (124/2025) entered into force on 8 April 2025, and the obligations it carries apply directly rather than through implementing decrees. It replaced Finland’s NIS1-era arrangements, which had been spread across sectoral legislation.
The Act has been amended four times, and three of those amendments took effect on 1 January 2026. Any summary written in 2025 - including most of the advisory material still ranking for this topic - predates them.
| Amending act | In force | What it changed |
|---|---|---|
| 369/2025 | 1 July 2025 | Sections 3, 4, 17, 26-28 and 45 - scope definitions and the supervision chapter |
| 494/2025 | 1 January 2026 | Section 40, enforcement of the administrative fine |
| 698/2025 | 1 January 2026 | Section 26 - the list of supervisory authorities, rewritten for the state administration reform |
| 997/2025 | 1 January 2026 | The Annex (sectors and entity types) |
Status
In force since 8 Apr 2025; consolidated text current to the three amendments of 1 Jan 2026.
Official law
Registration
You register with your own supervisory authority, not with a single national portal. Traficom’s list is here; the other six keep their own.
The statute is short by European standards and delegates very little. Fine levels, the reporting clock and the registration data set are all in the Act itself, which is why this page can state them precisely. What each supervisory authority may add is technical regulations on the format and content of filings, and sector-specific detail on risk management (sections 9 and 11).
Who is in scope
Finland uses the Directive’s two tiers, but its own vocabulary: a keskeinen toimija (essential entity) and everything else in scope, which the Act refers to simply as an entity that is not essential rather than as an "important" entity.
The distinction decides three things: the size of the maximum fine, whether you are supervised proactively, and little else. Section 27 is the provision to read. Supervision must be directed at essential entities. A non-essential entity may be supervised only where there is justified reason to suspect non-compliance. In practice that means a non-essential entity is unlikely to hear from its authority at all until something goes wrong - which is not the same as being outside the regime, because every filing duty and the fine still apply.
Who is essential
- An Annex I entity above the EU medium-sized thresholds (Recommendation 2003/361/EC).
- Qualified trust service providers, TLD registries and DNS service providers - at any size.
- Providers of public electronic communications networks or publicly available electronic communications services that meet or exceed the medium-sized thresholds.
The four duties that carry a fine
- Managing risk and having the operating model (sections 7, 8, 9(1))
- Implementing the section 9(2) measures
- Filing the incident report, interim report or final report (sections 11-13)
- Filing your registration data (section 41)
Nothing else in the Act is directly fineable. See Penalties.
Critical entities
An entity designated critical under the act transposing the CER Directive is in scope regardless of size. Where such an entity carries on no Annex I or II activity, section 26 hands supervision to the authority competent under section 19 of that act instead.
Registration & the one-month clock
Finland has no single registration deadline, and the dates every guide prints are the first cohort's dates only. Section 47 gives you one month from the Act entering into force or from the moment you first meet the section 3 criteria, whichever applies to you.
So 8 May 2025 was the deadline for organisations that were already in scope on 8 April 2025. A company that crossed a size threshold, entered an Annex sector or was designated critical in 2026 has one month from that moment. The obligation is rolling, and it did not expire. Fimea states the rule in these terms in its own English guidance.
What you file (section 41(2))
- Name; address, e-mail, telephone and other current contact details
- Your IP address ranges
- The relevant Annex I or II sector and sub-sector
- Whether you are an essential entity
- The EU member states where you offer in-scope services
- Whether you take part in the voluntary information-sharing arrangement under section 23
Digital infrastructure files more (section 41(3))
DNS providers, TLD registries, cloud and data-centre providers, CDNs, managed service and managed security providers, online marketplaces, search engines and social platforms must also give their entity type, the address of their main establishment and other EU establishments - or of their EU representative - and the member-state list.
Keeping it current
Changes must be notified without delay, and the Act sets two outer limits: two weeks for the section 41(2) data and three months for the section 41(3) data. This is a standing duty, not a one-off filing.
The risk-management operating model
Section 8 requires an up-to-date kyberturvallisuutta koskeva riskienhallinnan toimintamalli - a cybersecurity risk-management operating model. It is a document, it must identify risks on an all-hazards basis, and it must set out the objectives, procedures, responsibilities and the section 9 measures.
Its deadline is rolling in the same way registration is: three months from the Act entering into force, or three months from when you first meet the section 3 criteria. For the first cohort that was 8 July 2025.
Section 9(2) lists twelve things the model and its controls must cover and keep current:
| # | Measure |
|---|---|
| 1 | Risk-management policies, and evaluation of how effective the controls are |
| 2 | Policies on the security of networks and information systems |
| 3 | Security in acquisition, development and maintenance, including vulnerability handling and disclosure |
| 4 | The overall quality and resilience of direct suppliers’ products and service providers’ services, the controls in them, and those suppliers’ own cybersecurity practices |
| 5 | Asset management and identification of the functions important to security |
| 6 | Personnel security and cybersecurity training |
| 7 | Access control and authentication procedures |
| 8 | Policies and procedures on the use of cryptography, and where appropriate secured electronic communications |
| 9 | Incident detection and handling, to restore and maintain security and operational reliability |
| 10 | Backup, recovery planning, crisis management and other continuity management, and where appropriate secured backup communications systems |
| 11 | Basic cyber hygiene practices for operations, communications, hardware, software and data security |
| 12 | Physical and premises security for the environment of networks and information systems, and securing essential resources |
Measures must be proportionate to the nature and scale of the activity, the foreseeable direct impact of an incident, exposure, the likelihood and severity of incidents, the cost of the measures and the state of the art. Your supervisory authority may issue technical regulations adding sector-specific detail.
