news

NIS2 Finland one year later

Geschreven door Key2XS | Sep 7, 2026, 7:00:00 AM

Finland Shows What Happens When NIS2 Becomes Law

 

One year after Finland implemented NIS2, the first evidence is emerging: regulation is changing behaviour, increasing cybersecurity maturity and driving actual investment.

That matters far beyond Finland. For organisations operating critical infrastructure across Europe, NIS2 and the Critical Entities Resilience Directive, CER, are moving from regulatory programmes to operational reality. And as this happens, an important question emerges.

What happens when governance requirements move beyond IT and reach the physical infrastructure itself?

Finland provides an early answer. Finland implemented NIS2 through its national Cybersecurity Act in April 2025. On 31 August 2026, the Finnish Ministry of Transport and Communications published the results of its first evaluation of the legislation.

The legislation is generally considered successful. It has increased cybersecurity awareness, made risk management more systematic and encouraged organisations within its scope to further develop their risk management capabilities.

More importantly, the Ministry reports that the legislation has promoted investment in affected organisations.  This is significant. For years, European cybersecurity regulation has been discussed primarily in terms of compliance. Finland's first year of practical experience suggests something more fundamental is happening.

From compliance to operational controls

Regulation does not automatically make infrastructure more resilient.Policies do not protect substations. Risk assessments do not control access to water treatment facilities. Compliance reports do not prevent an unauthorised contractor from opening a cabinet containing critical equipment.

Eventually, governance has to translate into operational controls. The Finnish evaluation already shows the beginning of that transition. The Ministry notes that the impact of the Cybersecurity Act on technical risk management remains indirect and differs depending on the size and cybersecurity maturity of the organisation. At the same time, organisations are investing and developing their risk management capabilities. 

This is exactly what should be expected during the first phase of regulatory implementation. The first question is: Do we have the right policies? The next question becomes: Can we prove that those policies are actually enforced?
That second question is much harder.

And then comes CER

This is where the European Critical Entities Resilience Directive changes the discussion. NIS2 primarily addresses cybersecurity risks associated with networks and information systems. CER addresses the resilience of the critical entity itself.

Finland implemented CER through its Act on the Protection of Infrastructure Critical to Society and on the Improvement of Resilience, which entered into force on 1 July 2025. It covers sectors including energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, public administration, space and food. 

The Finnish legislation requires designated critical entities to perform risk assessments, establish resilience plans and implement the necessary measures. Finland has also deliberately connected the two regulatory regimes.

Amendments effective from 1 July 2025 extended the Cybersecurity Act to organisations designated as critical entities under the CER legislation, including organisations that might otherwise have fallen outside the scope of the Cybersecurity Act.  This is an important development. Cyber resilience and physical resilience are no longer separate governance discussions. They are becoming part of the same risk management framework.

The identity question moves into the physical world

Consider an electricity network operator. An engineer may have access to applications, operational systems and sensitive information. Identity Governance and Administration systems can determine:

- Who is the person?
- What is their role?
- What systems may they access?
- Who approved that access?
- When should access expire?
- What happens when they leave the organisation?

But the same engineer may also hold an electronic key providing access to substations, transformer stations, cabinets or other critical infrastructure. Suddenly, exactly the same governance questions apply.

- Who is the person?
- What physical assets may they access?
- Why do they have that access?
- Who approved it?
- For how long?
- Was the access actually used?
- And most importantly: When their role changes or employment ends, is physical access revoked at the same time as digital access?

For many organisations, the answer to that final question is still no.

The governance gap

Over the past twenty years, enterprises have invested heavily in digital identity governance. Joiner, mover and leaver processes have been automated. Access requests are governed. Segregation of Duties can be enforced. Privileges can be reviewed. Access can automatically expire.

Physical key management often operates differently.
Keys may be administered through separate lock management platforms, spreadsheets, local databases or manual processes. Different facilities may use different lock manufacturers. Contractors may receive physical access outside the organisation's central identity governance processes.

