ComplianceCodedSuomeksiBook a 30-min review
EU cybersecurity directive NIS2

NIS2 obligations have applied since 8 April 2025. The early warning for a significant incident must be filed within 24 hours.

Under the Finnish cybersecurity act, essential and important entities must maintain a documented cybersecurity risk-management framework, register with Traficom's register of entities, and report significant incidents within short deadlines. You only meet these deadlines if the risk management, responsibilities and reporting process are ready in advance.

early warning 24 hnotification 72 hregister of entities8 Apr 2025obligations in force
Book a 30-min reviewDoes NIS2 apply to us?
Scope

Does NIS2 apply to you?

NIS2 applies to organisations operating in critical sectors of society. Entities are classified as essential or important based on sector, size and criticality. As a general rule, the obligations apply to medium-sized and larger entities: 50–249 employees, or an annual turnover and balance-sheet total exceeding €10 million. In addition, nationally critical entities are in scope regardless of size.

Essential entities

Subject to proactive supervision. Typically large entities in high-criticality sectors:

  • Energy, and water and waste management
  • Transport (air, rail, water and road)
  • Banking and financial markets
  • Healthcare
  • Digital infrastructure and public administration

Important entities

Subject to ex-post supervision. Medium-sized entities in the same sectors, and for example:

  • Digital services such as cloud services, data centres and managed services
  • Online marketplaces, search engines and social platforms
  • Manufacturing and food production
  • Postal and courier services
  • Production and distribution of chemicals

The difference between an essential and an important entity affects the form of supervision and the maximum sanctions, but the risk-management and reporting obligations apply to both. In practice NIS2 also reaches smaller entities that operate in the supply and subcontracting chain of obligated companies: supply-chain security is one of the directive's explicit requirements. Scope is assessed by sector and size, and that is the first item in the review.

Timeline

The obligations already apply

16 Jan 2023 · EU

Directive enters into force in the EU

NIS2 entered into force in the EU and replaced the earlier Network and Information Security Directive. Member states had to transpose it into national law.

8 Apr 2025 · in force

Cybersecurity act enters into force

In Finland the NIS2 obligations took effect with the cybersecurity act: risk management, registration in the register of entities, and incident reporting.

ongoing · supervision

Supervision and registration

Entities must register in the register of entities. Traficom and sector-specific authorities supervise; essential entities are subject to proactive supervision.

Administrative fine for failing to meet the obligations: for essential entities up to €10 million or 2% of worldwide annual turnover, for important entities up to €7 million or 1.4%. The fine is imposed by the sanctions board on the supervisory authority's proposal. The dates and obligations are based on guidance from Traficom and the National Cyber Security Centre and on the NIS2 directive. Check the application to your own organisation with an expert; this page is not legal advice.

Obligations · Article 21

What NIS2 requires in practice

Article 21 of the directive sets out the cybersecurity risk-management measures the entity must implement and keep up to date. They must be documented and demonstrable to the supervisory authority. Registration in the register of entities, incident reporting and management responsibility are separate obligations.

Risk analyses and information system security policies
Incident handling
Business continuity management: backups, recovery planning and crisis management
Supply-chain security, including relationships with direct suppliers and service providers
Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure
Policies to assess the effectiveness of the risk-management measures
Basic cyber-hygiene practices and cybersecurity training
Policies on the use of cryptography and, where appropriate, encryption
Human resources security, access control and asset management
Where appropriate, multi-factor authentication, secured communications and secured emergency communication systems
Requirement and solution

NIS2 requires verifiable documentation

ComplianceCoded is a documentation platform where every change, approval and sign-off is recorded in the version history. The same capability that supports an ISO 27001 audit produces the evidence NIS2 requires.

NIS2 · risk management

Risk-management framework

The framework must be kept up to date and its implementation must be demonstrable to the supervisory authority.

On the platformpolicies, requirements, approvals and sign-offs with a version history: who changed what and when, and who approved it. The evidence is created as you work, not assembled afterwards.

NIS2 · incidents

Incident report in 24 h, 72 h and a final report

A significant incident is reported to the supervisory authority: an early warning within 24 hours, a notification within 72 hours and a final report within one month of the notification.

On the platforma reporting process with responsibilities ready and signed off. When an incident is underway, roles and report templates are available without separate preparation.

NIS2 · register of entities

Registration and contact details

Entity details and the scope of the service must be reported and kept up to date.

On the platformentity and contact details and the service description in one place, versioned, so registration and updates draw on the same source as the rest of the documentation.

Foundation in place

ISO 27001 already covers a large part

If ISO 27001 work is done or under way, a large part of NIS2's risk-management requirements is already covered.

On the platformthe same documentation serves both: ISO 27001 controls are mapped to NIS2 obligations, and the same content is not written twice.

Proof

The same basis as ISO 27001 certification

NIS2's risk-management requirements rest on the same information security management as ISO 27001. We build our own information security management system on the same platform we offer to customers, and the same documentation covers a large part of the NIS2 obligations. We do not offer a tool we would not put under inspection ourselves.

risk managementversion historyapprovalssign-offsincident reports

Half an hour is enough for a clear picture.

We go through whether your organisation falls within the scope of NIS2 as an essential or important entity, which obligations you already meet and which measures still need to be taken. The review is about your situation, not a generic pitch.

Book a 30-min review