Law / Finland

Kyberturvallisuuslaki, Significant-Incident Reporting Obligations

Kyberturvallisuuslaki (124/2025), 11-14 ja 22 §

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 8 April 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds you on the same scope as this jurisdiction's companion risk-management row: an Annex I or Annex II activity at medium-enterprise size or above, or, regardless of size, if you are a public electronic communications provider, a trust service provider, a top-level-domain registry operator, a DNS service provider, or a certain critical entity; the online marketplace, online search engine and online social-networking-platform digital-service-providers named in Annex II are flagged here.
  • Notify your supervisory authority without delay of a significant incident, one that has caused or could cause a serious service disruption or considerable financial loss to you, or that has affected or could affect another person with considerable material or immaterial damage.
  • File an early notification within 24 hours of detecting the significant incident, stating whether it is suspected to result from an unlawful or hostile act and the likelihood of cross-border effects, and a follow-up notification within 72 hours of detection, both clocks running from detection rather than from each other; if you are a trust service provider whose trust services are affected, file your follow-up notification within 24 hours instead of 72.
  • Provide an interim report on the authority's request, or within one month of your follow-up notification if the incident is long-running, and a final report within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken, and any cross-border effects.
  • Notify the recipients of your services without delay of a significant incident likely to adversely affect your service to them, and of a significant cyberthreat that may affect them together with the measures available to counter it.
  • Expect Finland's CSIRT unit, not your own organisation, to hold the coordinated vulnerability disclosure function under NIS2 Article 12 for a vulnerability reported about a product or service in Finland; a report to it may be made anonymously.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Act's own sanction for a Section 11, 12 or 13 breach is the administrative penalty in Sections 35 to 40; no provision reviewed here makes the breach itself a criminal offence.

Penalty structure

The same penalty provision that governs the Section 7 to 9 breach on this jurisdiction's companion risk-management row governs a Section 11, 12 or 13 breach: up to EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity, and up to EUR 7,000,000 or 1.4 percent for any other bound entity, mirroring NIS2 Article 34(4) and (5). The same Section 35 exclusion for state and church bodies applies.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Liikenne- ja viestintävirasto (Traficom), the Act's Section 26 supervisory authority for Annex I items 1 to 7 (transport, digital infrastructure and ICT service management) and Annex II items 1 to 5 (postal and courier services, and the online marketplace, search engine and social-networking-platform digital-service-providers flagged here); reports reach the CSIRT unit immediately under Section 17.

Settledness

As of
15 September 2026
Guidance link
https://kyberturvallisuuskeskus.fi/fi/toimintamme/saantely-ja-valvonta/nis-2-euroopan-unionin-kyberturvallisuusdirektiivi
Guidance body
Kyberturvallisuuskeskus (NCSC-FI), Liikenne- ja viestintävirasto Traficom
Open questions
What situations does the European Commission implementing act adopted under NIS2 Directive Article 23(11) specify as automatically significant, beyond the general definition Kyberturvallisuuslaki Section 11 states in its own right?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Sections 11 to 14 of the Kyberturvallisuuslaki require a bound entity to notify its supervisory authority without delay of a significant incident, defined as one that has caused or could cause a serious service disruption or considerable financial loss to the entity, or that has affected or could affect another natural or legal person with considerable material or immaterial damage.

An early notification is due within 24 hours of detecting the significant incident and a follow-up notification within 72 hours of detection, both clocks running from the moment of detection rather than from each other (Section 11). A trust service provider whose trust services are affected must instead file its follow-up notification within 24 hours rather than 72 (Section 11).

An interim report is due on the supervisory authority's request, or within one month of the follow-up notification if the incident is long-running (Section 12), and a final report is due within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken and any cross-border effects (Section 13).

Where a significant incident is likely to adversely affect an entity's service, or a significant cyberthreat may affect the recipients of that service, the entity must notify them without delay of the incident, the threat, and available countermeasures (Section 14).

Separately, Section 22 makes the Act's CSIRT unit, not the affected manufacturer or provider, the NIS2 Article 12 coordinator for coordinated vulnerability disclosure: it receives reports of vulnerabilities, which may be submitted anonymously, and handles the necessary follow-up. The same penalty bands and exemptions described on this jurisdiction's companion risk-management row apply to a failure of the Section 11, 12 or 13 reporting duties.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, Finlex, Kyberturvallisuuslaki 124/2025, version in force from 8 April 2025, amendments through 4 September 2026

Back to the example  ·  Lint your app