NIS2 Country Guide

NIS2 Finland: Cybersecurity Act 124/2025

Finland transposed NIS2 through the Cybersecurity Act (kyberturvallisuuslaki 124/2025), in force since 8 April 2025 and amended four times since. Seven separate authorities supervise it, and two of them were created on 1 January 2026. This page sets out who your supervisor is, what you must file and when, and what the fine regime actually reaches.

In force: 8 Apr 2025 Amended 4 times: 1 Jan 2026 7 supervisory authorities Report: 24h / 72h / 1 month Last updated: 12 August 2026

Introduction

Finland transposed NIS2 through the Cybersecurity Act (kyberturvallisuuslaki, 124/2025), which entered into force on 8 April 2025. The Act has been amended four times since, most recently by three acts that took effect on 1 January 2026.

The single most useful thing to know about the Finnish regime is that there is no single regulator. Section 26 of the Act splits supervision across seven authorities, each covering named points of Annexes I and II. Traficom’s Kyberturvallisuuskeskus is the CSIRT and the single point of contact for the whole country, but it supervises only its own sectors, and it is not where most entities register. Filing with the wrong authority is the most common avoidable mistake in this market.

Watch the authority names. On 1 January 2026 Finland reorganised its state administration. Valvira, the six regional state administrative agencies and most of the fifteen ELY Centres were dissolved, and their NIS2 duties passed to the new Lupa- ja valvontavirasto and to ten regional Elinvoimakeskus bodies. Guidance written before 2026 still names the old bodies, and valvira.fi still resolves, so the change is easy to miss.

NIS2 implementation in Finland

The Cybersecurity Act (124/2025) entered into force on 8 April 2025, and the obligations it carries apply directly rather than through implementing decrees. It replaced Finland’s NIS1-era arrangements, which had been spread across sectoral legislation.

The Act has been amended four times, and three of those amendments took effect on 1 January 2026. Any summary written in 2025 - including most of the advisory material still ranking for this topic - predates them.

Amending actIn forceWhat it changed
369/20251 July 2025Sections 3, 4, 17, 26-28 and 45 - scope definitions and the supervision chapter
494/20251 January 2026Section 40, enforcement of the administrative fine
698/20251 January 2026Section 26 - the list of supervisory authorities, rewritten for the state administration reform
997/20251 January 2026The Annex (sectors and entity types)

Status

In force since 8 Apr 2025; consolidated text current to the three amendments of 1 Jan 2026.

Registration

You register with your own supervisory authority, not with a single national portal. Traficom’s list is here; the other six keep their own.

The statute is short by European standards and delegates very little. Fine levels, the reporting clock and the registration data set are all in the Act itself, which is why this page can state them precisely. What each supervisory authority may add is technical regulations on the format and content of filings, and sector-specific detail on risk management (sections 9 and 11).

Who is in scope

Finland uses the Directive’s two tiers, but its own vocabulary: a keskeinen toimija (essential entity) and everything else in scope, which the Act refers to simply as an entity that is not essential rather than as an "important" entity.

The distinction decides three things: the size of the maximum fine, whether you are supervised proactively, and little else. Section 27 is the provision to read. Supervision must be directed at essential entities. A non-essential entity may be supervised only where there is justified reason to suspect non-compliance. In practice that means a non-essential entity is unlikely to hear from its authority at all until something goes wrong - which is not the same as being outside the regime, because every filing duty and the fine still apply.

Who is essential

  • An Annex I entity above the EU medium-sized thresholds (Recommendation 2003/361/EC).
  • Qualified trust service providers, TLD registries and DNS service providers - at any size.
  • Providers of public electronic communications networks or publicly available electronic communications services that meet or exceed the medium-sized thresholds.

The four duties that carry a fine

  • Managing risk and having the operating model (sections 7, 8, 9(1))
  • Implementing the section 9(2) measures
  • Filing the incident report, interim report or final report (sections 11-13)
  • Filing your registration data (section 41)

Nothing else in the Act is directly fineable. See Penalties.

Critical entities

An entity designated critical under the act transposing the CER Directive is in scope regardless of size. Where such an entity carries on no Annex I or II activity, section 26 hands supervision to the authority competent under section 19 of that act instead.

