NIS2 Country Guide

NIS2 Ireland: National Cyber Security Bill 2024

Ireland has still not transposed NIS2, and on 8 July 2026 the European Commission referred it to the Court of Justice. The transposing law exists only as a General Scheme. This page sets out what that draft actually says - the nine competent authorities, the fines, the adjudication regime - and what binds Irish organisations in the meantime.

Not transposed Referred to the CJEU 8 Jul 2026 Stage: General Scheme only Lead authority: NCSC Last updated: 12 August 2026

Introduction: NIS2 Directive & the Irish context

Ireland implemented the original NIS Directive (NIS1) through the 2018 NIS Regulations (S.I. 360/2018), covering a relatively small number of operators of essential services and certain digital service providers.

NIS2 widens the scope considerably and raises the bar for risk management, incident reporting and governance. Ireland’s chosen vehicle is the National Cyber Security Bill 2024, which would overhaul the existing regime, place the National Cyber Security Centre (NCSC) on a statutory footing and create a federated supervisory model with nine designated authorities.

That Bill does not exist yet. What exists is its General Scheme - a 183-page set of draft Heads published on 30 August 2024. It is unusually detailed for a General Scheme, and because almost nobody reads it, most of what is written about NIS2 in Ireland stops at “fines of up to 10 million euro”. This page works from the document itself.

Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

Where the Bill actually is

Ireland did not meet the EU deadline of 17 October 2024 for transposing NIS2. The NCSC has confirmed that the deadline was missed and that the earlier NIS1 regulations remain in force until the new legislation is enacted.

On 24 July 2024 the Government approved priority drafting of the National Cyber Security Bill 2024, and the General Scheme was published on 30 August 2024 as the vehicle for transposition. The designation of competent authorities had already been approved by Government in December 2023.

The Bill has not been introduced in the Oireachtas. As at 12 August 2026 the Oireachtas record contains no bill with “Cyber” in its title for 2024, 2025 or 2026. The NCSC’s own NIS2 page states only that the Heads of the General Scheme were published and that “drafting is progressing swiftly”. A General Scheme is pre-legislative: it precedes the drafting of the Bill, which precedes introduction, which precedes committee stage. Several published guides describe the Bill as being at committee stage. That claim is not supported by the Oireachtas record.

The enforcement chain has moved on regardless. The Commission sent Ireland a letter of formal notice on 28 November 2024 and a reasoned opinion on 7 May 2025. On 8 July 2026 it referred Ireland to the Court of Justice of the European Union in case INFR(2024)0279, asking the Court to impose “financial sanctions, consisting of a lump sum and daily penalties until notification of complete transposition”. No judgment has been given.

We print no predicted enactment date. Ministerial statements about notifying transposition have been made and have already slipped more than once; a date that gets quoted back to us is worth less than an accurate description of where the file sits.

Status

Not transposed. The transposing law exists as a General Scheme only and has not been introduced as a Bill. S.I. 360/2018 continues to apply until it is replaced.

Legal structure (planned)

The National Cyber Security Bill 2024 will transpose NIS2, establish the NCSC on a statutory basis, and define the supervisory and enforcement regime, including a federated model of competent authorities.

Interim position

NIS1 remains in force for designated Operators of Essential Services. The NCSC's draft Risk Management Measures and the Cyber Fundamentals framework are the best available statement of what will be expected. See what binds you right now.

What binds you right now

“No law yet” is not “no obligations”. An untransposed directive binds the State, not private parties - Ireland’s exposure is to the Court of Justice, and a company cannot be fined under NIS2 in Ireland today. But four things already reach Irish organisations.

NIS1 is still live

The European Union (Measures for a High Common Level of Security of Network and Information Systems) Regulations 2018 - S.I. 360/2018 - remain in full effect. The NCSC confirms NIS1 “continues to apply to already designated Operators of Essential Services (OESs) within the State”.

Sector regimes that already bite

DORA for financial entities; the electronic communications security regime under the Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023, which the Scheme would partly repeal and replace; and the GDPR wherever an incident touches personal data.

Supply-chain spillover

This is the one that actually catches Irish companies. A customer in a member state that has transposed must assess the cybersecurity of its direct suppliers under its own Article 21 equivalent. That obligation reaches Irish suppliers through contract terms today, with no Irish law involved.