Incident reporting: 24h / 72h / one month
Reports go to your supervisory authority, and both of the first two clocks run from detection of the incident - not from the previous report. This is the part of the Finnish regime that no competing English or Finnish guide sets out.
Trust services report faster
Where a significant incident affects a trust service provider’s trust services, the jatkoilmoitus is due within 24 hours of detection, not 72.
The final-report clock can favour you
For a long-running incident the month runs from the close of handling rather than from the 72-hour report. Most member states run it strictly from the notification.
What counts as significant
Section 11(1) sets the national test, and the Commission implementing act under Article 23(11) of the Directive adds the cases it specifies for digital infrastructure and digital providers.
National NIS2 timeline & key dates
Deadlines (Finland)
Finland’s deadlines are relative, not calendar. Section 47 ties both of them either to the Act’s entry into force or to the moment you first meet the section 3 criteria. The table below gives the rule and, for the first cohort, the date it produced.
| Duty | The rule | First cohort |
|---|---|---|
| Register with your supervisory authority (s.41) | One month from entry into force or from meeting the s.3 criteria | 8 May 2025 |
| Have the risk-management operating model (s.8) | Three months from entry into force or from meeting the s.3 criteria | 8 Jul 2025 |
| Notify changes to your s.41(2) registration data | Without delay, and at the latest within two weeks | Standing duty |
| Notify changes to your s.41(3) data (digital infrastructure) | Without delay, and at the latest within three months | Standing duty |
Sector-specific requirements (Finland)
- Electronic communications and digital infrastructure: Traficom supervises, and is also the CSIRT and SPOC. This is the one sector where the supervisor and the incident-response body are the same organisation.
- Energy: Energiavirasto supervises electricity, district heating and cooling, oil and parts of gas and hydrogen. Tukes takes the remaining Annex I point 10 and 12 sub-points, so gas and hydrogen are split between two authorities by sub-point.
- Health: split. Lupa- ja valvontavirasto covers Annex I point 13(a-b) - healthcare providers - while Fimea covers 13(c-f), the pharmaceutical and medical-device chain.
- Medicines and medical devices: Fimea maintains its own entity list and e-service, and charges a 360 euro processing fee and 360 euro annual maintenance fee.
- Food: Ruokavirasto supervises Annex II point 7 and publishes its own sector guidance - a supervisory role that no English-language summary of Finnish NIS2 records.
- Water, waste and transport-adjacent activity: Elinvoimakeskus covers Annex I points 14 and 15; the ten regional bodies replaced the ELY Centres on 1 January 2026.
- Manufacturing, chemicals, postal, waste management and research: Tukes covers Annex II points 6 and 11-13.
- Banking and financial market infrastructure: largely displaced by DORA, with a statutory information-exchange duty between the supervisors, Traficom and Finanssivalvonta under section 45.
Penalties & fines
The Finnish fine regime is narrower than the headline ceilings suggest, and the limits on it are the useful part. An administrative fine (hallinnollinen seuraamusmaksu) can be imposed only for four listed failures, and only where they are intentional or grossly negligent.
Essential entities
10,000,000 euros or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Entities that are not essential
7,000,000 euros or 1.4% of total worldwide annual turnover for the preceding financial year, whichever is higher.
No statutory minimum
Finland sets ceilings only. Several member states impose a floor beneath which a fine cannot fall; Finland does not, so a proportionate fine on a small entity can be genuinely small.
Section 35 - the four failures that can be fined:
- Failing to manage risk under section 7, to draw up the operating model under section 8, or to address the section 9(1) elements within it
- Failing to implement the measures required by section 9(2)
- Failing to give the incident report (s.11), the interim report (s.12) or the final report (s.13)
- Failing to give the registration data required by section 41
Anything else in the Act is enforced through orders rather than fines. Under section 34 a supervisory authority may back its decisions with a uhkasakko (conditional fine), a teettamisuhka (a threat to have the work done at your expense) or a keskeyttamisuhka (a threat of suspension).
The sanctions board
The authority that investigates you is not the authority that fines you. Section 36 creates a seuraamusmaksulautakunta, a sanctions board sitting in connection with Traficom. Your supervisory authority proposes the fine; the board decides it. The fine is paid to the State.
How it is composed
Traficom appoints the chair and vice-chair. Each of the seven supervisory authorities appoints one member and a personal alternate. Members are appointed for three-year terms and act independently and impartially.
What members must know
Each member must be familiar with cybersecurity risk management and with NIS2 obligations as they apply in the appointing authority's own sector. The chair and vice-chair must have sufficient legal expertise.