Financial sector: DORA displaces most of this regime for banking and financial market infrastructure. Section 45 still requires the supervisory authorities, Traficom and Finanssivalvonta to exchange information on significant incidents and threats regularly, and to notify the DORA oversight forum when powers are used against a designated critical ICT third-party provider.

Registration & the one-month clock

Finland has no single registration deadline, and the dates every guide prints are the first cohort's dates only. Section 47 gives you one month from the Act entering into force or from the moment you first meet the section 3 criteria, whichever applies to you.

So 8 May 2025 was the deadline for organisations that were already in scope on 8 April 2025. A company that crossed a size threshold, entered an Annex sector or was designated critical in 2026 has one month from that moment. The obligation is rolling, and it did not expire. Fimea states the rule in these terms in its own English guidance.

What you file (section 41(2))

  • Name; address, e-mail, telephone and other current contact details
  • Your IP address ranges
  • The relevant Annex I or II sector and sub-sector
  • Whether you are an essential entity
  • The EU member states where you offer in-scope services
  • Whether you take part in the voluntary information-sharing arrangement under section 23

Digital infrastructure files more (section 41(3))

DNS providers, TLD registries, cloud and data-centre providers, CDNs, managed service and managed security providers, online marketplaces, search engines and social platforms must also give their entity type, the address of their main establishment and other EU establishments - or of their EU representative - and the member-state list.

Keeping it current

Changes must be notified without delay, and the Act sets two outer limits: two weeks for the section 41(2) data and three months for the section 41(3) data. This is a standing duty, not a one-off filing.

Registration can cost money, and the amount depends on who supervises you. Fimea charges a 360 euro processing fee and a 360 euro annual maintenance fee for entities on its list. Each supervisory authority sets its own schedule under its own fee decree, so check your authority's rather than assuming Fimea's applies. We publish no national figure, because there is not one.

The risk-management operating model

Section 8 requires an up-to-date kyberturvallisuutta koskeva riskienhallinnan toimintamalli - a cybersecurity risk-management operating model. It is a document, it must identify risks on an all-hazards basis, and it must set out the objectives, procedures, responsibilities and the section 9 measures.

Its deadline is rolling in the same way registration is: three months from the Act entering into force, or three months from when you first meet the section 3 criteria. For the first cohort that was 8 July 2025.

Section 9(2) lists twelve things the model and its controls must cover and keep current:

#Measure
1Risk-management policies, and evaluation of how effective the controls are
2Policies on the security of networks and information systems
3Security in acquisition, development and maintenance, including vulnerability handling and disclosure
4The overall quality and resilience of direct suppliers’ products and service providers’ services, the controls in them, and those suppliers’ own cybersecurity practices
5Asset management and identification of the functions important to security
6Personnel security and cybersecurity training
7Access control and authentication procedures
8Policies and procedures on the use of cryptography, and where appropriate secured electronic communications
9Incident detection and handling, to restore and maintain security and operational reliability
10Backup, recovery planning, crisis management and other continuity management, and where appropriate secured backup communications systems
11Basic cyber hygiene practices for operations, communications, hardware, software and data security
12Physical and premises security for the environment of networks and information systems, and securing essential resources

Measures must be proportionate to the nature and scale of the activity, the foreseeable direct impact of an incident, exposure, the likelihood and severity of incidents, the cost of the measures and the state of the art. Your supervisory authority may issue technical regulations adding sector-specific detail.

Section 10 defines management, and the definition is wider than the board. Management approves the operating model and supervises its implementation, and must have sufficient familiarity with cybersecurity risk management. "Management" means the board, the supervisory board and the managing director - and anyone in a comparable position who in fact directs the entity’s operations. Finland does not, unlike some member states, prescribe the duration or content of that training.

Who supervises you: the seven authorities

Section 26 names seven supervisory authorities and allocates them by Annex point. This map is not published in English anywhere else, including on the regulator’s own NIS2 pages, which tell readers only to "contact the supervisory authority of your sector".

AuthoritySupervises
Liikenne- ja viestintavirasto (Traficom)Annex I points 1-7; Annex II points 1-5
Energiavirasto (Energy Authority)Annex I points 8 and 9, point 10(a-c), point 12(b)
Turvallisuus- ja kemikaalivirasto (Tukes)Annex I point 10(d-g), point 11, point 12(a); Annex II points 6 and 11-13
Lupa- ja valvontavirastoAnnex I point 13(a-b); Annex II point 8
ElinvoimakeskusAnnex I points 14 and 15
Ruokavirasto (Finnish Food Authority)Annex II point 7
Laakealan turvallisuus- ja kehittamiskeskus (Fimea)Annex I point 13(c-f); Annex II points 9 and 10

The authorities are required to cooperate in carrying out supervision.

