Finland enacts Cyber Resilience Act to bolster product cybersecurity
On June 1, 2026, Finland's national act on cyber resilience came into force, introducing stringent cybersecurity requirements for products with digital elements. This legislation aligns with the European Union's Cyber Resilience Act (CRA) and aims to enhance the security of software and hardware available in the market.
Key Provisions of the Cyber Resilience Act
- Product-Level Cybersecurity Requirements: Manufacturers are mandated to design and develop products with robust security measures, ensuring compliance with the CRA.
- Vulnerability Reporting: Starting September 11, 2026, manufacturers must report any actively exploited vulnerabilities and severe security incidents to the National Cyber Security Center Finland (NCSC-FI) within 24 hours of detection.
- Market Surveillance: The Finnish Transport and Communications Agency (Traficom) is designated as the authority responsible for supervising and enforcing compliance with the CRA in Finland.
Implications for Manufacturers and Importers
Entities involved in the production and distribution of digital products must ensure their offerings meet the new cybersecurity standards. This includes implementing secure design practices and establishing protocols for rapid vulnerability reporting. Non-compliance may result in administrative sanctions and impact market access within the EU.
Consumer Impact
For consumers, this legislation promises enhanced security in digital products, reducing the risk of cyber threats and data breaches. The act aims to foster trust in digital products by ensuring they adhere to high cybersecurity standards.
This reform is part of Finland's commitment to strengthening national and EU-wide cybersecurity frameworks, reflecting the growing importance of digital security in an increasingly connected world.