> Does NIS2 apply to your company? A quick test
> Lähde: https://developit.fi/en/services/security/does-nis2-apply/
> Koko sivusto koneluettavana: https://developit.fi/llms-full.txt

developit // turva

# Does NIS2 apply to your company?
The law requires companies to find this out for themselves — this test gives you a direction

The Cybersecurity Act brought the NIS2 obligations to Finland on 8 April 2025, and no authority sends a letter: every organisation has to find out for itself whether it falls within the scope of the law. Three questions tell you which way your situation leans.

The result is indicative, not legal advice. Nothing is stored or sent anywhere — the reasoning happens in your browser.

## Three questions
 01 Does your company operate in one of these sectors?Energy, transport, banking and finance, healthcare, water supply, digital infrastructure and ICT service management, postal and courier services, waste management, food, chemicals, or manufacturing.

 Yes No I’m not sure 
 02 Does your company exceed the size threshold?At least 50 employees, or annual turnover and balance sheet total both over 10 million euros.

 Yes No 
 03 Does your company provide digital infrastructure services to others?Certain services, for example domain name and trust services, fall within the scope of the law regardless of company size.

 Yes No 

Result

Applies

### Your company falls within the scope of the law
Your sector is covered by the law and the size threshold is exceeded, so the Cybersecurity Act applies to your company. The next steps: registering in the list of entities, a management-approved risk management framework and an incident reporting process with its deadlines.

Applies

### Your services bring your company within the scope of the law — regardless of size
Digital infrastructure services such as domain name and trust services fall within the scope of the law regardless of company size. The obligations are the same as for larger companies: the list of entities, a risk management framework and incident reporting.

Does not apply

### Your company does not fall within the scope of the law
Based on your answers, the law does not obligate your company. Two things are still worth keeping in mind: the situation needs to be checked again if you grow past the size threshold — and customers of yours who fall within the scope of the law may require similar security practices in their contracts.

Maybe

### The result depends on the sector definition
Your other answers are clear — the only open question is whether your sector is on the law’s list. The National Cyber Security Centre’s sector list gives the answer, or we can go through it together. After that, the result is unambiguous.

The result is based on your answers and is not legal advice — in borderline cases, the matter is confirmed by the supervisory authority for your sector.

 Let’s look at your situation together Read our NIS2 article 

## What is this based on?
The Cybersecurity Act came into force on 8 April 2025 and brought the obligations of the EU’s NIS2 directive to Finland. It covers sectors that are critical and important for the functioning of society, and it obligates the medium-sized and large organisations operating in them to manage their cyber risks systematically.

The test questions follow the scope of the law: the sector list and the size threshold come from the guidance of the National Cyber Security Centre and Traficom. The exact sources are at the end of our NIS2 article.

## Unsure about the result?
We’ll work out your situation and help you meet the obligations: the risk management framework, monitoring and the incident reporting process.

 Get in touch Our security services