This creates a governance gap. The employee's digital access might disappear automatically at 17:00 on their final working day. Their physical key may still open a critical infrastructure asset the next morning.

From an identity governance perspective, that distinction makes increasingly little sense.

Physical access becomes an identity decision

The logical consequence is that organisations will increasingly need to apply identity governance principles to physical access. At Key2XS, we describe this as Physical Access Governance.

The principle is simple: Every access decision to a Critical Infrastructure Asset should be an Identity Decision. The Identity Governance platform remains responsible for identity, policy, roles, approvals and lifecycle management. The electronic locking infrastructure remains responsible for securing the physical asset. Between them, a governance layer translates identity decisions into physical access rights and returns access information for governance, monitoring and audit.

Conceptually: Identity → Policy → Approval → Physical Access → Evidence

This creates one governance model across digital and physical access without requiring organisations to replace their existing Identity Governance platforms or electronic locking infrastructure.

Multi-vendor becomes important

There is another practical reality. Critical infrastructure organisations rarely operate a single homogeneous physical access environment.

An energy company, railway operator, municipality or water utility may have accumulated several generations of mechanical and electronic locking technology across thousands of geographically distributed assets.

That means Physical Access Governance cannot simply become another feature of an individual lock management system. The governance layer needs to operate independently from the underlying lock technology. The same identity policy should ultimately be capable of governing access across multiple electronic locking environments. That is comparable to what happened in digital identity.

Identity Governance platforms did not replace Active Directory, SAP, Salesforce or thousands of enterprise applications. They governed access across them.
Physical access is beginning to follow the same architectural pattern.

Finland is an interesting leading indicator

Finland is particularly interesting because its regulatory implementation is already relatively mature. The Finnish CER Act required the first designation of critical entities by 17 July 2026. In July, the Finnish Government reported that this identification process was nearing completion. 

Once designated, entities must conduct their first risk assessment within nine months of notification. A resilience plan must subsequently be prepared within one year of completing that assessment.  That creates a very tangible regulatory timeline. And Finland's experience with NIS2 provides an indication of what may happen next.

First comes legislation. Then governance. Then risk assessment. Then organisations discover gaps between policy and operational reality. And finally: Investment follows.

Enforcement capacity is not unlimited

The Finnish evaluation also identifies an important problem. Supervisory authorities do not currently have sufficient resources to provide comprehensive supervision, guidance and advice to every organisation within scope. Authorities have therefore had to prioritise their supervisory activities.  That should not be interpreted as meaning enforcement does not matter.

It means something else. Organisations cannot build their compliance strategy around continuous interaction with regulators. They need systems capable of producing their own evidence. That changes the value proposition of governance technology. The objective is no longer simply to pass an occasional audit. The organisation needs to be able to demonstrate continuously:

- Who had access?
- Why did they have access?
- Who approved it?
- Which assets could they access?
- Was access still appropriate?
- Was it revoked when it was no longer required?

Doing this manually becomes increasingly difficult as the number of identities, contractors, sites and critical assets increases. Automation therefore becomes an economic requirement as much as a compliance requirement.

Europe is moving from policy to execution

NIS2 and CER should therefore not be viewed simply as another wave of European compliance legislation. Something larger is happening. Europe is establishing a governance framework for the resilience of critical infrastructure.

NIS2 established cybersecurity obligations. CER extends resilience thinking into the organisation and its physical infrastructure.

Identity governance provides a mature model for controlling digital access. The next logical step is to extend that governance model to the physical assets on which essential services depend.

Finland's first NIS2 evaluation provides an early indication of how quickly regulation can change organisational behaviour. The Finnish Government reports greater awareness. More systematic risk management. Improved cybersecurity capabilities. And actual investment.

The next phase will be about turning those investments into demonstrable operational controls. For physical critical infrastructure, that means answering one deceptively simple question:

If identity determines what someone is allowed to do digitally, why shouldn't identity also determine which critical infrastructure they are allowed to physically access?

That is where Physical Access Governance begins.