NIS2 training requirements in Finland

Finland's Cybersecurity Act 124/2025 makes cybersecurity training part of risk management. Who is in scope, what the Act requires and how to evidence it.

Updated

In short

Finland transposed the NIS2 Directive (EU) 2022/2555 with the Cybersecurity Act (kyberturvallisuuslaki, 124/2025), in force since 8 April 2025. Section 9(2)(6) requires an entity's risk-management model to cover personnel security and cybersecurity training. Section 10 requires the management to have adequate familiarity with cybersecurity risk management.

The Act does not set hours, frequency or a syllabus. Measures must be proportionate to the risks, and the entity describes them in its own risk-management model. This guide cites the Act's sections directly so you can check each point.

Who is in scope

The Act applies to an entity that carries out an activity listed in its Annex I or II and is at least a medium-sized enterprise under Commission Recommendation 2003/361/EC (section 3). The annexes cover sectors such as energy, transport, health, drinking and waste water, digital infrastructure, ICT service management, postal services, waste management, chemicals, food, manufacturing and digital providers.

A small enterprise has fewer than 50 staff and a turnover or balance sheet of no more than €10 million. Size does not decide everything: providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers are in scope regardless of size, and so is an entity in an Annex I or II sector whose service is, for example, critical to society and not offered by others, as well as one designated a critical entity (section 3(2)–(3)).

Public administration's NIS2 duties are in a separate act, the Information Management Act (906/2019). Where an EU regulation such as DORA for the financial sector sets at least equivalent requirements, it applies instead of the Act's chapters on risk management and reporting, supervision and penalties (chapters 2, 4, 5 and section 41; section 5(2)).

Essential and important entities

The Act uses keskeinen toimija (essential entity); important entities are simply muu kuin keskeinen toimija, an entity other than an essential one. Tärkeä toimija is the Directive's Finnish term, not the Act's. Essential entities include large enterprises in Annex I sectors and, regardless of size, qualified trust service providers, TLD name registries and DNS service providers (section 27(2)). Other entities in scope are important entities.

The obligations, training included, are the same for both. The difference is supervision and penalties. Supervisors target essential entities proactively and important entities when there is reason to suspect non-compliance (section 27). The administrative fine is up to €10 million or 2 % of worldwide turnover for an essential entity, and up to €7 million or 1.4 % for others, whichever is higher (section 38).

What section 9 says about training

Section 9(2) lists twelve areas the risk-management model and its measures must cover and keep up to date. Point 6 is personnel security and cybersecurity training. The Directive's equivalent is in Article 21, on cybersecurity risk-management measures.

Measures are scaled to the nature and extent of the activity, the risks, the likelihood and severity of incidents, and cost (section 9(3)). In practice, your training should address the risks your own assessment identified. For some digital providers, such as cloud, data centre and managed service providers, Commission Implementing Regulation (EU) 2024/2690 adds detail, including a section on basic cyber hygiene practices and security training.

Training for the management

NIS2 Article 20(2) requires members of management bodies to follow training. The Finnish Act chose different wording: section 10 requires the management, meaning the board, supervisory board, CEO and anyone in an equivalent position who actually runs the entity, to have adequate familiarity with cybersecurity risk management. The management also approves the risk-management model and oversees its implementation.

Finland does not literally require every board member to attend a course, but supervisors can request information (section 28), so be ready to show it; training is the usual way to acquire and evidence it. For an essential entity, a person who repeatedly and seriously breaches section 10 can be temporarily barred from management roles after a warning (section 32).

How to evidence training

Supervisors can request information and carry out inspections (sections 28 and 29), and can order a security audit after a significant incident that caused a serious disruption or considerable damage, or after a material and serious failure to comply (section 30). A fine can follow if the section 9(2) measures are neglected intentionally or through gross negligence (section 35). Keep a record that would satisfy an auditor.

  • A training plan inside the risk-management model: who, what and how often
  • The link to your risk assessment: why these topics
  • Dated completion records per person
  • Evidence of knowledge, not just attendance, such as question results
  • Management approval and follow-up under section 10
  • A change history: when content was updated and why

Who supervises

Supervision is sectoral: Traficom, the Energy Authority, Tukes, the Finnish Food Authority, Fimea, Elinvoimakeskus for water, and since 1 January 2026 the Licensing and Supervisory Agency (Lupa- ja valvontavirasto) for health care and waste management. Traficom's National Cyber Security Centre (Kyberturvallisuuskeskus) is the CSIRT for everyone, but incident reports go to your sector's supervisor (section 11), in practice through the Centre's NIS2 incident notification application.

How Cyberact helps

Cyberact is Finnish security and AI training in two-minute daily lessons, with spaced repetition to keep it remembered, in Finnish and English. The manager console turns completions and knowledge into a report you can hand to an auditor or supervisor. Start for free at cyberact.io: your account is ready at once.

Sources

Checked against primary sources on 24 September 2026.

  • Cybersecurity Act 124/2025 with amendments 369/2025, 494/2025, 698/2025 and 997/2025 (Finnish), Finlex: https://www.finlex.fi/fi/lainsaadanto/2025/124
  • NIS2 Directive (EU) 2022/2555, EUR-Lex: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
  • Commission Implementing Regulation (EU) 2024/2690, EUR-Lex: https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj
  • Traficom National Cyber Security Centre, NIS2: https://www.kyberturvallisuuskeskus.fi/en/our-activities/regulation-and-supervision/nis2-european-union-cybersecurity-directive

Frequently asked questions

Is cybersecurity training mandatory under NIS2 in Finland?
Yes, for entities in scope of the Cybersecurity Act 124/2025. Section 9(2)(6) requires the risk-management model to cover personnel security and cybersecurity training. The Act does not prescribe format, length or frequency.
How often must NIS2 training be repeated in Finland?
The Act sets no interval. The Act requires the risk-management model and its measures to be kept up to date. Short, continuous training meets this better than a once-a-year course.
Do board members have to take cybersecurity training in Finland?
Section 10 of the Finnish Act requires the management to have adequate familiarity with cybersecurity risk management, rather than NIS2 Article 20(2)'s explicit training duty. Training is the usual and most demonstrable way to meet it.
What are the NIS2 fines in Finland?
Up to €10 million or 2 % of worldwide annual turnover for essential entities, and up to €7 million or 1.4 % for other entities in scope, whichever is higher (section 38). Fines are imposed by a sanctions board at Traficom on the supervisor's proposal (section 36).
What is the Finnish term for an essential entity?
Keskeinen toimija. The Cybersecurity Act 124/2025 calls other entities in scope muu kuin keskeinen toimija; tärkeä toimija, important entity, is the term in the Finnish text of the NIS2 Directive.

Read next

Training your team will actually finish

Cyberact teaches security and practical AI in two minutes a day, and keeps a record of what each person knows.