FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
payment of between EUR1,000 and EUR100,000. The Financial Supervisory Authority has published a com - prehensive guide on the basis of which the amount of penalty payments is determined. If the non-compli - ance is particularly reprehensible, an administrative fine of up to 10% of the annual turnover of the ICT DORA does not include comprehensive cross-border data transfer regulation comparable to the GDPR. However, DORA requires financial entities to include specific ICT-related provisions in their third-party ICT service contracts, including the locations of data pro - cessing and service provision, and notification obli - gations when planning to change these locations. Financial entities must also implement exit strategies for critical ICT services, notify competent authorities of planned contractual arrangements for critical or important functions, and assess concentration risks arising from using the same or closely related service providers. Extensive regulation on transfers of per - sonal data is included in the GDPR. 3.6 Threat-Led Penetration Testing DORA requires entities identified by the Financial Supervisory Authority to carry out threat-led penetra - tion testing (TLPT) on live production systems at least every three years. The Financial Supervisory Authority identifies the entities based on impact-related factors, possible financial stability concerns and ICT risk pro - file. Entities determine the scope of TLPT indepen - dently, subject to validation by the Financial Super - visory Authority. ICT service providers may also be included in the scope of TLPT. service provider may be imposed. 3.5 International Data Transfers TLPT may be conducted by either external or internal testers; however, an external tester must be engaged at least once every three years. Testers must satisfy requirements relating to independence, competence, certification, and risk management and mitigation. Compliance with the remaining testing requirements is achieved by adhering to the TIBER-FI framework.
The main source of cyber-resilience regulation in Fin - land is Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (the Cyber Resilience Act, or CRA). The CRA is a horizontal, harmonised product safety regu - lation, and the essential cybersecurity requirements under it are indicated by a product’s CE marking. In addition, Commission Implementing Regulation (EU) 2025/2392 further specifies the technical descrip - tions of important and critical products with digital elements under the CRA. The requirements under the CRA do not preclude the application of other require - ments that may apply to the same product pursuant to other EU product regulations. In Finland, national legislation implementing the CRA will enter into force at a later date. The CRA entered into force in 2024, and the applica - tion of its obligations starts in three steps between 2026 and 2028. The scope of the CRA is broad; as a general rule, it includes all devices and software with digital elements and expected use involving direct or indirect connection to a network or other device. Pure SaaS solutions that are not delivered together with a product with digital elements are generally excluded from the scope of the CRA. However, remote data pro - cessing solutions necessary for a product with digital elements to perform its functions are considered part of that product and, accordingly, fall within the scope of the CRA. An example of such products is smart home devices. 4.2 Key Obligations Under Legislation The CRA imposes extensive obligations on manu - facturers, importers and distributors of products with digital elements. Products must meet essential cybersecurity requirements contained in Annex I of the CRA, covering product properties (eg, security by default, access control, data protection) and vul - nerability handling processes. Manufacturers must conduct cybersecurity risk assessments, prepare technical documentation and provide user instruc -
106 CHAMBERS.COM
Powered by FlippingBook