CER, running in parallel

The Critical Entities Resilience Directive is being transposed separately by the Department of Defence, and the Scheme expects many of the same bodies to be competent authorities under both.

Who will be in scope

Even before full transposition, Irish organisations in NIS2-relevant sectors should assume that the EU Directive’s core obligations will apply and start preparing. The future Bill is expected to closely follow the NIS2 model of essential and important entities.

Who is likely in scope?

  • Entities in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities in Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
  • Medium and large organisations meeting NIS2 staff/turnover thresholds.
  • Entities covered regardless of size: DNS, TLD registries, trust service providers, major cloud and data-centre operators.

The two Heads that carry the big fines

Under the Scheme, the 10 million / 7 million euro ceilings attach to infringements of just two Heads:

  • Head 29 - cyber security risk-management measures
  • Head 15 - incident response powers and reporting obligations

Other failures are dealt with by compliance notice, and non-compliance with the notice is separately penalised under Head 37B.

Governance

Head 28 puts governance on the management board, defined in the Scheme as "a body of group of individuals vested with the authority and responsibility for the oversight, direction and control of an entity". Head 43 provides for offences by a body corporate, reaching officers who consented to or connived in the breach.

RMMs, CyFun & the Irish certification scheme

The NCSC has not waited for the legislation to say what good looks like. On 24 June 2025 it published draft Risk Management Measures (RMMs) under Article 21 and announced that Ireland is adopting the Cyber Fundamentals (CyFun) framework.

Draft RMMs

Not binding, but they are the NCSC’s own statement of the controls it expects, written against Article 21. They are the most reliable planning document available in Ireland today.

CyFun is Belgian in origin

The Cyber Fundamentals framework was built by Belgium’s Centre for Cybersecurity and is already the backbone of the Belgian conformity regime, with graded levels and a certification route. Ireland adopting it means Belgian practice is a genuine guide to where Irish expectations are heading - see our Belgium page for how the levels work in a country that has finished transposing.

Irish Cyber Security Measures Certification

The NCSC states this forthcoming scheme “will encompass NIS2 aligned measures” and will include a level aimed at helping SMEs strengthen resilience. Head 30 of the Scheme provides for the use of cyber security certification schemes.

Structures are being built ahead of the law. The NCSC lists a national competent authority forum, strengthening of CSIRT-IE, a national cyber security strategy, a national cyber emergency plan, and Cyber-CORE, a sectoral information-sharing network. The stated intention is that when the legislation lands the supporting machinery already exists.

The nine competent authorities

Ireland has chosen a federated model, and Head 17 of the General Scheme names the authorities sector by sector. The designations were approved by Government in December 2023. Most published summaries say only "sectoral regulators to be designated"; the draft is more specific than that.

AuthoritySectors
Commission for the Regulation of Utilities (CRU)Energy · Drinking Water · Waste Water
Commission for Communications Regulation (ComReg)Digital Infrastructure · ICT Service Management · Space · Digital Providers
Central Bank of Ireland (CBI)Banking · Financial Market
Irish Aviation Authority (IAA)Transport — Aviation
Commission for Rail Regulation (CRR)Transport — Rail
The Minister for TransportTransport — Maritime
National Transport Authority (NTA)Transport — Road
An Agency or Agencies under the remit of the Minister for HealthHealth
The NCSCAll other Schedule I and II sectors

NCSC as lead authority

Head 18 makes the NCSC lead competent authority: central coordinator for advice, guidance and the regulatory framework, and the central point for engagement with the Commission, EU bodies and other member states. It is also the national CSIRT (Head 12) and single point of contact (Head 13).

The list can change

The Minister may designate or discharge a competent authority by secondary legislation after consulting Ministers, bodies under their aegis, the designated authorities and the NCSC. The Scheme says discharge is foreseen mainly where a body changes its name.

Who pays for it

Head 19 funds the competent authorities by levy on regulated entities. The Scheme amends the Communications Regulation Act 2002 so ComReg can extend its levy to this function - so supervision will carry a direct cost to entities, not just a compliance cost.

Registration & the switched-off portals

Head 31 requires digital-sector entities to give the NCSC a defined data set. The Scheme carries the Directive’s own date - 17 January 2025 - which has passed without the obligation ever commencing, because the Act does not exist.