Two of these bodies did not exist before 2026, and one that many guides still name no longer does. Finland’s state regional administration was reorganised on 1 January 2026. Valvira, the six regional state administrative agencies and most of the fifteen ELY Centres ceased to exist. Their licensing and supervision work went to the new national Lupa- ja valvontavirasto, and regional duties to ten Elinvoimakeskus bodies. Amending act 698/2025 rewrote section 26 to match, with effect from the same day. If your compliance file names Valvira or an ELY Centre as your NIS2 supervisor, it names a body that has been dissolved.

CSIRT - and there is only one

Traficom’s Kyberturvallisuuskeskus is the national CSIRT unit. Unlike several member states, Finland does not split CSIRT duties between a civil and a defence or government team.

Single point of contact

Section 18 makes the same Kyberturvallisuuskeskus the SPOC, tasked with promoting cooperation and coordination between the seven supervisory authorities and with reporting to ENISA.

Crisis coordination

Section 44 makes Kyberturvallisuuskeskus the coordinator for large-scale incidents and crises. The plan under section 43 is drawn up with the section 26 authorities, the police, the Security Police, the Defence Forces and the National Emergency Supply Agency.

Incident reporting: 24h / 72h / one month

Reports go to your supervisory authority, and both of the first two clocks run from detection of the incident - not from the previous report. This is the part of the Finnish regime that no competing English or Finnish guide sets out.

Without delay - the duty arises. Section 11 requires notification of a significant incident: one that has caused or may cause serious operational disruption or considerable financial loss to you, or considerable material or non-material damage to others.
24 hours from detection - ensi-ilmoitus, the early warning. It states that a significant incident has been detected, whether it is suspected to result from a criminal, otherwise unlawful or hostile act, and whether cross-border effects are possible or likely.
72 hours from detection - jatkoilmoitus. An assessment of the nature, severity and impact of the incident, technical indicators of compromise where available, and any updates to the first report.
Interim report - on the authority’s request at any time, and for a long-running incident at the latest one month after the jatkoilmoitus.
Final report - one month from the jatkoilmoitus, or, for a long-running incident, one month from the end of its handling. It must give a detailed description of the incident, its severity and impact; the type of threat or likely root cause; the mitigation measures taken and under way; and any cross-border effects.

Trust services report faster

Where a significant incident affects a trust service provider’s trust services, the jatkoilmoitus is due within 24 hours of detection, not 72.

The final-report clock can favour you

For a long-running incident the month runs from the close of handling rather than from the 72-hour report. Most member states run it strictly from the notification.

What counts as significant

Section 11(1) sets the national test, and the Commission implementing act under Article 23(11) of the Directive adds the cases it specifies for digital infrastructure and digital providers.

Section 14 - the duty to tell your customers, which almost no guide mentions. You must without delay inform the recipients of your services of a significant incident likely to impair those services, and inform affected recipients of a significant cyber threat together with the remedies available to them. Where disclosure is in the public interest, the supervisory authority may order you to publish the incident, or publish it itself.

National NIS2 timeline & key dates

27 Dec 2022 — NIS2 published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline. Finland did not meet it.
8 Apr 2025 — the Cybersecurity Act (124/2025) enters into force. Bill trail: HE 57/2024, LiVM 1/2025, EV 15/2025.
8 May 2025 — registration due for entities already in scope on 8 April. For everyone else the one-month clock starts when they come into scope.
8 Jul 2025 — risk-management operating model due for the same first cohort; three months for everyone since.
1 Jul 2025 — amending act 369/2025 changes sections 3, 4, 17, 26-28 and 45.
1 Jan 2026 — acts 494/2025, 698/2025 and 997/2025 take effect. Valvira, the regional state administrative agencies and most ELY Centres are dissolved; Lupa- ja valvontavirasto and ten Elinvoimakeskus bodies take over their NIS2 duties.

Deadlines (Finland)

Finland’s deadlines are relative, not calendar. Section 47 ties both of them either to the Act’s entry into force or to the moment you first meet the section 3 criteria. The table below gives the rule and, for the first cohort, the date it produced.

