Skip to main content

Guide for management: EU NIS2.0 cybersecurity directive and national Cybersecurity Act in Finland

Jimmi Henvig and Lilian Stenholt standing outside by the railing
Author(s):
Ahonen Eve 900x1200.jpg
Eve Ahonen
Consultant

Introduction

The EU’s NIS2 Directive is now part of everyday business in Finland. In many organisations, the conversation has already moved from “how do we prepare?” to “can we prove we are doing the right things?” In practice, the question is whether the organisation can show that risk management, incident preparedness, and management responsibilities are actually in place.

NIS2 sets the background and overall framework for cybersecurity regulation, but organisations in Finland do not comply with NIS2 directly. Their obligations come from Finland’s Cybersecurity Act (124/2025, in force since 8 April 2025) and from the guidance issued by the relevant supervisory authorities. This blog gives a practical overview of the Finnish Act: who it applies to, what organisations need to do, and where to find reliable official information.

In short: four messages for the management

The law is already in force.

This is no longer a preparation or development phase; several obligations already apply. If registration in the entity list or the risk management model is still missing, those gaps should be fixed quickly.

Top management is responsible.

The Act does not leave cybersecurity to IT, the security team, or individual employees. Management approves the risk management measures, monitors implementation, and makes sure cybersecurity has enough resources. Management also needs to make sure it understands cybersecurity and how it should be managed.

Supply chain management matters more than ever.

Cloud services and AI technologies create new dependencies. Knowing your subcontractors and keeping contracts up to date are part of statutory preparedness, also for organisations that are not directly covered by NIS2 or the Cybersecurity Act.

This is about business continuity.

Good cybersecurity strengthens customer trust and helps the business keep running when something goes wrong. The threats are real and varied, but in many cases the requirements can be met with solid basic measures.

/

Meeting cybersecurity requirements is mostly about good management and workable processes. The right tools and technology can make implementation faster and stronger.

Eve Ahonen
Consultant

Does the law apply to us?

The organisation itself is responsible for identifying whether it falls within the scope of the law and for registering in the entity list. The six questions below help you assess whether the Act applies and what obligations follow.

1. Does your organisation operate in one of the sectors listed in Annex I or Annex II?

Annex I: Energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Annex II: Postal and courier services, waste management, chemicals, food, digital providers, manufacture of vehicles and other transport equipment, research organisations, manufacture of medical devices, electronics, electrical equipment, and machinery, online marketplaces, search engines, and social networking platforms.

The annexes often refer to very specific definitions, such as NACE classifications or sector-specific laws. Check your own activities against those definitions, not just based on a gut feeling.

Did you find your sector? Yes 👉 Continue to the next question.

No match? Jump straight to question 4.

2. Does your organisation meet the size criterion?

The law applies to organisations with at least 50 employees, or with annual turnover and balance sheet total exceeding EUR 10 million. In other words, check whether your organisation meets or exceeds the threshold for a medium-sized entity.

The size criterion is calculated for the whole undertaking, not just for the regulated part of the business. Group structures, ownership links, partner-enterprise relationships, and the municipality’s role as owner or operator may also affect the assessment.

Is either criterion met? Yes 👉 The law applies to you.

3. Are you covered regardless of size?

Some organisations fall within scope no matter their size. This includes providers of public electronic communications networks and services, trust service providers, top-level domain registries, and DNS service providers. It can also include Annex I or II entities that are the sole provider of a service critical to society, or whose disruption would have a major impact on public order, safety, or health, or be critical at national or regional level.

Answer: Yes 👉 The law applies to you.

4. Has your organisation been designated as a CER critical entity?

Under the new CER Act (310/2025), critical entities are designated by the ministry responsible for the relevant sector.

Answer: Yes 👉 The law applies to you.

Your organisation may have moved into the strictest supervisory category even if nothing changed in your own operations. Check this with the ministry or supervisory authority responsible for your sector.

5. Does any exception apply to your activities?

Section 4 of the Act includes several exclusions. These include activities provided for defence, national security, public order and safety, or crime prevention; certain financial-sector entities to which DORA does not apply; Annex I or II activities that are occasional and minor; and municipalities, for which the Act applies only to Annex I or II activities.

Answer: No 👉 The law applies to you.

6. essential or important entity?

Once you have assessed whether the Act applies, the final question is what category you fall into: essential or important entity? 👉 Essential entities include Annex I entities that exceed the medium-sized enterprise thresholds, qualified trust service providers, top-level domain registries, and DNS service providers, and entities covered under section 3(3). Other entities are important entities.

If you are within scope, the clock is already ticking. Registration in the entity list was due by 8 May 2025, and the risk management model by 8 July 2025. If the criteria are met only now, e.g., because of growth, a restructuring, or a CER designation, you must register within one month and prepare the model within three months of meeting the criteria.

If you are not within scope, it is still worth revisiting the situation again every year and whenever the organisation changes. Obligations may also reach you through customer contracts and supply chain requirements, even if the Act does not directly apply to your organisation.

If you are unsure, ask the supervisory authority for your sector. The authorities have published sector-specific guidance and FAQ pages specifically for this purpose.

Supervision in Finland is sector-specific. If you operate in more than one sector, register separately with each competent authority. Your sector’s supervisory authority can help in unclear situations. Transport and Communications Agency’s (Traficom) NIS2 info page also brings together information on the competent authorities.

Who supervises?

  • Traficom / National Cyber Security Centre (Kyberturvallisuuskeskus in finnish)

    Sector of responsibility: Digital infrastructure, ICT service management, transport, digital services, public administration, space, postal and courier services, research, vehicle manufacturing; also acts as the single point of contact and CSIRT.

