NIS2
NIS2 is not Irish law yet. Here is why it still reaches you.
There is no Irish NIS2 regulator, no registration duty and no NIS2 fine, because there is no Irish law creating any of them. That is not the same as nothing to do.
By Oscar CobbeCurrent as at 10 minute read7 sources
Where Ireland actually is
Directive (EU) 2022/2555, NIS2, had a transposition deadline of 17 October 2024. Ireland did not meet it and has still not transposed it.
The National Cyber Security Centre says so on its own page: the transposition deadline has not been met, Ireland continues to work through the requirements, and the predecessor regime NIS1 remains in full effect and covers the most critical operators in the State.
The European Commission escalated. Letters of formal notice went out on 28 November 2024, reasoned opinions on 7 May 2025, and on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, with a request that the Court impose financial sanctions consisting of a lump sum and daily penalties until complete transposition is notified.
One claim to be careful with
Several compliance write-ups say the National Cyber Security Bill is progressing through the Oireachtas. It is not a Bill. What exists is a General Scheme, published in 2024, which has had pre-legislative scrutiny. The Oireachtas legislation register for 2024, 2025 and 2026 contains no Bill with cyber in its title. A general scheme is a policy document, not draft law before the House.
What non-transposition means in law
A directive that has not been transposed cannot be enforced against a private company. That is settled and it has been for forty years.
The Court of Justice put it in Faccini Dori: a directive cannot of itself impose obligations on an individual and cannot therefore be relied upon as such against an individual. The principle originates in Marshall and has not moved since.
So today, in Ireland, there is no NIS2 competent authority with powers over a private company, no registration duty, no NIS2 incident reporting duty and no NIS2 fine. The NCSC confirms the practical consequence: its NIS2 registration and incident reporting portals are not available, and will be once the legislation is implemented.
Two things run the other way and are worth knowing. The absence of horizontal effect does not stop a private party invoking a sufficiently precise and unconditional provision against the State or an emanation of the State. And national law has to be interpreted, so far as possible, in conformity with the directive.
Who NIS2 will bind when it arrives
It is worth working this out now, because the answer for most Irish SMEs is that it will not reach them, and knowing that is worth more than a readiness programme.
NIS2 applies to entities of a type listed in Annex I or Annex II that qualify as medium-sized enterprises under the EU definition, or exceed those ceilings. Eighteen sectors in total: eleven of high criticality in Annex I, seven others in Annex II.
The size test is finer than the usual shorthand. Under the EU definition a small enterprise has fewer than 50 staff and turnover or balance sheet total not exceeding 10 million euro. So an entity crosses into medium-sized on 50 or more staff, or where both turnover and balance sheet total exceed 10 million. A thirty-person company with 12 million turnover and a 4 million balance sheet is still small.
Some entities are caught regardless of size: providers of public electronic communications networks or publicly available electronic communications services, trust service providers, TLD name registries, DNS service providers, domain name registration services, entities identified as critical under the CER Directive, and central government public administration.
| Situation | NIS2 position |
|---|---|
| Irish SME below the size threshold, ordinary sector | Not in scope even after transposition |
| Irish medium or large entity in an Annex I sector | Essential entity, once transposed |
| Irish medium or large entity in an Annex II sector | Important entity, once transposed |
| DNS, TLD registry, trust services, domain registration | In scope regardless of size |
| Supplier to an in-scope entity elsewhere in the EU | Bound by contract now, not by Irish law |
What binds an Irish supplier today, which is a contract
This is the practical answer to why NIS2 keeps landing on desks in a country that has not transposed it.
Article 21(2)(d) of the Directive requires in-scope entities to manage supply chain security, including the security of their direct suppliers. Entities in member states that did transpose are already regulated, and they are discharging that duty by pushing requirements down their supply chains in contract.
So an Irish software house selling into a German utility or a Dutch hospital is being asked for incident notification windows, vulnerability handling, multi-factor authentication and a right to audit. Those obligations are real and enforceable, and their source is the contract rather than Irish law. Arguing that Ireland has not transposed NIS2 is not a defence to a clause you signed.