Entities covered by Head 31 are DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing providers, data centre providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines and social networking platforms. They must submit:

  • the name of the entity;
  • the relevant sector, subsector and entity type under Annex I or II;
  • the address of the main establishment and other legal establishments in the Union, or of the designated representative if not established in the Union;
  • up-to-date contact details, including email addresses and telephone numbers;
  • the member states where the entity provides services; and
  • the entity’s IP ranges.

Changes must be notified without delay and in any event within three months.

The portals are built and switched off. The NCSC states that the NIS2 registration portal and the NIS2 incident reporting portal “are not available at this time” and that “once the legislation is implemented, both will be available for use”. So the practical answer to “where do I register in Ireland?” is that you cannot yet - but the data set above is what you will be asked for, and it is worth assembling now. IP range inventories in particular are rarely to hand.

Incident reporting: 24h / 72h / one month

Head 15 sets the chain, and both of the first two clocks run from becoming aware of the incident. Reports go to the CSIRT. None of this is on any competing Irish page.

24 hours — an early warning, without undue delay and in any event within 24 hours of becoming aware, indicating where applicable whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border impact.
72 hours — an incident notification, updating the early warning with an initial assessment of the incident including severity and impact, and where available the indicators of compromise.
Intermediate report — on the CSIRT's request, giving relevant status updates.
Final report — within one month of the incident notification: a detailed description including severity and impact; the type of threat or root cause likely to have triggered it; applied and ongoing mitigation measures; and any cross-border impact.
Still ongoing at that point? Provide a progress report then, and a final report within one month of the handling of the incident ending.

Trust services report faster

A trust service provider must notify the CSIRT within 24 hours of becoming aware of a significant incident that affects the provision of its trust services.

The CSIRT owes you a reply

Within 24 hours of the early warning where possible, the CSIRT must respond with initial feedback and, on request, guidance or operational advice on possible mitigation. The duty runs both ways.

What counts as significant

An incident that has caused or is capable of causing severe operational disruption of services or financial loss to the entity, or that has affected or is capable of affecting others by causing considerable material or non-material damage.

What the NCSC will be able to do

The Scheme gives the NCSC active technical powers, not just supervisory ones. These Heads attract little attention and are among the more consequential parts of the draft.

  • Head 6 — Scanning. Scanning for vulnerabilities and exposed services.
  • Head 7 — DNS blocking and sinkholing. A direct operational power to disrupt malicious infrastructure.
  • Head 8 — Sensors on the networks of essential and important entities, deployed with the entity’s consent: a physical device monitoring traffic entering the network.
  • Head 9 — Temporary sensors on communications networks.
  • Head 16 — Coordinated vulnerability disclosure.
The safeguards are judicial, and they are worth reading before consenting to anything. Data collected through sensors may be retained for no more than 18 months, and its destruction must be certified by the NCSC to the High Court. To obtain specific traffic data (OSI Layers 1 to 4) from providers of public communications networks or from data centre operators, the NCSC must apply ex parte to the High Court on information on oath, specifying the grounds and the retention period sought; the Court may exclude all but the parties, their lawyers and necessary witnesses where disclosure would risk the security of the State. Any order is limited in time and to what is strictly necessary, and its cessation must be recorded to the same judge.

Timeline & key dates

2018 — NIS1 implemented via S.I. 360/2018, establishing the first Irish NIS regime.
17 October 2024 — EU deadline for NIS2 transposition; Ireland does not meet the deadline.
30 August 2024 — General Scheme of the National Cyber Security Bill 2024 published as NIS2 vehicle.
28 November 2024 — the European Commission sends Ireland a letter of formal notice.
7 May 2025 — the Commission issues a reasoned opinion for failure to notify full transposition.
24 June 2025 — the NCSC publishes draft Risk Management Measures and announces the Cyber Fundamentals framework.
8 July 2026 — the Commission refers Ireland to the Court of Justice in INFR(2024)0279, seeking a lump sum and daily penalties until complete transposition is notified.
12 August 2026 — no Bill has been introduced in the Oireachtas; the General Scheme remains the only published text.

