Finland NIS2 competent authority hub and spoke network diagram abstract

Finland NIS2 Supervision: Traficom’s Single-Window Model vs Multi-Supervisor EU States — What It Means for Your Reporting Obligations

Finland took an unusual path with NIS2. While most EU member states patched the directive onto existing sector laws, Finland created something new: a single horizontal Cybersecurity Act (124/2025) with one coordination hub at the top — Traficom’s National Cyber Security Centre (NCSC-FI) — sitting above eight sector-specific supervisors. The act entered into force on 8 April 2025, making Finland one of the later transpositions (the EU deadline was 17 October 2024), but the result is structurally cleaner than what many peer states produced.

The distinction matters in practice. When you register under NIS2 in Finland, you register with your sector’s authority — not with Traficom directly. But when a significant incident crosses borders, or when inter-authority coordination breaks down, Traficom’s NCSC-FI steps in as the Article 8(3) single point of contact. Conflating these two roles leads to missed registrations and compliance gaps.

This guide maps the complete supervisor structure, explains what the single-window coordination model actually means for your organisation, and contrasts Finland’s approach with Denmark’s sector-fragmented implementation and the Netherlands’ anticipated multi-regulator model — so you know exactly who to register with, who will audit you, and what they will look for.

Finland’s Cybersecurity Act 124/2025 — The First Horizontal Cyber Law

Before NIS2, Finland’s cybersecurity obligations lived inside a patchwork of sector-specific statutes: the Information Society Code for electronic communications, Act 906/2019 governing information management in public administration, and separate requirements scattered across energy and healthcare legislation. The Cybersecurity Act 124/2025 replaced that patchwork with a single horizontal framework — the first in Finnish history.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The practical effect of a horizontal act is that one piece of legislation sets the baseline for all covered sectors. Sector supervisors can supplement it with sector-specific guidance, but the core obligations — risk management, incident reporting, registration, and management accountability — are identical for a telecom operator and a food manufacturer. This is in contrast to Denmark, which implemented NIS2 sector by sector across separate statutes.

Scope expanded significantly: from approximately 1,100 entities under the previous NIS1 framework to around 5,500 under the Cybersecurity Act. [1]

Does this apply to your organisation? Work through these three questions:

  1. Size: Does your organisation have 50 or more employees, or annual turnover and balance sheet exceeding €10 million? If yes, proceed to question 2. If no, check whether you are a trust service provider, DNS resolution service, TLD registry, or public electronic communications provider — these are in scope regardless of size.
  2. Sector: Does your organisation operate in one of the 18 sectors listed in NIS2 Annexes I or II? The sectors covered include energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, space, postal services, waste management, chemicals, food, manufacturing, digital providers, research, and public administration.
  3. Establishment: Is your organisation established in Finland, or does it provide services into Finland from another EU member state?

If all three answers are yes, you are likely in scope. For borderline cases, see our NIS2 scope guide and the essential vs important entity classification guide.

Entity classification thresholds:

Classification Size criterion Penalty exposure
Essential entity Large enterprise: 250+ employees OR €50M+ turnover and €43M+ balance sheet (sector-dependent) Up to €10M or 2% of global annual turnover
Important entity Medium enterprise: 50–249 employees OR €10M–€50M turnover Up to €7M or 1.4% of global annual turnover
Size-independent (always in scope) Trust services, DNS, TLD registries, public comms providers As above, depending on classification

Two notable exclusions apply. Financial sector operators — banks and financial market infrastructure entities — comply under DORA (Regulation (EU) 2022/2554) rather than the Cybersecurity Act; NIS2 expressly recognises that sector-specific Union legal acts with equivalent cybersecurity requirements take precedence for those entities. Defence and national security activities are similarly excluded from the directive’s scope as permitted under the directive’s own provisions.

Traficom and NCSC-FI — Finland’s Single Point of Contact Under Article 8(3)

Traficom (Finnish Transport and Communications Agency) holds two distinct roles under the Cybersecurity Act, and confusing them is the most common structural misunderstanding among compliance teams.

Role 1: Single Point of Contact under Article 8(3)

The NIS2 Directive requires each member state to designate one single point of contact (SPoC). [3] Finland designated the NCSC-FI at Traficom. The SPoC’s mandate is coordination, not primary supervision: under Article 8(4) it liaises with the European Commission and ENISA, facilitates cooperation between Finland’s domestic supervisory authorities, and manages Finland’s participation in the EU-CyCLONe cyber crisis network. [3]

The SPoC designation does not mean every Finnish organisation registers with Traficom. It means Traficom routes cross-border matters and resolves coordination questions between sector authorities.