DutyThe ruleFirst cohort
Register with your supervisory authority (s.41) One month from entry into force or from meeting the s.3 criteria 8 May 2025
Have the risk-management operating model (s.8) Three months from entry into force or from meeting the s.3 criteria 8 Jul 2025
Notify changes to your s.41(2) registration data Without delay, and at the latest within two weeks Standing duty
Notify changes to your s.41(3) data (digital infrastructure) Without delay, and at the latest within three months Standing duty
If you came into scope after April 2025, you have not missed anything. The widely reprinted "8 May 2025 deadline for all entities" describes only organisations that were already in scope when the Act commenced. Your clock started when you met the criteria. Equally, if you were in scope then and have not filed, the duty has not lapsed - it is simply overdue, and late filing is one of the four things that can be fined.

Sector-specific requirements (Finland)

  • Electronic communications and digital infrastructure: Traficom supervises, and is also the CSIRT and SPOC. This is the one sector where the supervisor and the incident-response body are the same organisation.
  • Energy: Energiavirasto supervises electricity, district heating and cooling, oil and parts of gas and hydrogen. Tukes takes the remaining Annex I point 10 and 12 sub-points, so gas and hydrogen are split between two authorities by sub-point.
  • Health: split. Lupa- ja valvontavirasto covers Annex I point 13(a-b) - healthcare providers - while Fimea covers 13(c-f), the pharmaceutical and medical-device chain.
  • Medicines and medical devices: Fimea maintains its own entity list and e-service, and charges a 360 euro processing fee and 360 euro annual maintenance fee.
  • Food: Ruokavirasto supervises Annex II point 7 and publishes its own sector guidance - a supervisory role that no English-language summary of Finnish NIS2 records.
  • Water, waste and transport-adjacent activity: Elinvoimakeskus covers Annex I points 14 and 15; the ten regional bodies replaced the ELY Centres on 1 January 2026.
  • Manufacturing, chemicals, postal, waste management and research: Tukes covers Annex II points 6 and 11-13.
  • Banking and financial market infrastructure: largely displaced by DORA, with a statutory information-exchange duty between the supervisors, Traficom and Finanssivalvonta under section 45.

Penalties & fines

The Finnish fine regime is narrower than the headline ceilings suggest, and the limits on it are the useful part. An administrative fine (hallinnollinen seuraamusmaksu) can be imposed only for four listed failures, and only where they are intentional or grossly negligent.

Essential entities

10,000,000 euros or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Entities that are not essential

7,000,000 euros or 1.4% of total worldwide annual turnover for the preceding financial year, whichever is higher.

No statutory minimum

Finland sets ceilings only. Several member states impose a floor beneath which a fine cannot fall; Finland does not, so a proportionate fine on a small entity can be genuinely small.

Section 35 - the four failures that can be fined:

  • Failing to manage risk under section 7, to draw up the operating model under section 8, or to address the section 9(1) elements within it
  • Failing to implement the measures required by section 9(2)
  • Failing to give the incident report (s.11), the interim report (s.12) or the final report (s.13)
  • Failing to give the registration data required by section 41

Anything else in the Act is enforced through orders rather than fines. Under section 34 a supervisory authority may back its decisions with a uhkasakko (conditional fine), a teettamisuhka (a threat to have the work done at your expense) or a keskeyttamisuhka (a threat of suspension).

Public bodies cannot be fined at all. Section 35(2) excludes state authorities, state enterprises, wellbeing services counties and joint counties, municipal authorities, independent public-law institutions, the offices of Parliament, the Office of the President of the Republic, and the Evangelical Lutheran Church and the Finnish Orthodox Church together with their parishes, parish unions and other bodies. They remain fully subject to the duties and to supervisory orders - the fine is what is withheld. Member states differ sharply on this: some exempt public bodies as Finland does, others fine them on a defined scale.
Section 46 - a decision binds you while you appeal it. A supervisory authority's decision must be complied with despite an appeal, unless the appellate court orders otherwise. Decisions imposing or enforcing a uhkasakko, teettamisuhka or keskeyttamisuhka follow the Act on Conditional Fines (1113/1990) instead.

The sanctions board

The authority that investigates you is not the authority that fines you. Section 36 creates a seuraamusmaksulautakunta, a sanctions board sitting in connection with Traficom. Your supervisory authority proposes the fine; the board decides it. The fine is paid to the State.