How it decides
Quorum is the chair or vice-chair plus at least two other members. The majority view prevails - and on a tie, the view more lenient to the entity wins.
Decisions are taken on presentation by an official of the supervisory authority whose remit the case falls in. The board may obtain the information necessary to set the fine notwithstanding secrecy provisions.
Section 37 sets the assessment. The amount rests on an overall evaluation taking account of at least:
- the seriousness of the breach and the importance of the provisions breached - shown by repetition; failing to report or remedy significant incidents; failing to fix identified shortcomings despite the authority's decisions or warnings; obstructing an inspection or failing to commission an ordered audit; and giving false or misleading information about risk management or significant incidents
- the duration of the breach
- any comparable earlier breaches by the entity
- the damage caused, including financial or economic losses, effects on other services and the number of users affected
- the degree of intent
- measures taken to prevent or mitigate the damage
- adherence to approved codes of conduct or certification mechanisms
- the entity's willingness to cooperate with the supervisory authority
When a fine is not imposed
Section 39 is drafted as a duty, not a discretion: in these cases the fine is not imposed (jatetaan maaraamatta). For most organisations this is the most practically important provision in the Act.
- You fixed it yourself. The entity took sufficient measures on its own initiative to correct the breach immediately after detecting it, notified the supervisory authority without delay, and cooperated - and the breach is neither serious nor repeated.
- The breach is minor.
- A fine would be manifestly unreasonable on some other ground.
Three further bars apply:
Five-year limitation
No fine may be imposed more than five years after the breach. For a continuing breach the period runs from the day it ended.
Criminal proceedings
No fine may be imposed on a person suspected of the same act in a pre-trial investigation, in consideration of charges, or in a pending criminal case - nor on anyone already given a final judgment for it.
The GDPR bar
No fine may be imposed on an entity that has already been fined for the same act under Article 83 of the GDPR. Section 33 separately requires your supervisory authority to notify the Data Protection Ombudsman where a failure may have caused a personal-data breach.
How Finland differs
If you are running NIS2 across several member states, these are the points where Finland will not behave like your other jurisdictions.
- There is no single regulator and no single register. Seven authorities supervise by Annex point and each keeps its own entity list. Most member states run one national register.
- Two of the seven authorities were created on 1 January 2026, and one that pre-2026 guidance names was abolished on the same day.
- The deadlines are relative, not calendar. One month and three months from entry into force or from meeting the criteria - so there is no national date after which registration closes.
- The fine reaches only four duties, and only on intent or gross negligence. Many transpositions make any breach of the security obligations fineable.
- A separate sanctions board imposes the fine, composed of one member from each supervisory authority, and ties go to the more lenient outcome.
- Public bodies cannot be fined - including, unusually, the Evangelical Lutheran and Orthodox Churches and their parishes.
- There is no statutory minimum fine.
- One CSIRT, not two. Several member states split CSIRT duties between civil and government or defence teams; Finland does not.
- Both reporting clocks run from detection, and the final-report clock can run from the close of handling instead.
- Registration fees are set per authority, not nationally.
Finnish terms you will meet
Official guidance, filing forms and the authorities’ own correspondence use these terms. The Act has no official English translation.
| Finnish | English |
|---|---|
| kyberturvallisuuslaki | the Cybersecurity Act (124/2025) |
| keskeinen toimija | essential entity |
| toimijaluettelo | the list of entities you register in |
| riskienhallinnan toimintamalli | risk-management operating model (s.8) |
| merkittava poikkeama | significant incident |
| ensi-ilmoitus | early warning, due in 24 hours |
| jatkoilmoitus | incident notification, due in 72 hours |
| valiraportti / loppuraportti | interim report / final report |
| valvova viranomainen | supervisory authority |
| hallinnollinen seuraamusmaksu | administrative fine |
| seuraamusmaksulautakunta | the sanctions board (s.36) |
| uhkasakko | conditional fine backing an order |
| Kyberturvallisuuskeskus | the National Cyber Security Centre, the CSIRT and SPOC |
How to prepare for NIS2 in Finland
- Identify which of the seven authorities supervises you - by Annex point, using the table above. Everything else follows from this, and it is where most Finnish NIS2 files go wrong.
- Establish your date. If you were in scope on 8 April 2025 your deadlines were 8 May and 8 July 2025. If you came into scope later, your clocks are one month and three months from that moment.
- File your section 41 data with that authority, including your IP address ranges, and check the fee schedule that applies to you.
- Put the change-notification duty on a calendar - two weeks for core data, three months for digital-infrastructure data. It is a standing obligation and it is directly fineable.
- Write the section 8 operating model as a document, covering all twelve section 9(2) elements, and have management approve it - the approval is the statutory act, not the drafting.
- Brief management to the section 10 definition: the board, the supervisory board, the managing director, and anyone who in fact directs operations.
- Build the reporting chain to run from detection: 24 hours, 72 hours, interim, final. Trust service providers need a 24-hour path for the second report.
- Prepare the section 14 customer notification in advance - who signs it off, and how fast.
- Document self-correction. Section 39 removes the fine where you fixed it yourself, told the authority without delay and cooperated. That defence only exists if you can evidence it.