Role 2: Competent authority for specific sectors under Article 8(1)

Traficom is also a substantive competent authority — a supervisory body with direct enforcement powers — for organisations in the following sectors: [2]

  • Electronic communications networks and services (telecoms)
  • Digital infrastructure: DNS resolution services, TLD name registries, cloud computing, data centre services, content delivery networks, trust services
  • ICT service management: managed service providers (MSPs) and managed security service providers (MSSPs)
  • Transport: air, rail, water, and road transport operators
  • Space
  • Postal and courier services
  • Domain name registration services
  • Public administration
  • Research entities
  • Vehicle and other transport equipment manufacturing

If your organisation operates in any of these sectors, Traficom is your registration authority, your supervisor, and the body that will audit your cybersecurity measures. You do not register with a separate sector body — Traficom handles the entire supervision lifecycle.

The NCSC-FI CSIRT function

Traficom’s NCSC-FI also operates Finland’s national Computer Security Incident Response Team under Article 10 of the directive. [4] When any in-scope entity — regardless of sector — detects a significant incident, the 24-hour early warning goes to NCSC-FI. The 72-hour detailed notification goes to both NCSC-FI and the relevant sector supervisor. Information voluntarily disclosed to the CSIRT may not be used without the notifier’s consent in criminal or administrative proceedings — a deliberate design choice to encourage early reporting. [2]

NCSC-FI also maintains the national Cybermeter (FI-Kybermittari) self-assessment tool. Sector supervisors increasingly reference it as minimum evidence for supply chain management compliance under Article 21(2)(d). Completing the Cybermeter before your audit is not legally required, but arriving at a supervision review without it is a practical disadvantage.

The Sector Supervisors — Complete Routing Table

Finland’s Cybersecurity Act distributes NIS2 supervision across eight competent authorities. Every in-scope entity must identify its sector supervisor and register with that body — not with NCSC-FI. The routing table below consolidates the official assignments. [2] [6] [5] [9]

Sector(s) Supervisory Authority NIS2 Annex
Electronic communications; digital infrastructure (DNS, TLD, cloud, CDN, data centres, trust services); ICT management (MSP/MSSP); transport (air/rail/water/road); space; postal/courier; public administration; research; vehicle manufacturing Traficom (NCSC-FI) I & II
Electricity supply, transmission and distribution; natural gas; district heating and cooling; hydrogen transmission and distribution Energy Authority (Energivirasto) I
Oil refining and distribution terminals; hydrogen production and storage; gas sector operators (production, transmission, distribution, supply, storage); chemical manufacturing and distribution; computer and electronic products (NACE Div. 26); electrical equipment (Div. 27); machinery and equipment (Div. 28) Tukes (Safety & Chemicals Agency) I & II
Banking; financial market infrastructure operators FIN-FSA (Fiva — Finanssivalvonta) I (via DORA)
Health service providers (hospitals, clinics, healthcare institutions) Valvira (Welfare & Health Supervisory Authority) I
Pharmaceutical manufacturing; medical device manufacturing; medicinal research Fimea (Finnish Medicines Agency) I & II
Food production and large-scale food distribution Finnish Food Authority (Ruokavirasto) II
Drinking water supply; wastewater management South Savo ELY Centre I

The FIN-FSA / Fiva note: Banks and financial market infrastructure operators appear in this table because FIN-FSA is formally listed as the competent authority for those entities. In practice, however, DORA (Regulation (EU) 2022/2554) is the operative legal framework. These entities are not required to register under Finland’s Cybersecurity Act — their cybersecurity obligations flow through DORA, supervised by FIN-FSA/Fiva. [7]

Multi-sector operators: An organisation that runs a hospital group and a pharmaceutical manufacturing unit must register separately with Valvira (for the healthcare services) and Fimea (for manufacturing). Each authority maintains its own entity list. Each may set different evidence formats, different audit cycles, and different procedural requirements. Omitting one registration constitutes non-compliance regardless of compliance with the other. [5]

Incident reporting across sectors: All significant incident notifications — regardless of sector — go to NCSC-FI. The 24-hour early warning and 72-hour detailed notification both route through NCSC-FI first; the sector supervisor receives copies. This dual-channel requirement is intentional: NCSC-FI maintains national situational awareness while sector supervisors handle entity-level enforcement. [2]

Finland vs Multi-Supervisor EU States — The Netherlands and Denmark Compared

Finland’s hub-and-spoke architecture — one horizontal law, one SPoC at the centre, sector authorities at the periphery — produces a compliance experience that is measurably different from the approaches taken in Denmark and the Netherlands.

