NIS2 in Finland — an early transposition, sectoral registration, and the NCSC-FI inside Traficom.
Finland transposed early: the Kyberturvallisuuslaki (124/2025) entered into force on 8 April 2025, with registration due to each entity's sectoral supervisor by 8 May 2025 — a four-week window, among the shortest in the Union. Traficom, the transport and communications agency, anchors the regime, with the National Cyber Security Centre Finland (NCSC-FI) as national CSIRT inside it; sectoral supervisors — the Energy Authority, the Finnish Food Authority and others — hold their own sectors.
The distinctive part is the registration model: rather than one national portal, entities registered with whichever authority supervises their sector. Groups with activities in several sectors answered to more than one supervisor from day one — a structure that rewards holding the entity-to-supervisor mapping as a managed record.
Who it applies to
Essential and important entities across the NIS2 sectors, registered with their sectoral supervisor — Traficom for most digital sectors; the Energy Authority, the Food Authority and other sector supervisors for theirs — by 8 May 2025, with entities crossing thresholds later registering without delay. Incident reporting runs the directive's three stages: 24 hours, 72 hours, one month.
The clock
Competent authority: Traficom and sectoral supervisors · NCSC-FI as national CSIRT. Transposition: Kyberturvallisuuslaki 124/2025.
| When | What happens |
|---|---|
| 8 Apr 2025 | Kyberturvallisuuslaki 124/2025 enters into force |
| 8 May 2025 | Registration deadline with each sectoral supervisor |
| Ongoing | Incident reporting to NCSC-FI · 24 h, 72 h, one month |
| Ongoing | Sectoral supervision by Traficom, the Energy Authority and other sector supervisors |
One law, many registrars
Finland distributed NIS2 registration across the supervisory landscape: an energy company registered with the Energy Authority (Energiavirasto), a food-sector entity with the Finnish Food Authority (Ruokavirasto), most digital sectors with Traficom — each supervisor receiving its own sectors' registrations against the same four-week window that closed on 8 May 2025. The NCSC-FI sits inside Traficom as national CSIRT, a converged-regulator model that predates NIS2. For multi-sector groups this makes the supervisor mapping itself compliance infrastructure: TruSecure holds each entity's supervisor, CSIRT routing and sectoral obligations as records, so evidence and reports go to the right authority per entity — not to whichever one the team remembers.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Finland transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with your sectoral supervisor — or now, if late | Entity profile · supervisor resolved per sector, registration facts held as records |
| Meet the security-measures duty with evidence on demand | Control library · continuously monitored, evidence attached |
| Report significant incidents to NCSC-FI: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Show management-body oversight and training | Governance workspace · approvals and training records, dated |
| Answer sectoral supervision with evidence | Supervision export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Registration
- Traficom · filed 28 Apr 2025
- Sectoral supervisor
- confirmed · digital infrastructure
- Controls evidenced
- 91/107 · 16 open, each with an owner and a date
- Incident reports
- 3 filed · all within statutory timeframes
- Export
- sealed · sha256:4a7e...9c2d
Where teams usually start
With a demo walked through by TruSecure — your sectoral supervisor confirmed, the controls you already operate mapped against the Kyberturvallisuuslaki, and a sample incident run against the reporting clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Finland by Traficom and sectoral supervisors · NCSC-FI as national CSIRT. TruSecure determines applicability against Finland's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.