Skip to main content
Back to overview

NIS2 in Ireland: Where the National Cyber Security Bill Stands

By NIS2Certify
NIS2IrelandNCSCNational Cyber Security BillCyFuncompliance
NIS2 in Ireland: Where the National Cyber Security Bill Stands

NIS2 is not yet law in Ireland. The National Cyber Security Bill that will transpose Directive (EU) 2022/2555 had not been enacted on 28 September 2026, so the NIS1 rules still apply and the NCSC's NIS2 registration and reporting portals are not live. The NCSC has already published the security measures it will expect.

Sources: NCSC Ireland, the Government Legislation Programme, the European Commission and the directive text on EUR-Lex. Status checked on 28 September 2026.

Key takeaways

  • No Irish NIS2 law yet. The Bill is listed for priority publication in the Government's Autumn 2026 Legislation Programme. Until it is enacted, the NIS1 regulations of 2018 (S.I. 360/2018) keep applying to designated operators of essential services.
  • The Commission has gone to court. On 8 July 2026 it referred Ireland, together with Spain, France and the Netherlands, to the Court of Justice of the EU and asked for a lump sum and daily penalties.
  • The NCSC's expectations are already public. Its draft Risk Management Measures set the minimum baseline, and it recommends the CyberFundamentals (CyFun) framework as the preferred way to show compliance.
  • Scope follows the directive: 18 sectors, 50 or more employees, or fewer if both annual turnover and balance sheet total exceed €10 million.
  • Once enacted, the directive's floors apply: incident reports within 24 hours, 72 hours and one month, fines of at least €10 million or 2% of worldwide turnover for essential entities, and management bodies that can be held liable.

Is NIS2 law in Ireland yet?

No. Member states had to transpose NIS2 by 17 October 2024, and Ireland is one of four member states the European Commission took to the Court of Justice on 8 July 2026 for not notifying full transposition (press release IP/26/1499). The Commission asked the Court to impose a lump sum and daily penalties until Ireland completes it.

Here is how far the legislation has come:

StepStatus
Cabinet decision on priority draftingJuly 2024
General Scheme of the National Cyber Security BillPublished in 2024 by the Department responsible for communications
Letter of formal notice from the Commission28 November 2024
Reasoned opinion from the Commission7 May 2025
NCSC draft Risk Management Measures and CyFun announcementJune 2025
Referral to the Court of Justice8 July 2026
Autumn 2026 Legislation ProgrammeBill listed for priority publication; drafting "ongoing"
Bill published, debated and enactedNot yet

The NCSC's own page is blunt about what that means today. The NIS2 registration portal and the NIS2 incident reporting portal are not available and will open once the legislation is in place. NIS1 remains in full effect and covers the operators of essential services already designated in Ireland.

So an Irish organisation that is newly in scope under NIS2 has no registration to complete and no NIS2 incident report to file yet. It does have a regulator that has told it, in writing, what it will be expected to do.

Who will be in scope?

The Bill will transpose the directive, so the directive's scope is the working assumption: organisations in the 18 sectors of Annexes I and II that are at least medium-sized. That means 50 or more employees, or fewer than 50 with both an annual turnover and a balance sheet total above €10 million.

The "both" matters. A 30-person Irish distributor with €12 million turnover and a €6 million balance sheet is a small enterprise under the EU definition and usually outside NIS2.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

Yes ↓No →
2

Does your organisation have 50 or more employees, or both an annual turnover and a balance sheet total exceeding €10 million?

Yes ↓No →
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

Yes ↓No →
✗

NIS2 does not directly apply to your organisation.

✓

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

Some organisations are in scope at any size, including trust service providers, TLD name registries, DNS service providers, providers of public electronic communications networks or services, and public administration bodies. The NCSC runs an Am I in Scope? tool that walks through these questions; it tells you it isn't a definitive answer, and neither is this article.

Being out of scope doesn't make you unaffected. Irish and EU customers that are in scope must manage the security of their direct suppliers under Article 21(2)(d), and that duty travels down to you through contracts. How NIS2 reaches suppliers explains what to expect.

Who will supervise you?

Under the Bill's design, the NCSC becomes the lead national authority and the national CSIRT, while sector regulators act as competent authorities for their own sectors, such as energy or communications. For public administration, the NCSC itself is the competent authority. The consequence for consultants: "who supervises this client?" can have a different answer per sector, so check it per entity rather than assuming the NCSC.

