Justiceface
Justiceface
Jun 19, 2026
Finland

Finland adopts national legislation to complement EU Cyber Resilience Act

On June 1, 2026, Finland enacted national legislation to complement the European Union's Cyber Resilience Act (CRA), introducing product-level cybersecurity requirements for software and hardware placed on the EU market. This move aims to enhance the cybersecurity of digital products and align national practices with EU regulations.

Key Aspects of the National Legislation

  • Designation of Authorities: The Finnish Transport and Communications Agency (Traficom) is appointed as the market surveillance and cybersecurity certification authority, responsible for supervising and enforcing compliance with the CRA.
  • Vulnerability Reporting: From September 11, 2026, manufacturers must report any actively exploited vulnerabilities and severe security incidents to Traficom within 24 hours of detection.
  • Conformity Assessment Bodies: Starting June 11, 2026, bodies in Finland can apply to be notified for assessment tasks under the CRA, enabling them to carry out conformity assessments across EU Member States.

Implications for Businesses

Manufacturers, importers, and distributors of products with digital elements must ensure their products comply with the new cybersecurity requirements. This includes implementing secure design practices and establishing protocols for rapid vulnerability reporting. Non-compliance may result in administrative sanctions and impact market access within the EU.

Consumer Impact

For consumers, this legislation promises enhanced security in digital products, reducing the risk of cyber threats and data breaches. The act aims to foster trust in digital products by ensuring they adhere to high cybersecurity standards.

This reform is part of Finland's commitment to strengthening national and EU-wide cybersecurity frameworks, reflecting the growing importance of digital security in an increasingly connected world.