Radium Technologies

Cyber security regulation

What NIS2 Means for Irish Businesses in 2026

NIS2 is still not part of Irish law, which has convinced a lot of Irish businesses they have time. They don't. The obligations are already arriving through EU customers and supply-chain clauses, and once the National Cyber Security Bill is enacted, registration and reporting land quickly.

8 minute read Compliance

Not yet law, already landing. Ireland missed the 17 October 2024 deadline and was referred to the Court of Justice of the EU in July 2026, while supply-chain clauses already reach Irish suppliers.

In short

Overview

NIS2 is still not part of Irish law. Ireland missed the EU transposition deadline of 17 October 2024, and the National Cyber Security Bill 2024 has yet to be enacted, so no Irish regulator is currently issuing NIS2 fines.

That gap has convinced a lot of Irish businesses they have time. They don't. On 8 July 2026 the European Commission referred Ireland to the Court of Justice of the EU for failing to notify complete transposition, asking the Court to impose a lump sum and daily penalties until the law is on the books. The political pressure to pass the Bill is now financial as well as reputational.

More to the point, the obligations are already arriving by other routes. EU customers regulated in member states that did transpose on time are pushing incident reporting and security clauses onto their Irish suppliers, and the National Cyber Security Centre has started telling Irish boards what will be expected of them.

Where it stands

Where NIS2 Stands in Irish Law in 2026

The directive has not been transposed, and the 2018 NIS regulations still govern the existing Irish regime. The National Cyber Security Bill 2024 is the intended vehicle and remains unenacted as of this writing.

The shape of the eventual law is not a mystery, though. The General Scheme of the National Cyber Security Bill 2024 sets out the competent authorities, the two entity categories and the penalty ceilings, and the final Act is expected to track it closely.

The sequence so far:

  • 17 October 2024. EU deadline for member states to transpose Directive (EU) 2022/2555. Ireland missed it, partly because the general election interrupted the legislative timetable.
  • May 2025. The European Commission issued Ireland a reasoned opinion, the second stage of infringement proceedings.
  • 7 July 2026. The NCSC published board-level cyber governance guidance for organisations that will be in scope.
  • 8 July 2026. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU, with financial sanctions requested.

Ireland has chosen a federated supervisory model. The NCSC will act as lead competent authority and as the national CSIRT, with sectoral regulators supervising their own industries.

The Commission for Regulation of Utilities covers energy and water, ComReg covers digital infrastructure and ICT service management, and the Central Bank of Ireland covers banking and financial market infrastructure.

Scope

Which Irish Businesses NIS2 Applies To

NIS2 applies to organisations operating in one of 18 named sectors that are at least medium-sized, and it splits them into essential entities and important entities. Both categories carry the same security obligations.

What separates them is how closely they are supervised and how far the fines can go.

Essential entitiesImportant entities
Size250 staff or more, or turnover above €50 million50 to 249 staff, or turnover above €10 million
SectorsHighly critical sectors under Annex IOther critical sectors under Annex II, plus smaller Annex I entities
SupervisionProactive, including inspections without a prior incidentReactive, triggered by evidence of a possible breach
Maximum fine€10 million or 2% of worldwide annual turnover, whichever is higher€7 million or 1.4% of worldwide annual turnover, whichever is higher

The 18 sectors

Sectors Covered by NIS2 in Ireland

Annex I covers the highly critical sectors, and Annex II covers the rest. Between them they reach far further than the original NIS regime did, which stopped at seven sectors.

Annex I includes energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management on a business-to-business basis, public administration and space. Financial services firms in this group also sit under DORA, which takes precedence where the two overlap on ICT risk management.

Annex II includes postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing of medical devices, electronics, machinery and vehicles, digital providers such as online marketplaces and search engines, and research organisations.

Size Thresholds That Bring a Business Into NIS2 Scope

The entry point is the medium-enterprise threshold, so 50 or more staff, or annual turnover or balance sheet total above €10 million, in a covered sector. Below that, most organisations fall outside direct scope.

A handful of provider types are in scope regardless of headcount or turnover. These include DNS service providers, top-level domain name registries, qualified trust service providers and providers of public electronic communications networks or services.

Indirect reach

Why NIS2 Reaches Businesses Outside Its Formal Scope

Supply chain security is written into the directive, so regulated entities are obliged to manage the cyber risk their suppliers introduce. A 30-person Irish software firm or facilities contractor selling into a regulated entity will be asked to evidence controls it has no direct legal duty to hold.

That pressure is already visible in Irish contract negotiations. The common asks include:

  • Incident notification windows that mirror the 24 and 72 hour regulatory clocks
  • Named security contacts and defined escalation paths
  • Evidence of access control, MFA and patching discipline
  • Audit or assurance rights over the supplier's controls
  • Business continuity and recovery commitments with tested restore times

There's a second route that catches many businesses off guard. Managed ICT service providers are themselves listed in Annex I, so the firm that runs your infrastructure is likely to be regulated.

If your provider ends up in scope and cannot demonstrate the controls, that becomes your problem at renewal.

The obligations

What NIS2 Requires Irish Businesses To Do

The directive sets out a baseline of risk management measures under Article 21 and strict incident reporting deadlines under Article 23. Both apply equally to essential and important entities.

The standard is proportionality. Measures must match the size of the organisation, its exposure and the likely societal impact of an outage.

Cyber Risk Management Measures Required Under Article 21

Article 21 lists ten areas every in-scope entity must address with technical, operational and organisational measures. Most competent teams already do several of these, but few can evidence all ten.

