Is your cybersecurity compliant with the NIS2 Directive?

The updated European Union’s NIS2 Directive entered into force in spring 2025. In Finland, the national version of this is the Cyber Security Act 124/2025. In Finland, Traficom provides guidance and supervision on compliance with the requirements of the Directive together with other sector-specific authorities.

NIS-2 supply chain obligations from customers to us

The NIS2 obligations include up-to-date cyber security risk management of communications networks and information systems, as well as reporting obligations. The requirements also include cybersecurity practices for the supply chain and the products and services they deliver. In practice, the requirements apply to almost all of our customers who operate in industries that are very critical from the perspective of the directive. These requirements therefore also extend to us, i.e. our operations and products, through our customers.

Software supply chain risk management starts by selecting suppliers who commit to high security requirements and transparency in terms of software quality and development processes

We meet these requirements – Ontec is ISO 27001 certified

NIS2 DIRECTIVE

  • European Union Network and Information Security Directive (NIS)
  • Published 2016, updated version effective as of 8.4.2025
  • Sets goals for information security measures and general information security

Are you a NIS2 operator? – Check the NCSC-FI on Traficom’s website:

https://www.kyberturvallisuuskeskus.fi/en/our-activities/regulation-and-supervision/nis2-european-union-cybersecurity-directive

ISO 27001 and NIS2

With a few exceptions, the requirements and objectives of ISO 27001 and NIS2 for cybersecurity are very similar. The main difference, however, lies in the principle of operation: the ISO standard provides tools and procedures for fulfilling these obligations, while NIS2 only sets requirements. In other words, the standard is a tool for meeting the requirements of the directive and at the same time a way to show that the company’s operations are already at the level of the requirements.

ISO 27001 STANDARD

  • Information Security Management System Standard
  • Latest edition SFS-EN ISO/IEC 27001:2022
  • Provides organizations with a structured framework for building, maintaining, and developing a management system
  • Risk-based approach to information security management and continuous improvement

Ontec Oy is ISO 27001 certified

Into Certification has audited Ontec Oy’s information security management system and found that it meets the requirements of the ISO/IEC 27001:2022 standard.

IISO 27001 is the best-known international standard for information security management systems (ISMS). It specifies in detail the requirements for establishing, implementing, maintaining, monitoring and continuously improving an enterprise information security management system.

The certificate shows that our company meets the requirements of the NIS2 directive for the supply chain

Why Ontec

Ontec invest heavily in product development and continuously collect feedback from our customers on our products. We actively monitor the development of the industry and pay special attention to the ease of use and reliability of our products. Ontec is a leading expert in our field and have invested especially in MID expertise since 2004.

Total deliveries

MID and ATEX turnkey supplier, software and control system modules are the result of consistent product development.

Strengths

Know-how, agility, and response time, as well as overall management, we know the customer’s production process, we can offer customers comprehensive solutions.

CyberSecurity

OntecCyberSecurity takes into account all aspects of corporate security. Build your company’s security from the inside out on multiple levels and with mutually supportive solutions.