How it is composed

Traficom appoints the chair and vice-chair. Each of the seven supervisory authorities appoints one member and a personal alternate. Members are appointed for three-year terms and act independently and impartially.

What members must know

Each member must be familiar with cybersecurity risk management and with NIS2 obligations as they apply in the appointing authority's own sector. The chair and vice-chair must have sufficient legal expertise.

How it decides

Quorum is the chair or vice-chair plus at least two other members. The majority view prevails - and on a tie, the view more lenient to the entity wins.

Decisions are taken on presentation by an official of the supervisory authority whose remit the case falls in. The board may obtain the information necessary to set the fine notwithstanding secrecy provisions.

Section 37 sets the assessment. The amount rests on an overall evaluation taking account of at least:

  • the seriousness of the breach and the importance of the provisions breached - shown by repetition; failing to report or remedy significant incidents; failing to fix identified shortcomings despite the authority's decisions or warnings; obstructing an inspection or failing to commission an ordered audit; and giving false or misleading information about risk management or significant incidents
  • the duration of the breach
  • any comparable earlier breaches by the entity
  • the damage caused, including financial or economic losses, effects on other services and the number of users affected
  • the degree of intent
  • measures taken to prevent or mitigate the damage
  • adherence to approved codes of conduct or certification mechanisms
  • the entity's willingness to cooperate with the supervisory authority

When a fine is not imposed

Section 39 is drafted as a duty, not a discretion: in these cases the fine is not imposed (jatetaan maaraamatta). For most organisations this is the most practically important provision in the Act.

  • You fixed it yourself. The entity took sufficient measures on its own initiative to correct the breach immediately after detecting it, notified the supervisory authority without delay, and cooperated - and the breach is neither serious nor repeated.
  • The breach is minor.
  • A fine would be manifestly unreasonable on some other ground.

Three further bars apply:

Five-year limitation

No fine may be imposed more than five years after the breach. For a continuing breach the period runs from the day it ended.

Criminal proceedings

No fine may be imposed on a person suspected of the same act in a pre-trial investigation, in consideration of charges, or in a pending criminal case - nor on anyone already given a final judgment for it.

The GDPR bar

No fine may be imposed on an entity that has already been fined for the same act under Article 83 of the GDPR. Section 33 separately requires your supervisory authority to notify the Data Protection Ombudsman where a failure may have caused a personal-data breach.

How Finland differs

If you are running NIS2 across several member states, these are the points where Finland will not behave like your other jurisdictions.

  • There is no single regulator and no single register. Seven authorities supervise by Annex point and each keeps its own entity list. Most member states run one national register.
  • Two of the seven authorities were created on 1 January 2026, and one that pre-2026 guidance names was abolished on the same day.
  • The deadlines are relative, not calendar. One month and three months from entry into force or from meeting the criteria - so there is no national date after which registration closes.
  • The fine reaches only four duties, and only on intent or gross negligence. Many transpositions make any breach of the security obligations fineable.
  • A separate sanctions board imposes the fine, composed of one member from each supervisory authority, and ties go to the more lenient outcome.
  • Public bodies cannot be fined - including, unusually, the Evangelical Lutheran and Orthodox Churches and their parishes.
  • There is no statutory minimum fine.
  • One CSIRT, not two. Several member states split CSIRT duties between civil and government or defence teams; Finland does not.
  • Both reporting clocks run from detection, and the final-report clock can run from the close of handling instead.
  • Registration fees are set per authority, not nationally.

Finnish terms you will meet

Official guidance, filing forms and the authorities’ own correspondence use these terms. The Act has no official English translation.

