NIS2 Country Guide

NIS2 Finland: Compliance, Authorities & Key Requirements

Understand how Finland implements NIS2 via the Cybersecurity Act (124/2025), which entities must register with NCSC-FI/Traficom, who supervises compliance, and what practical steps to take now.

Finland In force: 8 Apr 2025 Registration: NCSC-FI portal (ongoing)

Introduction

Finland implemented NIS2 through the Cybersecurity Act (124/2025). The National Cyber Security Centre (NCSC-FI) at Traficom is the national authority/CSIRT and operates the registration portal.

Quick link: NCSC-FI’s NIS2 overview and registration instructions.

NIS2 implementation in Finland

The Cybersecurity Act (124/2025) entered into force on 8 April 2025. NCSC-FI/Traficom provides national registration and guidance; some sectors also run their own lists (e.g., Fimea for medicines, Valvira for health/social providers).

Status

In force since 8 Apr 2025.

Registration

Register via NCSC-FI / Traficom. Sector portals may also apply (e.g., Fimea).

SectorFinnish note
Electronic communications & digital infrastructure NCSC-FI (Traficom) acts as competent authority/CSIRT and SPOC, including incident channels and guidance.
Medicines (pharma supply) Fimea maintains a NIS2 entity list and sector guidance (e-service active).
Health & social welfare Valvira provides sector guidance and runs the list for covered operators.

What you need to know about compliance & certification

Finland follows the NIS2 two-tier model (Essential / Important) with Article 21 risk-management measures and national reporting via NCSC-FI.

Scope criteria

  • Operate in an Annex I/II sector and meet size thresholds (≥50 employees or ≥€10m), or be otherwise designated.
  • Established in Finland or providing relevant services on Finnish territory.

Obligations

  • Risk management & security policy (IT/OT)
  • Incident handling & reporting to NCSC-FI
  • Business continuity & crisis management
  • Supply-chain security & vendor risk
  • Access control, segmentation, encryption
  • Executive accountability & training

Standards & alignment

Map controls to ISO/IEC 27001:2023, NIST CSF 2.0, and NCSC-FI guidance/notification thresholds.

Incident reporting: Use NCSC-FI’s national incident channels and thresholds for notification.

Competent authorities & CSIRT

NCSC-FI (Traficom) leads as national authority/CSIRT/SPOC; sector agencies cooperate in their domains.

RoleAuthorityNotes
National competent authority / CSIRT / Single Point of ContactNational Cyber Security Centre Finland (NCSC-FI), TraficomRegistration portal, guidance, incident notification and CSIRT operations.
Medicines sectorFimea (Finnish Medicines Agency)Sector list & registration e-service.
Health & social welfareValviraSector guidance and operator list under the Cybersecurity Act.

National NIS2 timeline & key dates

27 Dec 2022 — NIS2 published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline for Member States.
8 Apr 2025 — Finland’s Cybersecurity Act (124/2025) enters into force.

Deadlines (Finland)

DateWhatWho
8 May 2025 Register in the list of essential/important entities. All in-scope entities (general national deadline).
8 May 2025 Register in sector list. Health & social welfare operators (Valvira).
8 Jul 2025 Have a documented cybersecurity risk-management operating model in place. All essential/important entities.
From Apr–Jun 2025 Sector registration available; e-service live. Medicines sector (Fimea).

Missed a date? Register and implement without delay; authorities expect active progress.

Sector-specific requirements (Finland)

  • Electronic communications & digital infrastructure: NCSC-FI provides guidance and supervises, with incident channels via CSIRT.
  • Medicines: Fimea coordinates sector registration (e-service available; interim processes replaced).
  • Health & social welfare: Valvira guidance aligns NIS2 minimum obligations for covered operators.

Penalties for non-compliance

Under the Cybersecurity Act, supervisory powers and enforcement measures aligned with NIS2, including remedial orders, administrative fines and enhanced supervisory measures. The practical applications may vary depending on the sector and the competent authority.

How to prepare for NIS2 in Finland

  1. Determine scope: confirm Annex I/II services and size thresholds; classify EE/IE.
  2. Register: complete NCSC-FI registration (and any sector list such as Fimea/Valvira).
  3. Governance: board-level accountability and oversight.
  4. Risk management: align with ISO 27001 / NIST CSF and NCSC-FI guidance.
  5. Supply chain: assess MSPs/MSSPs and critical suppliers; contract for security.
  6. Incident readiness: set 24/7 detection, escalation and CSIRT notification playbooks.
  7. Continuity & crisis: document BCP/DR; test and exercise.
  8. Train & prove: executive training, awareness, and auditable evidence.

Official links & resources

FAQ: NIS2 in Finland

When did Finland’s NIS2 law enter into force?
On 8 April 2025 (Cybersecurity Act 124/2025).
Where do I register?
Register via the NCSC-FI/Traficom portal; sector lists may also apply (e.g., Fimea for medicines, Valvira for health/social).
Who is the competent authority?
NCSC-FI (Traficom) is Finland’s national competent authority/CSIRT/SPOC for NIS2.
Information provided for general guidance; consult official national sources for updates.