Sector-specific notes

  • Energy, drinking water and waste water: the CRU is the designated authority for all three, so a utility with more than one of these functions has a single supervisor.
  • Digital infrastructure, ICT service management, space and digital providers: ComReg. This is the widest single designation and it captures much of what Ireland is known for - data centres, cloud and managed services - and it is levy-funded.
  • Banking and financial market infrastructure: the Central Bank of Ireland, running alongside DORA, which takes priority for financial entities.
  • Transport is split four ways: aviation to the IAA, rail to the Commission for Rail Regulation, maritime to the Minister for Transport, and road to the National Transport Authority.
  • Health: “an Agency or Agencies under the remit of the Minister for Health” - the one designation the Scheme leaves open, so health providers cannot yet name their supervisor.
  • Everything else in Schedules I and II: the NCSC supervises directly - including postal and courier, waste management, food, chemicals, manufacturing, research and public administration.

Penalties & fines

These figures come from the General Scheme and are proposed, not enacted. They are worth knowing because the Scheme is unusually specific and because the structure around the numbers is more restrictive than the headline suggests.

Essential entities

The greater of 10 million euro and at least 2 per cent of worldwide turnover in the financial year ending in the year before the year in which the breach last occurred.

Important entities

The greater of 7 million euro and at least 1.4 per cent of worldwide turnover, on the same basis.

Only two Heads reach that level

The ceilings apply to infringements of Head 15 (incident reporting) and Head 29 (risk-management measures). Everything else runs through compliance notices.

Criminal offences sit alongside the administrative regime, and this is where Ireland departs from most of the EU. The Scheme provides for summary and indictable offences with fines of 5,000 euro on summary conviction and, on indictment, 50,000 euro or up to five years' imprisonment or both, with 250,000 euro for certain breaches. Most member states reviewed on this site transpose NIS2 as a purely administrative regime.

Compliance notices come first in practice. Heads 36 and 36A (essential entities) and 37 and 37A (important entities) build a supervisory ladder, and Head 37B penalises failure to comply with a notice. Head 37C gives powers of inspection and Head 37D provides for search warrants. Head 42 deals with infringements that also entail a personal data breach, and the Scheme requires information sharing and cooperation with the Data Protection Commission (Head 11).

Enforcement: adjudicators & the High Court

This is the most distinctive feature of the Irish design, and no other member state reviewed on this site has it: an administrative sanction does not take effect until the High Court confirms it.

Heads 44 to 44AW set out a full quasi-judicial process. The Department says it modelled the regime on the Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023, and that it was "cognisant of the need to provide for due process, fair procedures and rights of appeal".

Notice of suspected non-compliance (Head 44B) - an authorised officer who suspects on reasonable grounds a regulatory breach that is not a criminal offence serves written notice setting out the grounds.
Investigation by authorised officers (Head 39), with powers of inspection and search warrants.
Referral report (Head 44I) to the competent authority.
Adjudication by an independent adjudicator (Head 44O), who decides both the breach and any sanction (Heads 44AC, 44AD).
High Court confirmation (Head 44AE) - the adjudication takes effect only when confirmed by the High Court.
Appeal under the Scheme's appeal chapter.

An "administrative sanction" is defined as a requirement to cease a breach or take specified remedial measures, or a requirement to pay a financial penalty. The practical consequence is that an Irish NIS2 fine will be slower to arrive than a continental one, and harder to impose without evidence that survives judicial scrutiny.

How Ireland differs

If you are running NIS2 across several member states, these are the points where Ireland will not behave like your other jurisdictions.

  • It has no NIS2 law at all, and is one of three member states referred to the Court of Justice over it.
  • A fine will need a court. The adjudication regime ends in High Court confirmation before a sanction takes effect - unique among the transpositions reviewed here.
  • Criminal liability, including imprisonment. Up to five years on indictment, where most member states legislate a purely administrative regime.
  • Nine competent authorities, with transport alone split across four, and the health designation still unnamed.
  • Supervision is levy-funded, so being in scope carries a direct charge.
  • The NCSC gets active technical powers - scanning, DNS blocking and sinkholing, and network sensors - rather than only supervisory ones.
  • CyFun rather than a home-grown framework, which makes Belgian practice unusually relevant to Irish planning.
  • The registration and reporting portals already exist but are switched off pending the legislation.

