Skip to main content
NIS2 · FINLAND

NIS2 in Finland — an early transposition, sectoral registration, and the NCSC-FI inside Traficom.

Finland transposed early: the Kyberturvallisuuslaki (124/2025) entered into force on 8 April 2025, with registration due to each entity's sectoral supervisor by 8 May 2025 — a four-week window, among the shortest in the Union. Traficom, the transport and communications agency, anchors the regime, with the National Cyber Security Centre Finland (NCSC-FI) as national CSIRT inside it; sectoral supervisors — the Energy Authority, the Finnish Food Authority and others — hold their own sectors.

The distinctive part is the registration model: rather than one national portal, entities registered with whichever authority supervises their sector. Groups with activities in several sectors answered to more than one supervisor from day one — a structure that rewards holding the entity-to-supervisor mapping as a managed record.

Who it applies to

Essential and important entities across the NIS2 sectors, registered with their sectoral supervisor — Traficom for most digital sectors; the Energy Authority, the Food Authority and other sector supervisors for theirs — by 8 May 2025, with entities crossing thresholds later registering without delay. Incident reporting runs the directive's three stages: 24 hours, 72 hours, one month.

The clock

Competent authority: Traficom and sectoral supervisors · NCSC-FI as national CSIRT. Transposition: Kyberturvallisuuslaki 124/2025.

NIS2 in Finland · timeline
WhenWhat happens
8 Apr 2025Kyberturvallisuuslaki 124/2025 enters into force
8 May 2025Registration deadline with each sectoral supervisor
OngoingIncident reporting to NCSC-FI · 24 h, 72 h, one month
OngoingSectoral supervision by Traficom, the Energy Authority and other sector supervisors

One law, many registrars

Finland distributed NIS2 registration across the supervisory landscape: an energy company registered with the Energy Authority (Energiavirasto), a food-sector entity with the Finnish Food Authority (Ruokavirasto), most digital sectors with Traficom — each supervisor receiving its own sectors' registrations against the same four-week window that closed on 8 May 2025. The NCSC-FI sits inside Traficom as national CSIRT, a converged-regulator model that predates NIS2. For multi-sector groups this makes the supervisor mapping itself compliance infrastructure: TruSecure holds each entity's supervisor, CSIRT routing and sectoral obligations as records, so evidence and reports go to the right authority per entity — not to whichever one the team remembers.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Finland transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Finland requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with your sectoral supervisor — or now, if lateEntity profile · supervisor resolved per sector, registration facts held as records
Meet the security-measures duty with evidence on demandControl library · continuously monitored, evidence attached
Report significant incidents to NCSC-FI: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Show management-body oversight and trainingGovernance workspace · approvals and training records, dated
Answer sectoral supervision with evidenceSupervision export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Finland NIS2 readiness file · excerptSample data
Registration
Traficom · filed 28 Apr 2025
Sectoral supervisor
confirmed · digital infrastructure
Controls evidenced
91/107 · 16 open, each with an owner and a date
Incident reports
3 filed · all within statutory timeframes
Export
sealed · sha256:4a7e...9c2d

Where teams usually start

With a demo walked through by TruSecure — your sectoral supervisor confirmed, the controls you already operate mapped against the Kyberturvallisuuslaki, and a sample incident run against the reporting clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Finland by Traficom and sectoral supervisors · NCSC-FI as national CSIRT. TruSecure determines applicability against Finland's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Why is Finland's telecom regulator also its cybersecurity authority?
Traficom combined telecom regulation and national cybersecurity oversight (as NCSC-FI) before NIS2 existed — Finland extended that existing structure rather than standing up a separate agency.