08/31/2026 | Press release | Distributed by Public on 09/01/2026 05:28
The Ministry of Transport and Communications published its final report on the monitoring and evaluation of the Cybersecurity Act on 31 August 2026. The Act is generally regarded as successful, and its implementation has strengthened cybersecurity among organisations. A lack of resources among the authorities has presented challenges to the implementation of the Act.
The Cybersecurity Act monitoring project evaluated the achievement of the objectives of the Act and its application during the first year that it was in force. The Act entered into force in April 2025, implementing the EU Cybersecurity Directive (NIS 2). The supervisory authorities responsible for overseeing compliance with the Cybersecurity Act were interviewed for the purpose of monitoring, and an open online survey was also conducted. As part of the project, the Ministry also commissioned interviews with entities falling within the scope of the Act. At the time of the evaluation, the Act has been in force for approximately one year, which limits the detailed evaluation of the achievement of its objectives.
The monitoring and evaluation of the Cybersecurity Act is part of the Ministry of Transport and Communications' follow-up evaluation plan for legislation from 2026 to 2030.
According to the monitoring report, the Cybersecurity Act is generally regarded as clear, necessary and successful in its key aspects in relation to its objectives. The obligations set out in the Act are regarded as proportionate and up-to-date. The Act has made risk management more systematic and increased awareness of cybersecurity. It has also promoted the development of risk management and investments in organisations falling within the scope of the Act. However, the impacts of the Act on technical risk management are indirect and vary based on the operator's size and the starting level of cybersecurity. The project did not identify any urgent or extensive needs for amending the Cybersecurity Act.
The lack of resources among the authorities is a challenge with regard to the supervision and implementation of the Cybersecurity Act. According to the authorities, the comprehensive and effective supervision of the Act and increasing guidance and advice for operators is challenging with the current resources. The authorities have had to prioritise their supervisory activities to a significant extent.
Guidance and advice by the authorities is a key aspect of implementing the obligations set out in the Act. The entities falling within the scope of the Act regard guidance from the authorities as important and would like to see more of it. Cooperation between the authorities has been a strong point in the supervision and implementation of the Act. Supervisory activities have, for the most part, got off to a successful start within the scope permitted by the available resources.
According to the report, the development of a centralised national incident reporting system would benefit the entities falling within the scope of the Cybersecurity Act. The surveyed organisations would like incident reporting to be developed so that the same notification could also be used to fulfil reporting obligations under other regulations. It is assessed that developing the system would streamline the reporting of incidents and reduce the administrative burden associated with it.
The Cybersecurity Act implements the Directive on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). The aim of the Directive is to strengthen cybersecurity in critical sectors at the EU and national level. Entities falling within its scope of application must assess and manage the risks posed to the security of their communication networks and information systems. They are also required to notify the authorities of any significant incidents and report information to the supervisory authorities. The Directive applies primarily to medium-sized and large organisations operating in the sectors specified in the Annexes to the Directive.
The Cybersecurity Act sets out obligations in accordance with the NIS 2 Directive concerning organisations' risk management and the reporting of significant incidents. The provisions also cover other official duties required by the implementation, including the supervision of the obligations.
On 19 November 2025, the European Commission published the Digital Omnibus proposal, which aims to simplify the EU's digital regulation. As part of the Digital Omnibus, the Commission proposed the development of procedures concerning incident reporting in accordance with the NIS 2 Directive and the introduction of a single-entry point for the fulfilment of reporting obligations.
The Ministry of Transport and Communications will continue to monitor the application of the Cybersecurity Act and assess whether it remains up-to-date as part of the continuous monitoring of the effectiveness and functionality of legislation and the regulatory environment within its government branch.
Veikko Vauhkonen, Senior Officer for Legal Affairs, tel. +358 295 342 168, [email protected]
Katariina Kilpeläinen, Ministerial Adviser, tel. +358 295 342 328, [email protected]