Finland supplements EU Cyber Resilience Act to enhance smart device security
On May 28, 2026, the Finnish government approved national provisions supplementing the European Union's Cyber Resilience Act (CRA), set to enter into force on June 1, 2026. This legislation aims to improve the cybersecurity of smart devices and software by introducing mandatory requirements for manufacturers and aligning national practices with EU regulations.
Key Provisions of the Supplementary Legislation
- Market Surveillance: The Finnish Transport and Communications Agency (Traficom) is designated as the authority responsible for supervising and enforcing compliance with the CRA in Finland.
- Vulnerability Reporting: Manufacturers are required to report any actively exploited vulnerabilities and severe security incidents to Traficom within 24 hours of detection.
- Conformity Assessment Bodies: From June 11, 2026, bodies in Finland can apply to be notified for assessment tasks under the CRA, enabling them to carry out conformity assessments across EU Member States.
Implications for Manufacturers and Importers
Entities involved in the production and distribution of smart devices and software must ensure their products comply with the new cybersecurity requirements. This includes implementing secure design practices and establishing protocols for rapid vulnerability reporting. Non-compliance may result in administrative sanctions and impact market access within the EU.
Consumer Impact
For consumers, this legislation promises enhanced security in smart devices and software, reducing the risk of cyber threats and data breaches. The act aims to foster trust in digital products by ensuring they adhere to high cybersecurity standards.
This reform is part of Finland's commitment to strengthening national and EU-wide cybersecurity frameworks, reflecting the growing importance of digital security in an increasingly connected world.