28.3.2023

Cybersecurity directive NIS2 sets out new obligations for enterprises in critical sectors

The new cybersecurity directive NIS2 recently entered into force in the European Union. It aims to harmonise cybersecurity-related requirements and the implementation of cybersecurity measures between Member States. The NIS2 Directive replaces the earlier NIS cybersecurity directive. The obligations included in NIS2 must be transposed into national law by October 2024, and the Ministry of Transport and Communications launched the national implementation at the start of this year.

Regulated industries and operators

In addition to public entities, the NIS2 Directive lays down obligations mainly for large and medium-sized enterprises in critical sectors. Critical sectors under NIS2 include, for example, energy, finance, healthcare, transport and digital infrastructure. Certain highly critical enterprises would be subject to the obligations regardless of their size.

New obligations to the management bodies of entities under the Directive’s scope

One of the aims of the NIS2 Directive is to ensure a high level of responsibility for the cybersecurity risk-management measures and reporting obligations at the level of the entities under the Directive’s scope. With this in mind, NIS2 sets out new obligations for the management bodies of such entities.

NIS2 does not define management bodies in more detail; this will be a task for national legislators instead. However, based on the different language versions and the wording of NIS2, we find it likely that in Finland, these obligations would concern at least the boards of entities. Nevertheless, we will only know the exact definition when the draft bill for national legislation is published.

As for the obligations, the management body must approve the cybersecurity risk-management measures taken by the entity and oversee their implementation. The minimum requirements for such measures are laid down in more detail in NIS2, but they include at least the following:

Members of management bodies are also required to follow cybersecurity training in order to better identify potential cybersecurity risks and assess cybersecurity risk-management practices.

Liability rules extended to individual representatives of entities

NIS2 requires that Member States enforce a number of sanction mechanisms – such as administrative orders or fines – for infringements of the NIS2 Directive’s obligations. In certain situations, the new Directive extends liability rules from entities to their individual representatives.

Members of management bodies could be personally liable in case they neglect their obligation to ensure compliance with the entity’s cybersecurity obligations. When certain conditions are met, persons in management positions could also be temporarily suspended.

Now is a good time to start preparing for the changes

All in all, the NIS2 Directive sets out a number of new obligations for the critical sector entities under its scope. NIS2 also expects the management bodies of such entities to take on a more active role in ensuring cybersecurity. In future, individual members of management bodies can be held personally liable if they are unable to ensure compliance with the cybersecurity obligations under NIS2.

The obligations under NIS2 will only be fully outlined with national implementation, which must be completed by October 2024. However, entities falling under the Directive’s scope should start evaluating their cybersecurity practices and risk-management measures in good time, also with respect to their supply chains.

Latest references

We are acting as Finnish legal advisor to HANZA in connection with its acquisition of Fortaco Finland’s heavy mechanics and assembly business. The transaction is structured as a combined asset and share acquisition and includes Fortaco Finland’s heavy mechanics and assembly operations in Finland, as well as shares in two Estonian and two Polish subsidiaries. The transaction is expected to close during the fourth quarter of 2026, subject to customary closing conditions, including regulatory approvals. Founded in 2008, HANZA is a Swedish mechanical engineering and electronics contract manufacturing company listed on the Nasdaq Stockholm main list. HANZA has approximately 5,000 employees and annual sales of SEK 10 billion. We advise HANZA on this transaction in collaboration with the Swedish law firm Lindahl.
Case published 15.7.2026
We acted as Finnish counsel to RVRC Holding AB (RevolutionRace) in its acquisition of 90.1% of the shares in ICANIWILL AB (ICIW). Mannheimer Swartling (Sweden) acted as lead counsel for RevolutionRace. ICIW, founded in Sweden in 2012, is a Swedish training apparel brand.  RevolutionRace is a fast-growing Swedish outdoor brand offering multifunctional products to people with an active lifestyle. The company operates with a digital D2C business model reaching customers in approximately 40 countries. The company is listed on Nasdaq Stockholm since 2021. 
Case published 14.7.2026
We advised Efima Oyj on the sale of its financial management services business to Rantalainen as part of its strategic focus on fully concentrating on the delivery of business applications as well as data and AI solutions. As a result of the transaction, customer contracts related to financial management services and 65 experts working in these services will transfer to Rantalainen. The transaction will be carried out as a transfer of business, and the experts will move to the new owner as existing employees. Efima is a Finnish digital company that supports the sustainable growth of large and mid-sized companies by streamlining their business processes and by creating competitive advantage through the innovative use of artificial intelligence and data. The company has nearly 200 experts based in Helsinki and Tampere.
Case published 12.6.2026
We advised G&W Electric with its acquisition of Safegrid Oy, a leading provider of intelligent grid monitoring solutions based in Finland. The acquisition accelerates G&W Electric’s long-term strategy to integrate intelligent monitoring and predictive analytics into its power distribution portfolio, strengthening its offering to utility customers worldwide. Founded in 1905 and headquartered in Bolingbrook, Illinois, G&W Electric is a global leader in innovative power grid solutions, with a presence in over 100 countries. The company is known for advanced load and fault interrupting switches, reclosers, sensors, system protection equipment, power grid automation, intelligent grid monitoring, and transmission and distribution cable accessories. Safegrid is a Finnish technology company headquartered in Espoo, Finland. The company develops the Intelligent Grid System®, a grid monitoring solution that combines instant-on wireless sensors with advanced analytics to deliver real-time insight into grid conditions, enabling utilities to identify emerging issues, anticipate failures, and reduce outage duration across medium and high voltage distribution and transmission networks.
Case published 8.5.2026