ArticlesInformation security and audits
NIS2 is now law in Finland: does it apply to your company, and what does the supervisor expect?
4 August 2026 · 5 min read

The EU’s NIS2 directive entered into force in Finland as the Cybersecurity Act on 8 April 2025. The law requires thousands of companies to manage their cybersecurity more systematically than before, and supervision is now fully underway. This article explains whether the law applies to your company and what it requires in practice.
What are NIS2 and the Cybersecurity Act?
NIS2 is an EU directive that aims to establish a consistent level of cybersecurity across the union. In Finland it was implemented through the Cybersecurity Act, whose obligations took effect on 8 April 2025. The law covers sectors that are critical or important to the functioning of society, and it requires the organisations operating in them to manage their cyber risks and to report significant security incidents to the authorities.
Supervision is divided by sector: Traficom, for example, oversees digital infrastructure and transport, the Energy Authority oversees the energy sector, and the Financial Supervisory Authority oversees the financial sector. Traficom’s National Cyber Security Centre acts as the national single point of contact and receives incident reports.
Does the law apply to your company?
Two things decide it: sector and size. The sectors covered by the law include energy, transport, banking and finance, healthcare, water supply, digital infrastructure and digital services, postal services, waste management, food, chemicals and parts of the manufacturing industry.
The size threshold is a medium-sized enterprise: as a rule, the law applies to an entity with at least 50 employees, or whose annual turnover and balance sheet total both exceed 10 million euros. Smaller companies generally fall outside the scope, although certain services are covered regardless of size. In a borderline case, it is worth checking directly against the Cybersecurity Act or asking the supervisory authority for your sector.
An important detail: no one will send you a letter telling you that the law applies to your company. Every entity has an independent duty to determine whether it falls within the scope of the law and to register in the list of entities kept by its own supervisory authority. The first registration deadline was 8 May 2025, and an entity must register as soon as the law begins to apply to it. Changes must be reported within two weeks.
What obligations does the law bring?
The core of the law is a cybersecurity risk management framework. This means a documented whole in which the company identifies the cyber risks of its operations and implements protective measures proportionate to them. Proportionality is the key word here: a small entity is not expected to have the security organisation of a large corporation, but rather a level that is sensible in relation to its operations and risks. The law lists minimum measures, which include access management, backups, supply chain security, incident handling and staff training.
The second key obligation is incident reporting. A significant security incident must be reported to the National Cyber Security Centre with an initial notification within 24 hours of detection, a more detailed follow-up notification within 72 hours, and a final report once the incident has been handled.
The third is management responsibility: top management approves the risk management framework and oversees its implementation, and this responsibility cannot be outsourced. Neglect can result in an administrative fine of up to 10 million euros or 2 per cent of worldwide turnover for essential entities, and up to 7 million euros or 1.4 per cent of turnover for other entities.
What does the supervisor expect right now?
The transition period is over, so the supervisory authorities expect the basics to be in place: the company has registered in the list of entities, the risk management framework has been drawn up and put into use, and the incident reporting process works within the deadlines. In practice, it is worth making sure that the framework is genuinely documented and approved by management, that the minimum measures have been gone through point by point, and that staff know who to notify about an incident and how the 24-hour deadline is met.
A good test is to ask yourself: if we detected ransomware today, would the organisation know what to do and who to notify within 24 hours?
The importance of documentation should not be underestimated. From the supervisor’s point of view, a measure that has not been recorded is a measure that has not been taken. Risk assessments, descriptions of protective measures, training attendance lists and exercise notes are the material with which a company demonstrates that it has met its obligations. Even lightweight documentation is enough, as long as it is up to date and reflects reality.
What if the law doesn’t apply to your company?
Many small and medium-sized companies fall outside the law based on the size threshold or their sector, but the requirements still flow down the supply chain. Customers covered by the law must take care of the security of their supply chain, so they ask their subcontractors the same questions: how are access management, backups and incident handling taken care of. The same basic measures protect your company in any case, law or no law.
Where to start?
If you are not sure whether the Cybersecurity Act applies to your company, or whether the basics it requires are in place, a light assessment can settle the matter. Developit’s security services go through your company’s situation, help you draw up a risk management framework and put the technical protections in order in a sensible sequence. That way you meet your obligations and sleep soundly.
You can also get a sense of direction with three questions: test whether NIS2 applies to your company.
Read next
Consulting and business developmentFrom Excel to a System: Automating Processes Without a Giant ProjectRead the article
AI and automationAI in business 2026: the AI Act's rules of the game and where the real benefits areRead the article
Websites and graphic designIs your company found in AI search? The new visibility game for websitesRead the article