Denmark: fragmented by statute

Denmark implemented NIS2 through multiple sector-specific statutes rather than a single horizontal act. The Act on Security and Preparedness in the Telecommunications Sector entered into force on 1 July 2025; the energy sector has its own separate law; and the Danish Civil Contingency Agency (Styrelsen for Samfundssikkerhed) coordinates national resilience across these separate frameworks. [8]

For a compliance officer in a Danish multi-sector organisation, “what does NIS2 require us to do?” has no single-document answer. Each sector law must be reviewed independently. Obligations that are harmonised at the European level — incident reporting timelines, risk management domains — are re-enacted separately in each sector statute, creating risk of version drift as laws are updated on different timetables.

Finland’s single Cybersecurity Act 124/2025 eliminates this problem. When the national legislator updates the NIS2 implementation, the change flows to all sectors simultaneously. The compliance baseline is always the same document.

The Netherlands: anticipated multi-regulator model

The Netherlands’ Cyberbeveiligingswet (CBW) is still moving through parliament as of mid-2025, with entry into force expected in the second quarter of 2026. The Dutch model deliberately avoids creating a central enforcement body. Instead, the Rijksinspectie Digitale Infrastructuur (RDI) supervises IT companies; the national NCSC handles coordination and CSIRT functions; and sector-specific regulators manage their own industries without formal co-ordination under a shared horizontal act.

The practical gap this creates is one of jurisdictional clarity. Dutch organisations in sectors where the RDI and a sector regulator both have plausible claims will face a period of jurisdictional ambiguity during the CBW’s early enforcement phase. Finnish organisations face no equivalent uncertainty: the Cybersecurity Act explicitly assigns each sector to one competent authority, and NCSC-FI resolves any inter-authority coordination questions.

The coordination cost difference: A Finnish energy company with a telecoms subsidiary knows Energivirasto supervises the energy operations and Traficom supervises the telecoms operations — both under the same Cybersecurity Act with the same incident reporting timeline, the same risk management domains, and the same management liability provisions. A comparable Dutch group in Q1 2026 may still be determining which regulator takes precedence for shared infrastructure.

The comparison is not that Finland’s model is without friction — multi-sector operators still face parallel registrations. The advantage is that the rules governing every sector supervisor derive from one source, and NCSC-FI provides a single coordination point when those supervisors need to communicate.

Registration, Risk Management, and Incident Reporting Obligations

Three deadlines structure your compliance calendar under the Cybersecurity Act. All three are measured from the act’s entry into force date of 8 April 2025. [1]

Deadline Obligation Where to file
8 April 2025 Incident reporting obligations effective immediately NCSC-FI (all sectors)
8 May 2025 Registration in sector supervisor’s entity list Your sector supervisor (see routing table)
8 July 2025 Cybersecurity risk management operating model in place Internal (available for audit on request)

Registration requirements: When submitting to your sector supervisor’s entity list, you must provide: [2]

  • Organisation name and current contact details
  • IP address ranges used by the organisation
  • EU member states in which you provide services
  • Sector classification and sub-sector (Annex I or II)
  • Entity classification: essential or important
  • Participation in any voluntary cybersecurity information-sharing arrangement

Changes to any registered information must be reported to the supervisory authority without delay and in any event within two weeks of the change. [2]

Incident reporting: A “significant incident” triggers three-stage notification. An early warning reaches NCSC-FI within 24 hours of detection. A detailed notification — covering impact, suspected root cause, and initial mitigation actions — goes to NCSC-FI and the sector supervisor within 72 hours. A final report follows within one month, covering full root cause analysis, impact assessment, and remediation. [2]

For more on what constitutes a significant incident and how to structure your notification, see our incident reporting guide and the Article 23 notification guide.

Risk management: Entities must maintain proportionate cybersecurity measures across 10 domains including policies, network security, supply chain security, asset management, access controls, incident response, backup and recovery, physical security, cryptography, and vulnerability management. For an overview of what evidence supervisors expect, see our NIS2 scope and obligations guide.

Penalties, the Sanctions Board, and Management Liability

Finland’s enforcement structure has two features that distinguish it from simpler implementations: an administrative Sanctions Board that sits between investigation and fine, and personal liability for management bodies.

