NIS2 · National implementation

NIS2 in Finland

Finland transposed NIS2 through the Kyberturvallisuuslaki (124/2025), in force since 8 April 2025.

National law
Kyberturvallisuuslaki (124/2025)
Cybersecurity Act
Status
In force
In force
8 April 2025
Authority
Traficom / NCSC-FI and sector regulators

Supervision

Finland uses a decentralised model: Traficom (via its National Cyber Security Centre, NCSC-FI) is the general authority and CSIRT, while sector regulators supervise their own sectors. Entities register through Traficom's notification service.

What is specific to Finland

The Finnish act deliberately avoids gold-plating and stays close to the directive's minimums, with risk-management detail in a government decree. NCSC-FI's long-running incident cooperation culture means voluntary reporting and assistance are well developed; the same channels now carry the mandatory three-stage reports.

Official sources

Primary references: the national statute book at www.finlex.fi and the national cybersecurity authority at www.kyberturvallisuuskeskus.fi.

NIS2 in Finland: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states