Kybermittari — Cybermeter
NIS2 says what you must achieve, never how you demonstrate it. Finland answers with Kybermittari. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Kybermittari is a self-assessment instrument published by the authority, not a certification scheme and not a legal requirement. A completed assessment evidences that you have measured yourself against a recognised model — it does not certify anything, and it does not by itself demonstrate NIS2 compliance.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the certifiable route in Finland; Kybermittari is commonly used alongside it to direct effort rather than to replace it.
What it is built on
Kybermittari does not invent its own taxonomy. It sits on The US Department of Energy Cybersecurity Capability Maturity Model (C2M2) and the NIST Cybersecurity Framework.
Kybermittari is a capability maturity assessment rather than a control checklist: an organisation scores its own practices by domain and by maturity indicator level, then works the gaps. It was built for critical infrastructure operators but the authority presents it as suitable for any size and sector.
How it covers article 21(2)
Kybermittari follows the ten domains of the DoE Cybersecurity Capability Maturity Model, each assessed across maturity indicator levels MIL 0 to MIL 3.
Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target.
| Art. 21(2) | Measure | Kybermittari — C2M2 domain |
|---|---|---|
| (a) | Risk analysis and security policies | RISK PROGRAM |
| (b) | Incident handling | RESPONSE SITUATION |
| (c) | Business continuity | RESPONSE ARCHITECTURE |
| (d) | Supply chain security | THIRD-PARTIES |
| (e) | Security in acquisition, development and maintenance | THREAT ARCHITECTURE |
| (f) | Assessing the effectiveness of the measures | PROGRAM RISK |
| (g) | Basic cyber hygiene and cybersecurity training | WORKFORCE |
| (h) | Cryptography and encryption | ARCHITECTURE |
| (i) | Human resources security, access control and asset management | ACCESS ASSET WORKFORCE |
| (j) | Multi-factor authentication and secured communications | ACCESS ARCHITECTURE |
10 C2M2 domain units, in full
- ASSET — Asset Management
- THREAT — Threat and Vulnerability Management
- RISK — Risk Management
- ACCESS — Identity and Access Management
- SITUATION — Situational Awareness
- RESPONSE — Event and Incident Response, Continuity of Operations
- THIRD-PARTIES — Third-Party Risk Management
- WORKFORCE — Workforce Management
- ARCHITECTURE — Cybersecurity Architecture
- PROGRAM — Cybersecurity Program Management
What you already have, for the same measure
Nobody in scope starts from nothing. Kybermittari is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | Kybermittari | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | RISK PROGRAM | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | RESPONSE SITUATION | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | RESPONSE ARCHITECTURE | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | THIRD-PARTIES | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | THREAT ARCHITECTURE | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | PROGRAM RISK | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | WORKFORCE | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | ARCHITECTURE | 8.24 | SC |
| (i) HR, access, assets | ACCESS ASSET WORKFORCE | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | ACCESS ARCHITECTURE | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
We are not affiliated with Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland. Kybermittari and related marks belong to their owners.