The other live regime is the older one. NIS1 remains in effect here through S.I. No. 360 of 2018 for entities already designated as operators of essential services or as digital service providers.
The regime that has no such gap
It is worth putting the two side by side, because the smaller company is far more likely to be caught by the one nobody is discussing.
The Cyber Resilience Act is a regulation, so it applies directly without transposition. It has no SME exemption. Its reporting duty starts on 11 September 2026 and reaches backwards over products already in customers' hands. If you ship software or a connected product, that is the one with a date on it, and whether it reaches a SaaS at all turns on whether anything is installed at the customer's end.
NIS2 regulates operators above a size floor and is not law here. The CRA regulates products, has no floor, and is law everywhere in the Union already.
What the NCSC has published in the meantime
Guidance rather than obligation, and it is worth reading because it signals what the Irish regime will look like.
The NCSC published guidance on cyber governance for management board members in NIS2 entities in July 2026, built around its Cyber Fundamentals framework, which it adopted from the Belgian Centre for Cybersecurity. It has also published draft risk management measures, a NIS2 quick reference guide and a FAQ.
Certification or self-assessment under Cyber Fundamentals is optional and it is not a statutory presumption of compliance with anything. It is a reasonable thing to work towards if you expect to be in scope, and a poor use of money if you do not.
Date what you read. As at 31 August 2026 the NCSC's NIS2 landing page carries a last updated date of 24 June 2025, while its Cyber Resilience Act page was updated on 28 August 2026.
What to do about it
The proportionate answer depends entirely on which of three positions you are in.
- 1Below the size threshold and not in a named sector: do nothing about NIS2. Spend the attention on the Cyber Resilience Act if you ship anything, and on the data protection duties that are already enforceable.
- 2Above the threshold and in an Annex I or II sector: use the time. The measures in Article 21 are ordinary good practice and none of them becomes cheaper by waiting for an Irish Act to name a date.
- 3Supplying an in-scope entity elsewhere in the EU: read the contract, not the Directive. What you owe is in the clauses, and the notification windows in them are usually shorter than anything in the Directive.
- 4Whatever your position, have an incident process with names in it. The GDPR's 72 hours is already enforceable in Ireland and [it starts from awareness](/insights/data-breach-first-72-hours-ireland), which is the clock that will catch you first.
Sources
- 1.NIS2 Directive, national steps and Irish transposition status · National Cyber Security Centre, Ireland
- 2.Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice · European Commission
- 3.Directive (EU) 2022/2555 (NIS2) · EUR-Lex, Publications Office of the European Union
- 4.General Scheme of the National Cyber Security Bill 2024 · Department of Justice, Home Affairs and Migration
- 5.Case C-91/92, Faccini Dori v Recreb · Court of Justice of the European Union, via EUR-Lex
- 6.NCSC guidance library · National Cyber Security Centre, Ireland
- 7.Oireachtas legislation register · Houses of the Oireachtas
Free, and the answers stay in your browser
The regime that does have a date
The Cyber Resilience Act needs no transposition, has no SME exemption, and its reporting duty starts on 11 September 2026. Five questions and the free check says whether it reaches you.
Run the free checkIf a customer is asking you for security answers
Most of what a NIS2-regulated customer asks for is a description of things you either do or do not do: access control, patching, logging, backups, incident response. We work out which you already have, fix the gaps that matter, and write the answer once so it can be sent again.
Business tech setupWho wrote this
Oscar Cobbe · Founder, FourWinds Digital
Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.
More about how we work →Read next
Cyber Resilience Act
Does the Cyber Resilience Act cover a website, or a SaaS?
The test is not whether you sell software. It is whether the customer installs, embeds or runs any part of it themselves.
Cyber Resilience Act
If you ship software, a 24 hour reporting clock starts in September 2026
Most coverage points at December 2027. The duty that bites first arrives fifteen months earlier, and it reaches backwards over everything already in customers' hands.
GDPR
You have had a data breach. What the first 72 hours require
The 72 hours runs from when you became aware, not from when you finished investigating. That is the sentence most people get wrong on the day.
Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.