FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
tions. Vulnerabilities must be remediated without delay through security updates distributed securely and free of charge during the support period, which must reflect the product’s expected lifetime (mini - mum five years unless the expected lifetime is lower). The reporting timelines under the CRA correspond to those prescribed by the Cybersecurity Act and DORA, requiring notifications within 24 hours, 72 hours and one month, respectively (see 2.3 Incident Response and Notification Obligations and 3.3 Key Operational Resilience Obligations ). Before market placement, conformity assessment is required, followed by EU declaration of conformity and CE marking. Prior to placing products on the EU market, importers are required to verify that manufacturers have fulfilled their obligations, including conformity assessment, preparation of technical documentation and affixing of the CE marking, and must provide their own contact details on the product. Distributors must verify that the CE marking has been affixed and that manufacturers and importers have met their obligations concerning identification, contact information, user instructions and support period information before making prod - ucts available on the market. Both importers and dis - tributors are required to notify manufacturers of any discovered vulnerabilities without undue delay and, where a product poses a significant cybersecurity risk, to immediately inform the relevant market sur- veillance authorities, providing detailed information on the non-compliance identified and any corrective measures taken. The market surveillance authority in Finland for prod - ucts within the scope of the CRA is expected to be Traficom. As an initial enforcement measure, the relevant economic operator is required to bring the non-compliance to an end by, for example, bringing the product into compliance, withdrawing or recall - ing the product, or arranging for its destruction. This requirement may be enforced by means of a penal - ty payment. If the operator fails to comply with the requirement, the authority may itself recall or restrict the availability of the product on the market. In addi - tion, the CRA sets out administrative fines for non- compliance, ranging up to:
• EUR15 million or 2.5% of annual turnover (which - ever is higher) for manufacturers; • EUR10 million or 2% of annual turnover for author - ised representatives, importers, distributors and notified bodies; and • EUR5 million or 1% of annual turnover for the submission of incorrect, incomplete or misleading information. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Finland is part of the EU’s cybersecurity certifica - tion framework established under Regulation (EU) 2019/881 (the EU Cybersecurity Act, or CSA). The National Cybersecurity Certification Authority (NCCA) in Finland is Traficom, which is responsible for the accreditation of Conformity Assessment Bodies (CABs) that can act as certifiers delivering certificates or as evaluators auditing and testing. The CSA establishes three assurance levels: basic, substantial and high. The basic level provides assur - ance against basic risks; the substantial level address - es significant risks; and the high level is intended for situations involving the highest risks, requiring the most stringent evaluation methods, such as penetra - tion testing. Certification under the CSA is generally voluntary; however, certificates are commonly used as require - ments for certain critical products, and certification under the CSA is a recognised means of demonstrat - ing compliance. To date, the only adopted European cybersecurity certification scheme is the EUCC (Euro - pean Cybersecurity Certification Scheme on Common Criteria), which primarily targets ICT products. Howev - er, ENISA is currently developing additional certifica - tion schemes covering cloud services, 5G networks, digital identity wallets and managed security devices. Should the European Commission exercise its power to mandate the use of European cybersecurity certi - fications for products listed in Annex IV of the Cyber Resilience Act, and if such certifications become more widely available, the CSA certification framework
107 CHAMBERS.COM
Powered by FlippingBook