What should Irish organisations do now?

Prepare against the NCSC's published baseline now, because the law will arrive with obligations that are already known. Four steps cover most of it.

  1. Confirm scope for every entity in your group, using the directive's sectors and size test and the NCSC's tool.
  2. Read the NCSC's draft Risk Management Measures. The NCSC describes them as the minimum it believes is required to meet NIS2, aligned with the Commission's Implementing Regulation (EU) 2024/2690 for digital infrastructure providers. They tell you what to do; the framework you choose tells you how.
  3. Pick one control framework. The NCSC recommends CyFun as the preferred method, and says certification under it will be optional. ISO 27001, ISO/IEC 62443 for industrial control systems, COBIT, NIST and your own ISMS remain acceptable ways to meet the measures. If you already hold ISO 27001, map it to the RMM and close the gaps rather than starting again; NIS2 vs ISO 27001 shows where those gaps usually are.
  4. Measure the gap against Article 21. The ten measures of Article 21 are the backbone of both the RMM and CyFun. A step-by-step gap analysis gives you a dated baseline to show a board, a customer or, later, the regulator.

Two things are worth setting up before the portals open, because they take longest. The first is an incident process that can produce an early warning within 24 hours, weekends included. The second is board involvement: Article 20 requires the management body to approve the measures, oversee them and follow training, and that takes calendar time to arrange.

Don't wait for an Irish certification scheme either. The NCSC says a national certification system will take 18 to 24 months to establish, and encourages organisations to use the framework internally in the meantime.

Penalties once the law is enacted

Once the Bill is enacted, Ireland must at least meet the directive's floors: fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher (Article 34). The exact Irish amounts and procedures will be in the Act, so check them when it is published.

The fine is rarely the first measure. Supervisors can issue binding instructions, order audits and require an organisation to inform its customers. For essential entities they can also temporarily ban a person from exercising managerial functions. Management bodies can be held liable for infringements under Article 20.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
▼
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
▼
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

The commercial cost tends to arrive first. An Irish supplier that can't show its security posture to an in-scope customer elsewhere in the EU can lose the contract long before any Irish regulator gets involved.

How Ireland compares with the rest of the EU

Ireland isn't alone, but it is now in a small group. Most member states have notified their national law; the Commission's July 2026 referral named only Ireland, Spain, France and the Netherlands, and the Netherlands has since applied its law from 15 August 2026. For the rules that apply everywhere, and the status of the larger member states, read What is NIS2?.

For Irish organisations with customers or subsidiaries in other member states, that gap matters. Your Irish entity may have no NIS2 registration to do yet, while your German or Belgian subsidiary is already past its deadline.

Frequently asked questions

Is NIS2 applicable in the UK?

No. NIS2 is an EU directive and does not apply in the UK, which is reforming its own NIS Regulations 2018. A UK company is still affected through subsidiaries established in the EU, and cloud, DNS, managed service and some other digital providers that offer services in the EU must designate a representative in a member state (Article 26). For UK groups with an Irish subsidiary, that subsidiary falls under the Irish law once it is enacted.

Who needs to be NIS2 compliant?

Organisations in the 18 sectors of Annexes I and II of the directive with 50 or more employees, or with fewer employees but both turnover and balance sheet above €10 million. Some providers, such as DNS service providers and public administration bodies, are in scope at any size. In Ireland, the obligations take effect once the National Cyber Security Bill is enacted.

When will the National Cyber Security Bill be enacted?

There is no date. The Government's Autumn 2026 Legislation Programme lists the Bill for priority publication, which means the Bill itself still has to be published and pass through the Oireachtas.

Does NIS1 still apply in Ireland?

Yes. The 2018 regulations that transposed the first NIS Directive (S.I. 360/2018) remain in effect for the operators of essential services already designated in Ireland, until the new law replaces them.

Is CyFun mandatory in Ireland?

No. The NCSC recommends CyberFundamentals as the preferred way to demonstrate compliance and says certification under it will be optional. It also recognises other standards, such as ISO 27001 and ISO/IEC 62443.

Where can I find the NCSC's guidance?

On the NCSC's NIS2 page, including the NIS2 Quick Reference Guide, an FAQ and the Am I in Scope? tool. Questions can go to NIS2Queries@ncsc.gov.ie.

Want a first reading of where your organisation stands against the ten Article 21 measures? Take the free NIS2 quick scan.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.