NIS2 Ireland: National Cyber Security Bill 2024
Ireland has still not transposed NIS2, and on 8 July 2026 the European Commission referred it to the Court of Justice. The transposing law exists only as a General Scheme. This page sets out what that draft actually says - the nine competent authorities, the fines, the adjudication regime - and what binds Irish organisations in the meantime.
Introduction: NIS2 Directive & the Irish context
Ireland implemented the original NIS Directive (NIS1) through the 2018 NIS Regulations (S.I. 360/2018), covering a relatively small number of operators of essential services and certain digital service providers.
NIS2 widens the scope considerably and raises the bar for risk management, incident reporting and governance. Ireland’s chosen vehicle is the National Cyber Security Bill 2024, which would overhaul the existing regime, place the National Cyber Security Centre (NCSC) on a statutory footing and create a federated supervisory model with nine designated authorities.
That Bill does not exist yet. What exists is its General Scheme - a 183-page set of draft Heads published on 30 August 2024. It is unusually detailed for a General Scheme, and because almost nobody reads it, most of what is written about NIS2 in Ireland stops at “fines of up to 10 million euro”. This page works from the document itself.
Where the Bill actually is
Ireland did not meet the EU deadline of 17 October 2024 for transposing NIS2. The NCSC has confirmed that the deadline was missed and that the earlier NIS1 regulations remain in force until the new legislation is enacted.
On 24 July 2024 the Government approved priority drafting of the National Cyber Security Bill 2024, and the General Scheme was published on 30 August 2024 as the vehicle for transposition. The designation of competent authorities had already been approved by Government in December 2023.
The enforcement chain has moved on regardless. The Commission sent Ireland a letter of formal notice on 28 November 2024 and a reasoned opinion on 7 May 2025. On 8 July 2026 it referred Ireland to the Court of Justice of the European Union in case INFR(2024)0279, asking the Court to impose “financial sanctions, consisting of a lump sum and daily penalties until notification of complete transposition”. No judgment has been given.
We print no predicted enactment date. Ministerial statements about notifying transposition have been made and have already slipped more than once; a date that gets quoted back to us is worth less than an accurate description of where the file sits.
Status
Not transposed. The transposing law exists as a General Scheme only and has not been introduced as a Bill. S.I. 360/2018 continues to apply until it is replaced.
Legal structure (planned)
The National Cyber Security Bill 2024 will transpose NIS2, establish the NCSC on a statutory basis, and define the supervisory and enforcement regime, including a federated model of competent authorities.
Interim position
NIS1 remains in force for designated Operators of Essential Services. The NCSC's draft Risk Management Measures and the Cyber Fundamentals framework are the best available statement of what will be expected. See what binds you right now.
What binds you right now
“No law yet” is not “no obligations”. An untransposed directive binds the State, not private parties - Ireland’s exposure is to the Court of Justice, and a company cannot be fined under NIS2 in Ireland today. But four things already reach Irish organisations.
NIS1 is still live
The European Union (Measures for a High Common Level of Security of Network and Information Systems) Regulations 2018 - S.I. 360/2018 - remain in full effect. The NCSC confirms NIS1 “continues to apply to already designated Operators of Essential Services (OESs) within the State”.
Sector regimes that already bite
DORA for financial entities; the electronic communications security regime under the Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023, which the Scheme would partly repeal and replace; and the GDPR wherever an incident touches personal data.
Supply-chain spillover
This is the one that actually catches Irish companies. A customer in a member state that has transposed must assess the cybersecurity of its direct suppliers under its own Article 21 equivalent. That obligation reaches Irish suppliers through contract terms today, with no Irish law involved.
CER, running in parallel
The Critical Entities Resilience Directive is being transposed separately by the Department of Defence, and the Scheme expects many of the same bodies to be competent authorities under both.
Who will be in scope
Even before full transposition, Irish organisations in NIS2-relevant sectors should assume that the EU Directive’s core obligations will apply and start preparing. The future Bill is expected to closely follow the NIS2 model of essential and important entities.
Who is likely in scope?
