Law / Finland

Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience Act

Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), 1, 7-9, 15-16 ja 31-38 §

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 4 months, effective 1 June 2026.

A product security requirements rule binding private bodies.

As of 15 September 2026.

What it requires

  • This does not create a new substantive product-security duty of its own: the essential cybersecurity requirements, vulnerability-handling and support-period duties for a product with digital elements are the Cyber Resilience Act's (Regulation (EU) 2024/2847), documented at the European Union level; this Act supplies Finland's market-surveillance authority and its own administrative-penalty amounts for a breach of that Regulation.
  • Report an actively exploited vulnerability in your product with digital elements, or a severe incident affecting its security, to Finland's CSIRT unit under the Regulation's own Article 14 clock; this Act only directs the report to that unit and does not restate the duty or its deadline.
  • Expect Liikenne- ja viestintävirasto (Traficom) to act as your market surveillance authority under Article 52 of the Regulation, except where your product is a high-risk AI system within the Regulation's scope, in which case the market surveillance authority the Act on the Supervision of Certain Artificial Intelligence Systems designates applies instead.
  • As a manufacturer, expect exposure up to EUR 15,000,000 or 2.5 percent of your worldwide turnover for breaching the essential cybersecurity requirements of Article 13 and Annex I Part I, and up to EUR 10,000,000 or 2 percent for breaching your other manufacturer obligations; the same EUR 10,000,000 or 2 percent band applies to an authorised representative, importer, distributor or notified body for its own obligations. A lower EUR 5,000,000 or 1 percent band applies to other Regulation-related breaches such as supplying incorrect or misleading information, and a flat EUR 100,000 cap applies to a cybersecurity-certification breach.
  • You may voluntarily report a vulnerability, cyberthreat, security incident or near miss affecting your product to Finland's CSIRT unit under the Regulation's Article 15; information reported this way cannot be used against you in a criminal investigation or an administrative decision without your consent.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Act's own sanction for the breaches reviewed here is the administrative penalty in Sections 31 to 41; no provision reviewed here makes a breach itself a criminal offence.

Penalty structure

Section 38 sets four separate bands within Regulation Article 64's own limits. A manufacturer's breach of the essential cybersecurity requirements (Article 13 and Annex I Part I) carries the headline cap this structure records: EUR 15,000,000 or 2.5 percent of worldwide turnover, whichever is higher. A manufacturer's other obligations, and an authorised representative's, importer's, distributor's or notified body's own obligations, cap at EUR 10,000,000 or 2 percent. Supplying incorrect, incomplete or misleading information to a notified body or the market surveillance authority, and the other Regulation-related breaches Section 36(4) lists, cap at EUR 5,000,000 or 1 percent. A cybersecurity-certification breach under Section 37 carries a flat EUR 100,000 cap, which this structure's fields cannot represent alongside the turnover-based bands.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
2.5

Who enforces it

Enforcement body

Liikenne- ja viestintävirasto (Traficom), designated as the Regulation's Article 52 market surveillance authority by Section 15, except for a high-risk AI system within the Regulation's scope, which the Act on the Supervision of Certain Artificial Intelligence Systems' own designated authority supervises instead (Section 16).

Settledness

As of
15 September 2026
Guidance link
https://kyberturvallisuuskeskus.fi/en
Guidance body
Kyberturvallisuuskeskus (NCSC-FI), Liikenne- ja viestintävirasto Traficom
Open questions
Will Traficom publish sector guidance illustrating how the four Kyberkestävyyslaki penalty tiers apply to specific manufacturer conduct once the Cyber Resilience Act's own Article 14 reporting duty applies from 11 September 2026?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), known colloquially as the Kyberkestävyyslaki, specifies and supplements the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847) and its national application, rather than restating the Regulation's own essential cybersecurity requirements, which are documented at the European Union level and are not repeated here.

Section 7 leaves a manufacturer's duty to report an actively exploited vulnerability or a severe security-affecting incident entirely to Article 14 of the Regulation, adding only that the report goes to Finland's CSIRT unit, which must in turn notify the market surveillance authority under the Regulation's Article 16(3); Section 8 lets a manufacturer or other party voluntarily report a vulnerability, cyberthreat, incident or near miss to the CSIRT unit under Article 15, and information reported this way cannot be used against the reporter in a criminal investigation or an administrative decision without consent.

Section 15 names Liikenne- ja viestintävirasto (Traficom) as the Regulation's Article 52 market surveillance authority, except that Section 16 assigns a high-risk AI system within the Regulation's scope to the market surveillance authority the Act on the Supervision of Certain Artificial Intelligence Systems designates instead.

Chapter 6 sets Finland's own administrative penalty amounts within the bands Regulation Article 64 allows a Member State to set: up to EUR 15,000,000 or 2.5 percent of a manufacturer's worldwide turnover for breaching the essential cybersecurity requirements of Article 13 and Annex I Part I (Section 31, first paragraph); up to EUR 10,000,000 or 2 percent for a manufacturer's other obligations, or for an authorised representative's, importer's, distributor's or notified body's own obligations (Section 31 second paragraph and Sections 32 to 35); up to EUR 5,000,000 or 1 percent for other Regulation-related breaches, such as supplying incorrect or misleading information to a notified body or the market surveillance authority (Section 36); and a flat EUR 100,000 cap for a cybersecurity-certification breach (Section 37).

Finland's Act entered into force 1 June 2026, ahead of the Regulation's own Article 14 reporting duty, which applies from 11 September 2026.

When LexLint raises it

  • distributes_software_product

Read the law

Consolidated text
Finlex, Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista 439/2026, version in force from 1 June 2026

Back to the example  ·  Lint your app