  • Energy Authority (Energiavirasto in finnish)

    Sector of responsibility: Energy; confirm the product-group-specific competent authority where necessary.

  • Financial Supervisory Authority (Finanssivalvonta in finnish)

    Sector of responsibility: Banking and financial market infrastructures; note the primacy of DORA where applicable.

  • Finnish Supervisory Agency (Lupa- ja valvontavirasto, ex Valvira in finnish)

    Sector of responsibility: Social and healthcare services, waste management.

  • Finnish Medicines Agency (Fimea in finnish)

    Sector of responsibility: Manufacture and supply of medicines and medical devices, medicinal research and development, blood establishments, pharmacies.

  • Economic Development Centre (Elinvoimakeskus in finnish)

    Sector of responsibility: Drinking water, wastewater.

  • Finnish Safety and Chemicals Agency (Tukes in finnish)

    Sector of responsibility: Manufacture, production and distribution of chemicals; manufacture of electronics, electrical equipment and machinery.

  • Finnish Food Authority (Ruokavirasto in finnish)

    Sector of responsibility: Food production, processing and distribution; wholesale of food.

What is required in practice?

The Cybersecurity Act is built around risk-based management. In practice, this means choosing technical and organisational measures that match the risks in your organisation’s core activities. A good starting point is to break the obligations into smaller parts and make sure the basics are covered first.

1. Strategic level

  • Decide whether the law applies to you. The organisation itself is responsible for identifying whether it is within scope.

  • Make sure management understands cybersecurity. According to Traficom’s recommendation, this should be built through regular training or equivalent measures; one webinar is not enough.

  • Define risk appetite, acceptable residual risks, and risk management principles. The law requires continuity, backups, and crisis management; however, the target level is set by management, not the technical team.

  • Decide what cybersecurity training is needed and make sure there are enough resources and budget. Management is responsible for the direction, resourcing, and follow-up of competence development.

2. Administrative level

  • Register in the entity list and keep the information up to date. Registration is made with the supervisory authority for the relevant sector, or with several authorities if you operate in more than one sector.

  • Prepare a risk management model. Writing out the section 9 measures of the Cybersecurity Act, keeping the model up to date, basing it on a model such as an ISMS, and approving and reviewing it every year is one of the most cost-effective compliance investments.

  • Bring the obligations into contracts. List critical suppliers, assess their risks, and include at least incident notification obligations measured in hours, audit rights, supply-chain transparency, and exit clause.

  • Make sure incident preparedness and the 24h/72h/one-month reporting process are clear. Define incident communications and roles in advance: who notifies the authority, who informs customers, and who handles media communications.

  • Build a security culture and train personnel. Personnel security and cyber hygiene are statutory minimum measures and part of risk management.

3. Operational level

  • Make sure the basic controls are in place: multi-factor authentication, access management, encryption, backups, updates, asset management, physical environment, and facility security, all proportionate to your organisation’s activities and risks.

  • Build a detection process and incident classification. Agree who makes the classification decision, what criteria they use, and also document decisions not to notify.

  • Practise regularly. A two-hour tabletop exercise once a year can reveal more than a hundred-page plan.

4. Avoid overlaps

The law requires significant cybersecurity incidents to be reported to the supervisory authority (articles 11-15).

The same event may also be a personal data breach under the GDPR, which triggers two separate notification obligations to different authorities and with different deadlines: Traficom/CSIRT and the Data Protection Ombudsman. In the financial sector, DORA is supervised by the Financial Supervisory Authority, and its ICT risk management and reporting requirements take priority over the corresponding obligations in the Cybersecurity Act.

That is why it makes sense to build one clear incident classification and management model, instead of separate processes for each obligation. This cuts down duplicate work and helps make sure all notifications are processed on time.

How Context& and Microsoft solutions support compliance

Meeting cybersecurity requirements is mostly about good management and workable processes. The right tools and technology can make implementation faster and stronger, but they do not replace clear ownership and decision-making. Sometimes more documentation is needed; sometimes simply better decisions, smoother processes, and the ability to keep operating during disruptions. We work with cybersecurity on three levels:

Strategic security

  • NIS2 applicability assessment and entity classification

  • Cybersecurity governance model and definition of management responsibilities

  • Risk appetite, risk-based roadmap, cybersecurity target state, and investment prioritisation

Administrative security

  • Risk management operating model and security policies

  • ISMS implementation and development, and consulting on meeting Cybersecurity Act requirements

  • Incident management process and reporting procedure

  • Supply chain management and contractual clauses

  • Management and personnel training programmes in Finnish and English

Operational security

  • Access management and MFA (Microsoft Entra ID, PIM)

  • Threat detection and incident handling (Microsoft Defender, Sentinel)

  • Information protection and insider risks (Microsoft Purview: DLP, Information Protection, Insider Risk Management)

  • Device and network management (Microsoft Intune, Defender for Endpoint)

  • Continuity and backup (Azure Backup, Site Recovery)

  • Incident exercise testing whether the 24-hour notification chain works in practice

Information needs to move between all levels, in every direction. We help clarify roles and responsibilities and put the necessary measures in place in a way that is practical, proportionate, and fit for purpose.

Read more:

icon
Blog

Guide for management: EU NIS2.0 cybersecurity directive and national Cybersecurity Act in Finland

icon
Blog

How to Protect Your Business from Emerging Social Engineering Cyberthreats?

icon
Blog

Multichannel Social Engineering: The Next Evolution of Cyber Threats

icon
Blog

Microsoft 365 E7 – what’s included in the new premium package, and is it worth it?