FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
Clearly defined roles and responsibilities for differ - ent actors in both the public and private sectors are considered essential prerequisites for effective cyber resilience, and cybersecurity is recognised as a vital part of national defence. Towards a Unified Cybersecurity Approach Overall, the current regulatory strategy for cyber - security in Finland emphasises the importance of a unified approach to cybersecurity, recognising that the subject matter concerns all areas of society. At the international level, Finland strives to be a strong cybersecurity ally within the EU and NATO, actively participating in discussions on future developments. 1.2 Cybersecurity Laws The cybersecurity legislation in Finland is largely EU- based, but many details are regulated at the national level. EU regulations are directly applicable in Finland and require very limited national implementation legis - lation, if any. EU directives are not directly applicable; instead, they oblige the Finnish legislature to enact national provisions that reflect the requirements of the directives. The principal cybersecurity laws applicable in Finland are listed below. The legislation is divided into three categories: • legislation primarily concerning cybersecurity; • legislation regulating the protection of personal data, including cybersecurity requirements; and • other legislation relevant to cybersecurity. Cybersecurity The NIS 2 Directive (Directive (EU) 2022/2555) has been implemented in national legislation as described in this section. The Cybersecurity Act (124/2025, Kyberturvallisuusla- ki ) implements the NIS 2 Directive, imposing uniform cybersecurity requirements for actors operating in essential sectors, and setting out minimum cyberse - curity requirements for entities within its scope. How - ever, more specific requirements imposed by any oth - er regulation may be applied in addition to or instead of the Cybersecurity Act – for example, see below regarding the requirements for public administration.
The Act also established an institutional framework for supervision and national cyber resilience. The Act on Information Management in Public Admin - istration (906/2019, Laki julkisen hallinnon tiedonhal- linnasta ) governs, among other topics, data security, interfaces and interoperability in public administration. Chapter 4a of the Act implements the requirements for public administration set out in the NIS 2 Directive. For public administration entities, this provision applies instead of the national Cybersecurity Act. The Digital Operational Resiliency Act (Regulation (EU) 2022/2554) (DORA) creates a uniform regulatory framework for reducing cybersecurity risks within financial entities and related ICT suppliers. DORA applies primarily to financial sector entities as lex spe - cialis instead of the national Cybersecurity Act. The EU Cybersecurity Act (Regulation (EU) 2019/881) (CSA) established the EU Agency for Cybersecurity (ENISA) and the EU-wide certification system to har - monise cybersecurity requirements, increase safety and reduce parallel certification requirements for ICT products, services and processes. The Cyber Resilience Act (Regulation (EU) 2024/2847) (CRA) regulates extensively all connectible hardware and software, and introduces mandatory cybersecu - rity requirements for manufacturers and developers. One way to prove a product’s compliance with the CRA can be a certification under the CSA. The Network Code On Cybersecurity (Regulation (EU) 2024/1366) (NCCS) complements Regulation (EU) 2019/943 of the European Parliament and of the Council of 5 June 2019 on the internal market for electricity, setting out rules on cybersecurity risk management, common minimum requirements, plan - ning, monitoring, reporting and crisis management for, inter alia, certain energy sector actors and critical ICT providers in the energy sector. The Cyber Solidarity Act (Regulation (EU) 2025/38) sets up a framework for EU-level collaboration, to allow EU member states to better defend themselves against large-scale cyber-attacks.
98 CHAMBERS.COM
Powered by FlippingBook