Directive NIS2 European Union
Kybermittari

Kybermittari — Cybermeter

NIS2 says what you must achieve, never how you demonstrate it. Finland answers with Kybermittari. If you operate there, this is what your regulator reads.

Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Kybermittari is a self-assessment instrument published by the authority, not a certification scheme and not a legal requirement. A completed assessment evidences that you have measured yourself against a recognised model — it does not certify anything, and it does not by itself demonstrate NIS2 compliance.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the certifiable route in Finland; Kybermittari is commonly used alongside it to direct effort rather than to replace it.

What it is built on

Kybermittari does not invent its own taxonomy. It sits on The US Department of Energy Cybersecurity Capability Maturity Model (C2M2) and the NIST Cybersecurity Framework.

Kybermittari is a capability maturity assessment rather than a control checklist: an organisation scores its own practices by domain and by maturity indicator level, then works the gaps. It was built for critical infrastructure operators but the authority presents it as suitable for any size and sector.

Mapping

How it covers article 21(2)


Basis

Kybermittari follows the ten domains of the DoE Cybersecurity Capability Maturity Model, each assessed across maturity indicator levels MIL 0 to MIL 3.

Limit of this mapping

Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target.

Mapped at the level of
C2M2 domain
Units in the framework
10
Units carrying article 21(2)
10
Each of the ten risk-management measures of article 21(2), mapped to the C2M2 domain units of Kybermittari
Art. 21(2) Measure Kybermittari — C2M2 domain
(a) Risk analysis and security policies RISK PROGRAM
(b) Incident handling RESPONSE SITUATION
(c) Business continuity RESPONSE ARCHITECTURE
(d) Supply chain security THIRD-PARTIES
(e) Security in acquisition, development and maintenance THREAT ARCHITECTURE
(f) Assessing the effectiveness of the measures PROGRAM RISK
(g) Basic cyber hygiene and cybersecurity training WORKFORCE
(h) Cryptography and encryption ARCHITECTURE
(i) Human resources security, access control and asset management ACCESS ASSET WORKFORCE
(j) Multi-factor authentication and secured communications ACCESS ARCHITECTURE
10 C2M2 domain units, in full
  • ASSET — Asset Management
  • THREAT — Threat and Vulnerability Management
  • RISK — Risk Management
  • ACCESS — Identity and Access Management
  • SITUATION — Situational Awareness
  • RESPONSE — Event and Incident Response, Continuity of Operations
  • THIRD-PARTIES — Third-Party Risk Management
  • WORKFORCE — Workforce Management
  • ARCHITECTURE — Cybersecurity Architecture
  • PROGRAM — Cybersecurity Program Management
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. Kybermittari is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to Kybermittari and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) Kybermittari ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis RISK PROGRAM 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling RESPONSE SITUATION 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity RESPONSE ARCHITECTURE 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain THIRD-PARTIES 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development THREAT ARCHITECTURE 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness PROGRAM RISK 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training WORKFORCE 5.37 6.3 8.7 AT SI CM
(h) Cryptography ARCHITECTURE 8.24 SC
(i) HR, access, assets ACCESS ASSET WORKFORCE 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms ACCESS ARCHITECTURE 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Sources

We are not affiliated with Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland. Kybermittari and related marks belong to their owners.

Cart 0