Skip to content

developit // turva

Does NIS2 apply to your company?

The law requires companies to find this out for themselves — this test gives you a direction

The Cybersecurity Act brought the NIS2 obligations to Finland on 8 April 2025, and no authority sends a letter: every organisation has to find out for itself whether it falls within the scope of the law. Three questions tell you which way your situation leans.

The result is indicative, not legal advice. Nothing is stored or sent anywhere — the reasoning happens in your browser.

Three questions

01Does your company operate in one of these sectors?

Energy, transport, banking and finance, healthcare, water supply, digital infrastructure and ICT service management, postal and courier services, waste management, food, chemicals, or manufacturing.

02Does your company exceed the size threshold?

At least 50 employees, or annual turnover and balance sheet total both over 10 million euros.

03Does your company provide digital infrastructure services to others?

Certain services, for example domain name and trust services, fall within the scope of the law regardless of company size.

What is this based on?

The Cybersecurity Act came into force on 8 April 2025 and brought the obligations of the EU’s NIS2 directive to Finland. It covers sectors that are critical and important for the functioning of society, and it obligates the medium-sized and large organisations operating in them to manage their cyber risks systematically.

The test questions follow the scope of the law: the sector list and the size threshold come from the guidance of the National Cyber Security Centre and Traficom. The exact sources are at the end of our NIS2 article.

Unsure about the result?

We’ll work out your situation and help you meet the obligations: the risk management framework, monitoring and the incident reporting process.

Get in touchOur security services

Security moment

Well then. It said “don’t press”, and you pressed anyway.

No worries — curiosity is human. That’s exactly what security attacks count on: the most tempting link is the one you’re not supposed to open. While you’re here, let’s see whether you can tell a genuine message from a scam. You’ll get four messages, and the clock is running.

Back to top