How to prepare

  1. Work out which of the nine authorities will supervise you, using the Head 17 table above. If you are in health, note that the designation is still open.
  2. Check whether NIS1 already applies to you. If you are a designated Operator of Essential Services under S.I. 360/2018, you have live obligations today - that is not a future question.
  3. Assemble the Head 31 data set now, especially your IP ranges. It is the one item organisations consistently cannot produce quickly, and the portal will ask for it.
  4. Work to the draft RMMs and CyFun rather than waiting. They are the NCSC’s own statement of expected controls, and CyFun is already operating in Belgium.
  5. Build the reporting chain to run from awareness: 24 hours, 72 hours, one month. Decide now who declares an incident significant, because that decision starts the clock.
  6. Answer the supply-chain questionnaires properly. Customers in transposed member states are already obliged to assess you; this is where Irish organisations meet NIS2 first.
  7. Brief the board. Head 28 puts governance on the management board and Head 43 provides for offences by a body corporate reaching officers personally.
  8. Budget for the levy. Supervision is to be funded by levy on regulated entities, so being in scope carries a running cost.

Official links & resources

General Scheme of the National Cyber Security Bill 2024 — the primary source for everything on this page (183 pages)
NCSC Ireland — NIS2 information page, including the draft Risk Management Measures and the Cyber Fundamentals announcement
Oireachtas Bills tracker — where the Bill will appear when it is introduced
S.I. 360/2018 — the NIS1 regulations still in force

FAQ: NIS2 in Ireland

Has Ireland transposed NIS2?
No. As at 12 August 2026 NIS2 has not been transposed. The National Cyber Security Bill 2024 exists only as a General Scheme published on 30 August 2024, and no Bill has been introduced in the Oireachtas.
Is the Bill at committee stage?
No, and this is worth being clear about because several published guides say otherwise. The Oireachtas record contains no bill with “Cyber” in its title for 2024, 2025 or 2026, and the NCSC’s own page refers only to the Heads of the General Scheme. A General Scheme is pre-legislative: drafting, introduction and committee stage all come afterwards.
What happened with the Court of Justice?
On 8 July 2026 the European Commission referred Ireland to the Court of Justice of the European Union in case INFR(2024)0279, seeking “financial sanctions, consisting of a lump sum and daily penalties until notification of complete transposition”. The chain was: transposition deadline 17 October 2024, letter of formal notice 28 November 2024, reasoned opinion 7 May 2025, referral 8 July 2026. No judgment has been given.
Can we be fined under NIS2 in Ireland today?
No. An untransposed directive does not impose obligations on private parties - it binds the State, which is why the Commission is pursuing Ireland rather than Irish companies. But NIS1 obligations under S.I. 360/2018 are live for designated Operators of Essential Services, and customers in transposed member states are already contractually pushing NIS2 requirements onto Irish suppliers.
Who will supervise us?
One of nine authorities named in Head 17: CRU, ComReg, the Central Bank of Ireland, the IAA, the Commission for Rail Regulation, the Minister for Transport, the National Transport Authority, an agency under the Minister for Health, or the NCSC for everything else. See the table.
What are the proposed fines?
The greater of 10 million euro or 2% of worldwide turnover for essential entities, and 7 million or 1.4% for important entities - but only for infringements of Head 15 (incident reporting) or Head 29 (risk management). The Scheme also creates criminal offences carrying up to five years’ imprisonment on indictment. These are proposed figures in a draft.
Who actually imposes a fine?
An independent adjudicator, following a notice of suspected non-compliance and a referral report - and the adjudication takes effect only when confirmed by the High Court. That judicial confirmation step is unique among the transpositions covered on this site.
Where do we register?
You cannot yet. The NCSC has built a registration portal and an incident reporting portal but states they “are not available at this time” and will open once the legislation is implemented. Head 31 sets out the data you will be asked for, including your IP ranges.
Should we wait for the law before preparing?
No. Work to the NCSC’s draft Risk Management Measures and the Cyber Fundamentals (CyFun) framework, which Ireland has adopted. Because CyFun originated in Belgium and is already in force there, Belgian practice is a reasonable guide to Irish expectations.
Will ISO 27001 be mandatory?
No standard is mandatory by name. Head 30 provides for the use of cyber security certification schemes, and the NCSC has said its forthcoming Irish Cyber Security Measures Certification scheme “will encompass NIS2 aligned measures” and will include a level aimed at SMEs.
Information provided for general guidance; always consult the future Irish NIS2 legislation, NCSC publications and legal counsel for definitive NIS2 compliance requirements.