Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance
Kyberturvallisuuslaki (124/2025), 3 ja 7-10 §
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 8 April 2025.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds you if you carry out an Annex I or Annex II activity and meet or exceed the medium-enterprise thresholds of Commission Recommendation 2003/361/EC, or, regardless of size, if you are a public electronic communications network or service provider, a trust service provider, a top-level-domain registry operator, a DNS service provider, or a critical entity designated outside the public administration sector under the Act on Protecting and Improving the Resilience of Critical Infrastructure (310/2025); the online marketplace, online search engine and online social-networking-platform digital-service-providers named in Annex II are flagged here, and the wider Annex I and Annex II sector classes this vocabulary cannot express are not raised on that account.
- Identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services, and act to prevent or minimise an incident's impact on your operations, their continuity, the recipients of your services and other services.
- Maintain a documented cybersecurity risk-management operating model covering at minimum: risk-management policy and effectiveness assessment; network and information system security policy; supply-chain security, including vulnerability handling and disclosure for your direct suppliers and service providers; asset management and identification of security-critical functions; personnel security and cybersecurity training; access-control and authentication procedures; cryptography policy; incident detection and handling; backup, recovery planning, crisis management and business continuity; basic cyber-hygiene practices; and, where appropriate, multi-factor or continuous authentication.
- Have your board, supervisory board or chief executive approve and oversee this operating model; they must hold sufficient familiarity with cybersecurity risk management to do so.
- The public administration sector named in NIS2 Annex I point 10 is carved out of this Act's own scope and governed instead by the Act on Information Management in Public Administration (906/2019), a different Finnish instrument not researched here.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Act's own sanction for a Section 7, 8, 9, 11, 12, 13 or 41 breach is the administrative penalty in Sections 35 to 40; no provision reviewed here makes the breach itself a criminal offence.
Penalty structure
Section 38 sets the maximum administrative penalty for an essential entity's breach at EUR 10,000,000 or 2 percent of worldwide annual turnover in the preceding financial year, whichever is higher, and the maximum for any other bound entity at EUR 7,000,000 or 1.4 percent, mirroring NIS2 Article 34(4) and (5). Section 35 excludes state authorities, state enterprises, wellbeing regions and joint authorities, municipal authorities, independent public-law institutions, parliamentary agencies, the Office of the President, and the Evangelical Lutheran and Orthodox Churches of Finland and their parishes from the penalty entirely.
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Liikenne- ja viestintävirasto (Traficom), the Act's Section 26 supervisory authority for Annex I items 1 to 7 (transport, digital infrastructure and ICT service management) and Annex II items 1 to 5 (postal and courier services, and the online marketplace, search engine and social-networking-platform digital-service-providers flagged here); the Act designates seven further sector authorities for its other Annex I and II classes.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://kyberturvallisuuskeskus.fi/fi/toimintamme/saantely-ja-valvonta/nis-2-euroopan-unionin-kyberturvallisuusdirektiivi
- Guidance body
- Kyberturvallisuuskeskus (NCSC-FI), Liikenne- ja viestintävirasto Traficom
- Open questions
- Does the Act on Information Management in Public Administration (906/2019) impose risk-management duties on Finland's public administration sector equivalent to Kyberturvallisuuslaki Sections 7 to 10, given Section 1 excludes that sector from this Act's own scope and points to the other Act instead?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Sections 7 to 10 of the Kyberturvallisuuslaki require an entity within scope to identify, assess and manage the risks to the network and information systems it uses in its operations or to provide its services, and to act to prevent or minimise an incident's impact on its operations, their continuity, the recipients of its services and other services (Section 7).
The entity must maintain a documented cybersecurity risk-management operating model (Section 8) whose management measures cover, at minimum, twelve areas matching NIS2 Article 21(2): risk-management policy and effectiveness assessment; network and information system security policy; supply-chain security, including vulnerability handling and disclosure for direct suppliers and service providers; asset management and identification of security-critical functions; personnel security and cybersecurity training; access-control and authentication procedures; cryptography policy; incident detection and handling; backup, recovery planning, crisis management and business continuity; basic cyber-hygiene practices; and, where appropriate, multi-factor or continuous authentication (Section 9).
The entity's board, supervisory board or chief executive is responsible for organising the implementation and oversight of this risk management, approves the operating model, and must hold sufficient familiarity with cybersecurity risk management (Section 10).
Liikenne- ja viestintävirasto (Traficom) is the supervisory authority for Annex I items 1 to 7, covering transport, digital infrastructure and ICT service management, and for Annex II items 1 to 5, covering postal and courier services and the online marketplace, online search engine and online social-networking-platform digital-service-providers flagged here; the Act designates seven further sector authorities for its other Annex I and II classes.
An intentional or grossly negligent failure of the Section 7, 8 or 9 duties is subject to an administrative penalty of up to EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity and up to EUR 7,000,000 or 1.4 percent for any other bound entity (Section 38), mirroring NIS2 Article 34(4) and (5), though Section 35 exempts state authorities, state enterprises, wellbeing regions and joint authorities, municipal authorities, independent public-law institutions, parliamentary agencies, the Office of the President, and the Evangelical Lutheran and Orthodox Churches of Finland and their parishes from the penalty itself, without exempting them from the underlying duty.
Beyond the entities that meet or exceed the medium-enterprise thresholds of Commission Recommendation 2003/361/EC while carrying out an Annex I or Annex II activity, Section 3 binds a narrower set of entities regardless of size: a provider of public electronic communications networks or publicly available electronic communications services, a trust service provider, a top-level-domain registry operator, a DNS service provider, and a critical entity designated outside the public administration sector under the Act on Protecting and Improving the Resilience of Critical Infrastructure (310/2025).
Section 1 excludes the public administration sector named in NIS2 Annex I point 10 from this Act's own scope, assigning that sector instead to the Act on Information Management in Public Administration (906/2019), a different Finnish instrument not researched here.
When LexLint raises it
operates_social_platform