Under the Finnish cybersecurity act, essential and important entities must maintain a documented cybersecurity risk-management framework, register with Traficom's register of entities, and report significant incidents within short deadlines. You only meet these deadlines if the risk management, responsibilities and reporting process are ready in advance.
NIS2 applies to organisations operating in critical sectors of society. Entities are classified as essential or important based on sector, size and criticality. As a general rule, the obligations apply to medium-sized and larger entities: 50–249 employees, or an annual turnover and balance-sheet total exceeding €10 million. In addition, nationally critical entities are in scope regardless of size.
Subject to proactive supervision. Typically large entities in high-criticality sectors:
Subject to ex-post supervision. Medium-sized entities in the same sectors, and for example:
The difference between an essential and an important entity affects the form of supervision and the maximum sanctions, but the risk-management and reporting obligations apply to both. In practice NIS2 also reaches smaller entities that operate in the supply and subcontracting chain of obligated companies: supply-chain security is one of the directive's explicit requirements. Scope is assessed by sector and size, and that is the first item in the review.
NIS2 entered into force in the EU and replaced the earlier Network and Information Security Directive. Member states had to transpose it into national law.
In Finland the NIS2 obligations took effect with the cybersecurity act: risk management, registration in the register of entities, and incident reporting.
Entities must register in the register of entities. Traficom and sector-specific authorities supervise; essential entities are subject to proactive supervision.
Administrative fine for failing to meet the obligations: for essential entities up to €10 million or 2% of worldwide annual turnover, for important entities up to €7 million or 1.4%. The fine is imposed by the sanctions board on the supervisory authority's proposal. The dates and obligations are based on guidance from Traficom and the National Cyber Security Centre and on the NIS2 directive. Check the application to your own organisation with an expert; this page is not legal advice.
Article 21 of the directive sets out the cybersecurity risk-management measures the entity must implement and keep up to date. They must be documented and demonstrable to the supervisory authority. Registration in the register of entities, incident reporting and management responsibility are separate obligations.
ComplianceCoded is a documentation platform where every change, approval and sign-off is recorded in the version history. The same capability that supports an ISO 27001 audit produces the evidence NIS2 requires.
The framework must be kept up to date and its implementation must be demonstrable to the supervisory authority.
On the platformpolicies, requirements, approvals and sign-offs with a version history: who changed what and when, and who approved it. The evidence is created as you work, not assembled afterwards.
A significant incident is reported to the supervisory authority: an early warning within 24 hours, a notification within 72 hours and a final report within one month of the notification.
On the platforma reporting process with responsibilities ready and signed off. When an incident is underway, roles and report templates are available without separate preparation.
Entity details and the scope of the service must be reported and kept up to date.
On the platformentity and contact details and the service description in one place, versioned, so registration and updates draw on the same source as the rest of the documentation.
If ISO 27001 work is done or under way, a large part of NIS2's risk-management requirements is already covered.
On the platformthe same documentation serves both: ISO 27001 controls are mapped to NIS2 obligations, and the same content is not written twice.
NIS2's risk-management requirements rest on the same information security management as ISO 27001. We build our own information security management system on the same platform we offer to customers, and the same documentation covers a large part of the NIS2 obligations. We do not offer a tool we would not put under inspection ourselves.
We go through whether your organisation falls within the scope of NIS2 as an essential or important entity, which obligations you already meet and which measures still need to be taken. The review is about your situation, not a generic pitch.