- Entities in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
- Entities in Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
- Medium and large organisations meeting NIS2 staff/turnover thresholds.
- Entities covered regardless of size: DNS, TLD registries, trust service providers, major cloud and data-centre operators.
The two Heads that carry the big fines
Under the Scheme, the 10 million / 7 million euro ceilings attach to infringements of just two Heads:
- Head 29 - cyber security risk-management measures
- Head 15 - incident response powers and reporting obligations
Other failures are dealt with by compliance notice, and non-compliance with the notice is separately penalised under Head 37B.
Governance
Head 28 puts governance on the management board, defined in the Scheme as "a body of group of individuals vested with the authority and responsibility for the oversight, direction and control of an entity". Head 43 provides for offences by a body corporate, reaching officers who consented to or connived in the breach.
RMMs, CyFun & the Irish certification scheme
The NCSC has not waited for the legislation to say what good looks like. On 24 June 2025 it published draft Risk Management Measures (RMMs) under Article 21 and announced that Ireland is adopting the Cyber Fundamentals (CyFun) framework.
Draft RMMs
Not binding, but they are the NCSC’s own statement of the controls it expects, written against Article 21. They are the most reliable planning document available in Ireland today.
CyFun is Belgian in origin
The Cyber Fundamentals framework was built by Belgium’s Centre for Cybersecurity and is already the backbone of the Belgian conformity regime, with graded levels and a certification route. Ireland adopting it means Belgian practice is a genuine guide to where Irish expectations are heading - see our Belgium page for how the levels work in a country that has finished transposing.
Irish Cyber Security Measures Certification
The NCSC states this forthcoming scheme “will encompass NIS2 aligned measures” and will include a level aimed at helping SMEs strengthen resilience. Head 30 of the Scheme provides for the use of cyber security certification schemes.
Registration & the switched-off portals
Head 31 requires digital-sector entities to give the NCSC a defined data set. The Scheme carries the Directive’s own date - 17 January 2025 - which has passed without the obligation ever commencing, because the Act does not exist.
Entities covered by Head 31 are DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing providers, data centre providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines and social networking platforms. They must submit:
- the name of the entity;
- the relevant sector, subsector and entity type under Annex I or II;
- the address of the main establishment and other legal establishments in the Union, or of the designated representative if not established in the Union;
- up-to-date contact details, including email addresses and telephone numbers;
- the member states where the entity provides services; and
- the entity’s IP ranges.
Changes must be notified without delay and in any event within three months.
Incident reporting: 24h / 72h / one month
Head 15 sets the chain, and both of the first two clocks run from becoming aware of the incident. Reports go to the CSIRT. None of this is on any competing Irish page.
Trust services report faster
A trust service provider must notify the CSIRT within 24 hours of becoming aware of a significant incident that affects the provision of its trust services.
The CSIRT owes you a reply
Within 24 hours of the early warning where possible, the CSIRT must respond with initial feedback and, on request, guidance or operational advice on possible mitigation. The duty runs both ways.
What counts as significant
An incident that has caused or is capable of causing severe operational disruption of services or financial loss to the entity, or that has affected or is capable of affecting others by causing considerable material or non-material damage.
What the NCSC will be able to do
The Scheme gives the NCSC active technical powers, not just supervisory ones. These Heads attract little attention and are among the more consequential parts of the draft.
- Head 6 — Scanning. Scanning for vulnerabilities and exposed services.
- Head 7 — DNS blocking and sinkholing. A direct operational power to disrupt malicious infrastructure.
- Head 8 — Sensors on the networks of essential and important entities, deployed with the entity’s consent: a physical device monitoring traffic entering the network.
- Head 9 — Temporary sensors on communications networks.
- Head 16 — Coordinated vulnerability disclosure.
Timeline & key dates
Sector-specific notes
- Energy, drinking water and waste water: the CRU is the designated authority for all three, so a utility with more than one of these functions has a single supervisor.
- Digital infrastructure, ICT service management, space and digital providers: ComReg. This is the widest single designation and it captures much of what Ireland is known for - data centres, cloud and managed services - and it is levy-funded.