Penalty amounts: [2]

Entity type Maximum fine Scope
Essential entities €10 million or 2% of total global annual turnover Whichever is higher
Important entities €7 million or 1.4% of total global annual turnover Whichever is higher
Public administration entities Administrative orders and corrective measures No monetary fines

The Sanctions Board: Fines are not imposed directly by sector supervisors. Sector supervisors investigate, gather evidence, and propose sanctions. An independent Sanctions Board — composed of representatives appointed by the supervisory authorities — reviews each proposal and issues the final administrative decision. This procedural separation is designed to ensure proportionality and prevent sector supervisors from acting as both investigator and judge in the same case.

Management liability: The Cybersecurity Act places explicit personal accountability on management bodies. The management body of an essential or important entity must: approve the organisation’s cybersecurity risk management measures; oversee their implementation and compliance; and demonstrate adequate cybersecurity knowledge to discharge this oversight duty. Management bodies can be held personally liable for violations attributable to insufficient oversight. [7]

The practical implication is direct. A board that delegated cybersecurity entirely to the IT department — without formally approving the risk management framework, without board-level review of incident response plans, without evidence of adequate governance oversight — faces personal liability exposure under the act. The evidence trail that demonstrates board engagement — board minutes, approval records, documented board-level KPIs on cybersecurity — is therefore not optional. It is the primary defence against liability claims.

For penalty detail by violation type, see our NIS2 penalties guide and the supervisory measures guide.

Frequently Asked Questions

Is Traficom my NIS2 supervisor?
Only if you operate in digital infrastructure, telecoms, transport, space, postal and courier services, public administration, managed services, or research. For all other sectors, register with your sector-specific authority. Traficom’s NCSC-FI handles incident reporting coordination and cross-border liaison regardless of which authority supervises you.

Our organisation is a Finnish bank. Do we comply under the Cybersecurity Act or under DORA?
DORA (Regulation (EU) 2022/2554) is the applicable framework. You comply under DORA’s ICT risk management provisions, supervised by FIN-FSA (Fiva/Finanssivalvonta). You are not required to register under Finland’s Cybersecurity Act. [7]

Can we rely on NCSC-FI incident reports as our only notification?
No. The 24-hour early warning goes to NCSC-FI. The 72-hour detailed notification goes to NCSC-FI and your sector supervisor. Both channels are required; filing only one constitutes partial non-compliance. [2]

Our organisation operates in two sectors with different supervisors. Do we register twice?
Yes. You must register separately with each applicable sector supervisor and comply with each authority’s requirements. Being registered with one does not fulfil the obligation to the other. [5]

When did NIS2 obligations begin in Finland?
Incident reporting and general obligations began 8 April 2025 when the Cybersecurity Act entered into force. Registration was due 8 May 2025. The risk management operating model was required by 8 July 2025. [1]

Key Takeaways

  • Finland’s Cybersecurity Act 124/2025 (in force 8 April 2025) implements NIS2 as a single horizontal law — the first of its kind in Finnish legislative history.
  • Traficom’s NCSC-FI holds two roles: Article 8(3) SPoC for cross-border coordination, and direct sector supervisor for digital infrastructure, telecoms, transport, space, postal, public administration, and research.
  • Eight sector supervisors handle the remaining sectors; registration goes to the sector supervisor, not Traficom, unless Traficom is your sector’s authority.
  • Finland’s hub-and-spoke model provides clearer sector routing than Denmark’s statute-fragmented approach or the Netherlands’ anticipated multi-regulator model.
  • Management bodies are personally accountable for cybersecurity oversight adequacy; board-level evidence trails are the primary defence against personal liability claims.
  • Financial sector entities (banks, financial market infrastructure) comply via DORA under FIN-FSA supervision, not the Cybersecurity Act.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Cybersecurity Act passed by Parliament — Traficom (official)
  2. NIS2 important information — NCSC-FI / Traficom (official)
  3. Article 8: Competent Authorities and Single Points of Contact — NIS2 Directive (EU) 2022/2555
  4. Article 10: CSIRTs — NIS2 Directive (EU) 2022/2555
  5. Registration open for Fimea’s NIS2 entity list — Fimea (official)
  6. Cybersecurity — Tukes Finnish Safety and Chemicals Agency (official)
  7. Finnish Cybersecurity Act enters into force — Roschier
  8. NIS2 Transposition: Denmark — nis-2-directive.com
  9. NIS2 Directive implementation in Finland — European Commission
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: