Skip to main content
NIS2 · FINLAND

NIS2 in Finland — an early transposition, sectoral registration, and the NCSC-FI inside Traficom.

Finland transposed early: the Kyberturvallisuuslaki (124/2025) entered into force on 8 April 2025, with registration due to each entity's sectoral supervisor by 8 May 2025 — a four-week window, among the shortest in the Union. Traficom, the transport and communications agency, anchors the regime, with the National Cyber Security Centre Finland (NCSC-FI) as national CSIRT inside it; sectoral supervisors — the Energy Authority, the Finnish Food Authority and others — hold their own sectors.

The distinctive part is the registration model: rather than one national portal, entities registered with whichever authority supervises their sector. Groups with activities in several sectors answered to more than one supervisor from day one — a structure that rewards holding the entity-to-supervisor mapping as a managed record.

Who it applies to

Essential and important entities across the NIS2 sectors, registered with their sectoral supervisor — Traficom for most digital sectors; the Energy Authority, the Food Authority and other sector supervisors for theirs — by 8 May 2025, with entities crossing thresholds later registering without delay. Incident reporting runs the directive's three stages: 24 hours, 72 hours, one month.

The clock

Competent authority: Traficom and sectoral supervisors · NCSC-FI as national CSIRT. Transposition: Kyberturvallisuuslaki 124/2025.

NIS2 in Finland · timeline
WhenWhat happens
8 Apr 2025Kyberturvallisuuslaki 124/2025 enters into force
8 May 2025Registration deadline with each sectoral supervisor
OngoingIncident reporting to NCSC-FI · 24 h, 72 h, one month
OngoingSectoral supervision by Traficom, the Energy Authority and other sector supervisors

One law, many registrars

Finland distributed NIS2 registration across the supervisory landscape: an energy company registered with the Energy Authority (Energiavirasto), a food-sector entity with the Finnish Food Authority (Ruokavirasto), most digital sectors with Traficom — each supervisor receiving its own sectors' registrations against the same four-week window that closed on 8 May 2025. The NCSC-FI sits inside Traficom as national CSIRT, a converged-regulator model that predates NIS2. For multi-sector groups this makes the supervisor mapping itself compliance infrastructure: TruSecure holds each entity's supervisor, CSIRT routing and sectoral obligations as records, so evidence and reports go to the right authority per entity — not to whichever one the team remembers.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Finland transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Finland requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with your sectoral supervisor — or now, if lateEntity profile · supervisor resolved per sector, registration facts held as records
Meet the security-measures duty with evidence on demandControl library · continuously monitored, evidence attached
Report significant incidents to NCSC-FI: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Show management-body oversight and trainingGovernance workspace · approvals and training records, dated
Answer sectoral supervision with evidenceSupervision export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Finland NIS2 readiness file · excerptSample data
Registration
Traficom · filed 28 Apr 2025
Sectoral supervisor
confirmed · digital infrastructure
Controls evidenced
91/107 · 16 open, each with an owner and a date
Incident reports
3 filed · all within statutory timeframes
Export
sealed · sha256:4a7e...9c2d

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your sectoral supervisor confirmed, the controls you already operate mapped against the Kyberturvallisuuslaki, and a sample incident run against the reporting clocks. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Finland by Traficom and sectoral supervisors · NCSC-FI as national CSIRT. TruSecure determines applicability against Finland's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Why is Finland's telecom regulator also its cybersecurity authority?
Traficom combined telecom regulation and national cybersecurity oversight (as NCSC-FI) before NIS2 existed — Finland extended that existing structure rather than standing up a separate agency.