M67 (Määräys teletoiminnan tietoturvasta — Regulation on information security in telecommunications operations) is Finland’s binding technical regulation for the information security of public telecommunications. It is issued by Traficom (Finnish Transport and Communications Agency) under the Act on Electronic Communications Services (917/2014), sections 244, 247 and 272, and implements obligations stemming from the European Electronic Communications Code (Directive (EU) 2018/1972, Article 40) and the ePrivacy Directive (2002/58/EC, Article 4). The familiar “M67” label dates from FICORA’s Regulation 67 A/2015 M (4 March 2015). Traficom issued a full rewrite on 16 February 2024; it entered into force on 1 September 2024 (with cryptography, testing/assessment, and 3GPP standards obligations applying from 1 December 2024) and repealed the 2015 text. Unlike voluntary frameworks (ISO 27001) or product certification schemes (EUCC, NESAS), M67 is mandatory for in-scope operators, supervised by Traficom / NCSC-FI, with sanctions under AECS sections 330–332, 340 and 349. There is no separate “M67 certificate”: operators must implement, document, and continuously maintain compliance.
The regulation applies to public telecommunications services — Finnish telecommunications operators providing public communications networks and publicly available communications services. Limited interface-protection duties also reach public authority networks where they interconnect to the public network. Chapter 2 sets horizontal duties across the network/service lifecycle: information security and risk management (including supply chain, virtualisation, and edge computing), personnel security, system/telecom and physical security, secure operations and change management, testing and security assessments, threat awareness, information classification, customer identification before security-sensitive changes, IP address registry documentation, and hardened management-plane traffic. Mobile operators must implement the security requirements of the 3GPP SCAS specifications listed in Annex 1 for LTE, 5G, and IP-based public telephony (latest applicable 3GPP version), or document justified non-implementation per requirement. Chapters 3–6 add service-specific controls: interface hardening and IP interconnection security (routing anomaly detection, anti-spoofing, ROA/RPKI), internet access traffic separation and malicious-traffic filtering (including connection disconnection as a last resort), SMS/MMS filtering, and email security (no open relays, abuse contacts, encrypted authenticated mailbox access). The 2024 revision specifically targets 5G architecture (including network slicing and edge computing), SMS/MMS abuse, customer-identity takeover risks, and routing security at IP peering points.
Adjacent Finnish rules (not M67). Continuous monitoring and incident/disturbance notification are primarily Traficom Regulation 66 (Disturbances in telecommunications services), which requires operators to constantly monitor networks and services for events that disturb or threaten functionality or information security, and to notify Traficom and users of significant incidents — complementary to M67, not part of it. The December 2026 expansion to certain 5G base stations is likewise a different instrument: Traficom’s Regulation on critical parts of a communications network (issued 19 December 2025, in force 19 December 2026) requires operators to identify, assess, and document critical network parts, including 5G base stations that materially control access or traffic (for example Rel-18+ radio-network autonomy or AI/ML-based control). That regulation’s explanatory material treats M67 as the separate infosec minimum-requirements rule. Finland’s NIS2 transposition is the Cybersecurity Act (124/2025) (in force 8 April 2025); it runs alongside AECS and Traficom telecom regulations rather than replacing M67. Terms such as “drift detection” do not appear in M67 — the closest duties are continuous risk treatment, change and configuration management, and security assessments of policy realisation.
Red Hat does not hold an M67 product certification — the duty sits with the Finnish telecommunications operator — but Red Hat platforms are widely used under those operators’ M67 programmes, especially for cloud-native 5G core and telco edge. M67’s emphasis on virtualisation least privilege, edge isolation, management-plane protection, cryptography, continuous risk treatment, and 3GPP SCAS-aligned security maps to RHEL hardening (SELinux, system-wide crypto policies, FIPS-capable modules, OpenSCAP), OpenShift isolation and network policy, the Compliance Operator for continuous configuration evidence, RHACS for runtime threat detection, and Red Hat’s telco positioning alongside vendors whose network functions undergo SCAS/NESAS evaluation. For Finnish operators running CNFs on OpenShift, Red Hat supplies the platform controls and audit artefacts that operators fold into their Traficom-facing documentation — policy, risk records (retained at least three years), change management, and security assessment evidence — rather than a Finland-specific Red Hat attestation.
Additional Information#
- Traficom / NCSC-FI — Information security
- Regulation on information security in telecommunications operations (Finlex PDF, EN)
- Traficom announcement — updated M67 in force 1.9.2024 (FI)
- Regulation 66 A/2019 M — Disturbances in telecommunications services (EN)
- Critical parts of a communications network — Traficom (in force 19.12.2026)
- Traficom — 5G base stations brought within critical-parts regulation (19.12.2025)
- Cybersecurity Act / NIS2 obligations enter into force 8 April 2025 — Traficom