CER Act in Finland: New Resilience Obligations for Critical Entities
Act on the Protection of Infrastructure Critical to Society and on the Improvement of Resilience (310/2025) (”the CER Act”) entered into force on 1 July 2025. The CER Act implemented at the national level the EU Directive on the resilience of critical entities (“the CER Directive”), which entered into force on 16 January 2023. The CER Directive was prompted by changes in Europe’s security and operational environment and an increased emphasis on preparing for new, diverse threats. The requirements of the CER Directive apply to operators that form the backbone of society, where serious disruptions or crises could lead to large-scale societal, economic, and security-related problems.
The national CER Act imposes obligations on companies and other entities providing essential services in specified sectors that have been designated as critical entities through a separate administrative decision. The first decision on designating entities as critical entities had to be made by 17 July 2026. An entity can be designated as critical if it (i) provides an essential service to the functioning of society, (ii) operates in Finland and its infrastructure is located in Finland and (iii) a disruption affecting its infrastructure would have significant disruptive effects on the entity’s service provision or on the services of dependent sectors. In determining which entities are critical, consideration is also given to the national plan on the resilience of critical entities, the national risk assessment concerning critical infrastructure and the resilience of critical entities, as well as cross-border activities and European commensurability. The decision to designate an entity as critical is made by the ministry responsible for the sector, and the decision is valid for a maximum of four (4) years at a time. The decision may also be revoked if the entity no longer meets the requirements. Since the decision to designate an entity as a critical entity is communicated separately to each entity that meets the requirements, an entity cannot unknowingly fall within the scope of the CER Act.
The cybersecurity obligations of critical entities under the CER Act are regulated in the Cybersecurity Act (124/2025). A critical entity under the CER Act is subject to the provisions of the Cybersecurity Act applicable to essential entities, regardless of its size, even if, prior to the decision designating it as a (CER) critical entity, it (i) had not fallen within the scope of the Cybersecurity Act, or (ii) had fallen within the scope of the Cybersecurity Act as a so-called important entity. CER entities must therefore also comply with the obligations of the Cybersecurity Act within the established timeframes.
Obligations for Critical Entities Under the CER Act
Critical entities are subject to obligations set forth in the CER Act, which can be summarised as risk management and reporting obligations. Critical entities must carry out a risk assessment, draw up a resilience plan and notify the competent authority of significant incidents that disrupt or have the potential to disrupt the provision of essential services. As part of risk management, entities must pay attention to, among other things, the protection of physical infrastructure, administrative security and continuity management.
A critical entity must assess the risks to its operations. The assessment must cover essential services, supply chains and dependencies. The risk assessment must be carried out for the first time within nine (9) months after being designated as a critical entity. The entity must update the risk assessment as circumstances or risk developments require, and at least every four (4) years.
A critical entity must also draw up a resilience plan within twelve (12) months of completing the risk assessment. In addition, the entity must designate an official contact point responsible for the flow of information between the authorities and the entity. As part of the resilience plan, the entity must ensure that it has designed and implemented measures to respond to and recover from deviations or disruptions.
A critical entity must notify the relevant supervisory authority and the Government Situation Centre of any significant deviation that disrupts or may disrupt the provision of essential services. The entity must submit an initial report on the detection of the deviation to the supervisory authority and the Government Situation Centre without unnecessary delay, but no later than twenty-four (24) hours after detection, unless reporting is practically impossible. If necessary, the entity must prepare a detailed report on the deviation for the authority no later than one (1) month after the deviation is detected.
Supervising Authorities and Sanctions
Critical entities are supervised by several different authorities, depending on the sector:
- the Energy Authority: the energy sector
- Economic Development Centre of Southeast Finland: drinking water and wastewater
- the Finnish Transport and Communications Agency (Traficom): the transport sector
- the Finnish Medicines Agency (Fimea): research, manufacture, and sale of medicines and medical devices, as well as blood establishments
- the Finnish Food Authority: food production, processing, and distribution
- the Finnish Safety and Chemicals Agency (Tukes): oil, hydrogen, and gas operators in the energy sector (excluding those subject to supervision by the Energy Authority)
- the Finnish Supervisory Agency: social welfare and health care
Failure to comply with the obligations under the CER Act may result in a notice, a written warning, a conditional fine, or a negligence fee of EUR 2,000–20,000. However, a negligence fee may not be imposed if the negligence is minor or the fee would be manifestly unreasonable, if more than five (5) years have passed since the negligence occurred, or if the operator has responded to the negligence on its own initiative and without delay, and the negligence is not recurring.
For more information please contact
-
Markus PulkkinenSenior Associate
Attorney-at-Law -
Toni TainioAssociate
Master of Laws