Directive NIS2 European Union
FI · Member state

NIS2 in Finland


What binds you in Finland is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
Traficom
National CSIRT
VAT on your purchase
25.5%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


National law

Kyberturvallisuuslaki (124/2025)

In force

Finland missed the 17 October 2024 deadline; the Act was passed in March 2025. Identity confirmed against Finlex, the official statute collection.

National assessment framework

Kybermittari — Cybermeter — Kybermittari

by Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland. Built on The US Department of Energy Cybersecurity Capability Maturity Model (C2M2) and the NIST Cybersecurity Framework.

Finland spread supervision across sector-specific authorities rather than concentrating it in one regulator, so which body supervises you depends on your sector. Kybermittari is the assessment instrument the national centre publishes; it is not mandatory.

A label is not compliance

Kybermittari is a self-assessment instrument published by the authority, not a certification scheme and not a legal requirement. A completed assessment evidences that you have measured yourself against a recognised model — it does not certify anything, and it does not by itself demonstrate NIS2 compliance.

Kybermittari in full — levels, controls and what it does not cover →

Who supervises you

Traficom is the competent authority designated by Finland. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to NCSC-FI, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Finland legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0