- Banking and financial market infrastructure: the Central Bank of Ireland, running alongside DORA, which takes priority for financial entities.
- Transport is split four ways: aviation to the IAA, rail to the Commission for Rail Regulation, maritime to the Minister for Transport, and road to the National Transport Authority.
- Health: “an Agency or Agencies under the remit of the Minister for Health” - the one designation the Scheme leaves open, so health providers cannot yet name their supervisor.
- Everything else in Schedules I and II: the NCSC supervises directly - including postal and courier, waste management, food, chemicals, manufacturing, research and public administration.
Penalties & fines
These figures come from the General Scheme and are proposed, not enacted. They are worth knowing because the Scheme is unusually specific and because the structure around the numbers is more restrictive than the headline suggests.
Essential entities
The greater of 10 million euro and at least 2 per cent of worldwide turnover in the financial year ending in the year before the year in which the breach last occurred.
Important entities
The greater of 7 million euro and at least 1.4 per cent of worldwide turnover, on the same basis.
Only two Heads reach that level
The ceilings apply to infringements of Head 15 (incident reporting) and Head 29 (risk-management measures). Everything else runs through compliance notices.
Criminal offences sit alongside the administrative regime, and this is where Ireland departs from most of the EU. The Scheme provides for summary and indictable offences with fines of 5,000 euro on summary conviction and, on indictment, 50,000 euro or up to five years' imprisonment or both, with 250,000 euro for certain breaches. Most member states reviewed on this site transpose NIS2 as a purely administrative regime.
Enforcement: adjudicators & the High Court
This is the most distinctive feature of the Irish design, and no other member state reviewed on this site has it: an administrative sanction does not take effect until the High Court confirms it.
Heads 44 to 44AW set out a full quasi-judicial process. The Department says it modelled the regime on the Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023, and that it was "cognisant of the need to provide for due process, fair procedures and rights of appeal".
An "administrative sanction" is defined as a requirement to cease a breach or take specified remedial measures, or a requirement to pay a financial penalty. The practical consequence is that an Irish NIS2 fine will be slower to arrive than a continental one, and harder to impose without evidence that survives judicial scrutiny.
How Ireland differs
If you are running NIS2 across several member states, these are the points where Ireland will not behave like your other jurisdictions.
- It has no NIS2 law at all, and is one of three member states referred to the Court of Justice over it.
- A fine will need a court. The adjudication regime ends in High Court confirmation before a sanction takes effect - unique among the transpositions reviewed here.
- Criminal liability, including imprisonment. Up to five years on indictment, where most member states legislate a purely administrative regime.
- Nine competent authorities, with transport alone split across four, and the health designation still unnamed.
- Supervision is levy-funded, so being in scope carries a direct charge.
- The NCSC gets active technical powers - scanning, DNS blocking and sinkholing, and network sensors - rather than only supervisory ones.
- CyFun rather than a home-grown framework, which makes Belgian practice unusually relevant to Irish planning.
- The registration and reporting portals already exist but are switched off pending the legislation.
How to prepare
- Work out which of the nine authorities will supervise you, using the Head 17 table above. If you are in health, note that the designation is still open.
- Check whether NIS1 already applies to you. If you are a designated Operator of Essential Services under S.I. 360/2018, you have live obligations today - that is not a future question.
- Assemble the Head 31 data set now, especially your IP ranges. It is the one item organisations consistently cannot produce quickly, and the portal will ask for it.
- Work to the draft RMMs and CyFun rather than waiting. They are the NCSC’s own statement of expected controls, and CyFun is already operating in Belgium.
- Build the reporting chain to run from awareness: 24 hours, 72 hours, one month. Decide now who declares an incident significant, because that decision starts the clock.
- Answer the supply-chain questionnaires properly. Customers in transposed member states are already obliged to assess you; this is where Irish organisations meet NIS2 first.
- Brief the board. Head 28 puts governance on the management board and Head 43 provides for offences by a body corporate reaching officers personally.
- Budget for the levy. Supervision is to be funded by levy on regulated entities, so being in scope carries a running cost.