FinnishEnglish
kyberturvallisuuslakithe Cybersecurity Act (124/2025)
keskeinen toimijaessential entity
toimijaluettelothe list of entities you register in
riskienhallinnan toimintamallirisk-management operating model (s.8)
merkittava poikkeamasignificant incident
ensi-ilmoitusearly warning, due in 24 hours
jatkoilmoitusincident notification, due in 72 hours
valiraportti / loppuraporttiinterim report / final report
valvova viranomainensupervisory authority
hallinnollinen seuraamusmaksuadministrative fine
seuraamusmaksulautakuntathe sanctions board (s.36)
uhkasakkoconditional fine backing an order
Kyberturvallisuuskeskusthe National Cyber Security Centre, the CSIRT and SPOC

How to prepare for NIS2 in Finland

  1. Identify which of the seven authorities supervises you - by Annex point, using the table above. Everything else follows from this, and it is where most Finnish NIS2 files go wrong.
  2. Establish your date. If you were in scope on 8 April 2025 your deadlines were 8 May and 8 July 2025. If you came into scope later, your clocks are one month and three months from that moment.
  3. File your section 41 data with that authority, including your IP address ranges, and check the fee schedule that applies to you.
  4. Put the change-notification duty on a calendar - two weeks for core data, three months for digital-infrastructure data. It is a standing obligation and it is directly fineable.
  5. Write the section 8 operating model as a document, covering all twelve section 9(2) elements, and have management approve it - the approval is the statutory act, not the drafting.
  6. Brief management to the section 10 definition: the board, the supervisory board, the managing director, and anyone who in fact directs operations.
  7. Build the reporting chain to run from detection: 24 hours, 72 hours, interim, final. Trust service providers need a 24-hour path for the second report.
  8. Prepare the section 14 customer notification in advance - who signs it off, and how fast.
  9. Document self-correction. Section 39 removes the fine where you fixed it yourself, told the authority without delay and cooperated. That defence only exists if you can evidence it.

Official links & resources

Finlex open data — consolidated text of the Cybersecurity Act 124/2025 (the authoritative current text, including all four amendments)
Lupa- ja valvontavirasto — the national authority that took over Valvira’s duties on 1 January 2026

FAQ: NIS2 in Finland

When did Finland’s NIS2 law enter into force?
On 8 April 2025 (Cybersecurity Act 124/2025). It has been amended four times since — by 369/2025 from 1 July 2025, and by 494/2025, 698/2025 and 997/2025 from 1 January 2026.
Who is my supervisory authority?
One of seven, depending on which Annex I or II point you fall under: Traficom, Energiavirasto, Tukes, Lupa- ja valvontavirasto, Elinvoimakeskus, Ruokavirasto or Fimea. See the table. There is no single national regulator for NIS2 in Finland.
Is Valvira still a NIS2 authority?
No. Valvira was dissolved on 1 January 2026 in the state administration reform, along with the regional state administrative agencies and most ELY Centres. Its duties passed to Lupa- ja valvontavirasto, and amending act 698/2025 rewrote section 26 accordingly. Guidance written before 2026 still names Valvira.
Where do I register?
With your own supervisory authority — each maintains its own toimijaluettelo. There is no single national portal. Traficom’s list covers its own sectors; Fimea, Ruokavirasto and the others run theirs.
Have I missed the registration deadline?
Probably not. Section 47 gives one month from entry into force or from when you first meet the section 3 criteria. The widely quoted 8 May 2025 date applies only to organisations already in scope on 8 April 2025. If you came into scope later, your own one-month clock applied.
How much can we be fined?
10 million euros or 2% of worldwide turnover (whichever is higher) for an essential entity; 7 million or 1.4% otherwise. But a fine is possible only for four listed failures, only where they are intentional or grossly negligent, and section 39 requires the fine to be withheld where you corrected the problem yourself and told the authority. There is no statutory minimum.
Who actually imposes the fine?
A sanctions board (seuraamusmaksulautakunta) sitting in connection with Traficom, on the proposal of your supervisory authority — so the investigating body does not decide the penalty. Each of the seven authorities appoints one member, and a tied vote goes to the more lenient outcome.
Can a public body be fined?
No. Section 35(2) exempts state and municipal authorities, wellbeing services counties, independent public-law institutions, the offices of Parliament, the Office of the President, and the Evangelical Lutheran and Orthodox Churches and their parishes. All the underlying duties and supervisory orders still apply.
What are the incident reporting deadlines?
24 hours for the ensi-ilmoitus and 72 hours for the jatkoilmoitus, both from detection; then a final report one month after the jatkoilmoitus, or one month after handling ends for a long-running incident. Trust service providers file the second report within 24 hours.
Do we have to tell our customers?
Yes. Section 14 requires you to inform service recipients without delay of a significant incident likely to impair your services, and to inform affected recipients of a significant cyber threat and the remedies available. The authority can also order publication, or publish it itself.
Information provided for general guidance; consult official national sources for updates.