  • Risk analysis and information system security policies
  • Incident handling procedures
  • Business continuity, backup management, disaster recovery and crisis management
  • Supply chain security, including the security of direct suppliers
  • Security in the acquisition, development and maintenance of systems, including vulnerability management and coordinated disclosure
  • Policies to assess whether the risk measures actually work
  • Basic cyber hygiene practices and security awareness training
  • Cryptography and encryption policies
  • Human resources security, access control and asset management
  • Multi-factor authentication, secured communications and secure emergency communication systems

Incident Reporting Deadlines Under NIS2

Reporting runs on a three-stage clock that starts when the entity becomes aware of a significant incident, and the first stage closes within one day.

DeadlineWhat has to be submitted
Within 24 hoursEarly warning to the CSIRT, flagging whether the incident appears malicious or could have cross-border effects
Within 72 hoursIncident notification with an initial assessment, severity, impact and any indicators of compromise
Within one monthFinal report covering root cause, mitigation applied and cross-border effects

An incident counts as significant if it causes or could cause severe operational disruption or financial loss, or if it affects others through considerable material or non-material damage. Interim reports can also be requested along the way.

Board accountability

What NIS2 Means for Directors and Senior Management

Article 20 makes the management body personally accountable for approving and overseeing cyber risk management measures, and allows members to be held liable for the organisation's infringements. Board members are also required to undertake training so they can identify and assess cyber risk themselves.

Ireland's regulator has already set out its expectations. The NCSC's guidance on cyber governance for management board members is aimed at CEOs, managing directors, CIOs and CISOs rather than technical teams, and it is built around the Cyber Fundamentals Framework, known as CyFun, as the preferred practical route to putting the obligations into effect.

The guidance is clear that boards are not expected to become technical specialists. What they are expected to do is different.

  • Understand the organisation's current cyber risk position in business terms
  • Approve the risk management measures rather than rubber-stamp them
  • Confirm that cyber risk sits inside the wider enterprise risk process
  • Assure themselves the organisation can respond to and recover from an incident
  • Ask supply chain questions and expect documented answers

Practical steps

How To Prepare for NIS2 Before the Bill Is Enacted

Start with a scope determination and a control gap assessment, because both take longer than teams expect and neither depends on the final wording of the Act. The directive's requirements are settled, and the Irish Bill is transposing them rather than rewriting them.

A practical order of work:

  • Determine your status. Check your sector against Annex I and Annex II, then apply the size threshold. Record the reasoning, because you may need to show it.
  • Map your suppliers and your customers. Identify which regulated entities you depend on and which ones depend on you. Contract clauses will arrive from both directions.
  • Run a gap assessment against the ten Article 21 areas. CyFun gives you a structure the Irish regulator has already endorsed.
  • Build the incident reporting process now. Decide who declares a significant incident, who drafts the 24-hour warning and who signs it off, then test it.
  • Brief the board and document the briefing. Article 20 training is a requirement, and evidence of it will matter.
  • Close the basics first. MFA everywhere, tested backups, patching discipline and access reviews cover a large share of the exposure.

Most of this work has value regardless of when the Bill passes, which is the argument that usually gets budget approved.

If the internal capacity isn't there, the gap assessment and the evidence pack are the two pieces worth outsourcing to a team with genuine compliance and governance experience across regulated Irish sectors, since both are judgement-heavy and both get scrutinised later.

The window

Getting Ahead of NIS2 Before Enforcement Starts

Ireland's delay has bought businesses preparation time rather than an exemption, and that time is running short. Once the National Cyber Security Bill is enacted, registration and reporting obligations land quickly, and organisations that started in 2026 will be answering questions their competitors are only beginning to ask.

For high-value firms in property, funds, finance, legal and medical work, this stopped being a helpdesk question some time ago. It affects service continuity, client confidence and whether you stay on approved supplier lists.

Book a strategic IT review to establish whether you are in scope and where your gaps sit.

Frequently asked questions

NIS2 questions from Irish businesses.

Is NIS2 law in Ireland yet?

No. The National Cyber Security Bill 2024, which transposes the directive into Irish law, has not been enacted. Ireland missed the October 2024 deadline and was referred to the Court of Justice of the EU in July 2026 over the delay.

Does NIS2 apply to small businesses in Ireland?

Usually not directly. The threshold starts at 50 staff or turnover above €10 million in a covered sector. Smaller firms are still affected through supply chain clauses from regulated customers, and a few provider types are in scope at any size.

What is the difference between an essential and an important entity?

Both face identical security obligations. Essential entities are larger organisations in highly critical sectors and face proactive supervision with fines up to €10 million or 2% of turnover. Important entities are supervised reactively, with fines capped at €7 million or 1.4%.

How quickly does an incident have to be reported under NIS2?

An early warning goes to the national CSIRT within 24 hours of becoming aware of a significant incident. A fuller notification with an initial assessment follows within 72 hours, and a final report within one month.

Can directors be held personally liable under NIS2?

Yes. Article 20 makes management bodies responsible for approving and overseeing cyber risk measures and allows them to be held liable for infringements. Authorities can also impose temporary management bans on responsible individuals at essential entities.

Do NIS2 and DORA both apply to financial firms?

Financial entities can fall under both, but DORA takes precedence where the two overlap on ICT risk management, resilience testing and incident reporting. Obligations outside DORA's scope may still come from the national NIS2 regime once enacted.

Book a strategic IT review to establish whether you are in scope for NIS2 and where your gaps actually sit.

Contact Us