NIS2 in Ireland: What Applies, and What Already Applies to You
There is a comfortable reading of the NIS2 position in Ireland: the directive has not been transposed, so nothing has changed. It is comfortable and it is wrong, for a reason that has nothing to do with the legislative timetable.
Where the law stands
NIS2 is Directive (EU) 2022/2555. Member States were required to transpose it by 17 October 2024. Ireland missed that deadline, and as of 2026 it still has not transposed. The National Cyber Security Bill 2024 is the intended vehicle and remains unenacted, its timetable disrupted by the 2024 general election.
The Commission has not treated this as a technicality. On 8 July 2026 it referred Ireland, alongside Spain and France, to the Court of Justice of the EU for incomplete transposition.
In the meantime the older NIS1 framework remains in force. That is the whole of the legal answer, and it is the part that misleads people.
Why it already reaches you
NIS2 obligations flow down through contracts. A customer in Germany, the Netherlands or any Member State that has transposed is subject to supply chain security requirements, and it discharges them by writing incident reporting and control obligations into its contracts with suppliers - including Irish ones.
So the practical trigger is not Irish law. It is your customer’s procurement team. Businesses with no direct NIS2 classification are already signing up to NIS2-shaped obligations because a contract required it, often without anyone internally noticing what was agreed.
Ireland’s National Cyber Security Centre has also moved ahead of the legislation. In July 2026 it published guidance on cyber governance for management board members in NIS2 entities, setting out that the directive assigns cybersecurity risk management accountability to the highest level of executive management.
Who is in scope when it does land
NIS2 covers eighteen sectors and splits organisations into two classes. Essential entities include energy, transport, health, drinking water, digital infrastructure, B2B ICT service management, public administration and space. Important entities cover the remaining in-scope sectors.
The distinction is about supervision rather than about how seriously the rules apply. Essential entities are supervised proactively. Important entities are generally reviewed after a concern has been raised.
Size thresholds matter too. Ireland’s draft legislation aligns with the directive’s model, with essential entity thresholds around 250 full-time employees and 50 million euro turnover, and important entity thresholds around 50 employees and 10 million euro. Estimates put roughly 6,000 Irish entities in scope.
Do not wait to be told. The obligation to work out whether you are in scope sits with you, and it depends on your sector and size rather than on a letter arriving.
What the obligations look like
Both essential and important entities must manage cyber risk proportionately and report significant incidents to a competent authority. Ireland’s draft Bill designates different authorities by sector - ComReg for digital infrastructure and ICT service management, the Central Bank for banking and financial markets, sectoral regulators for aviation, rail, maritime, road and health, and the NCSC for everything else in scope.
The penalties follow the directive’s ceilings. Essential entities face up to 10 million euro or 2% of worldwide turnover, whichever is higher. Important entities face up to 7 million euro or 1.4%.
The change that gets least attention is governance. Management boards carry accountability, and Ireland’s draft legislation carries personal liability exposure for board members. Cyber risk stops being something delegated to IT and becomes an organisational risk that someone has to own by name.
What to do during the gap
The transitional period is an advantage if it is used. Four things are worth doing before the law arrives:
- Work out your position. Sector, size, and whether you supply anyone who is in scope. The third is the one that catches people.
- Read your contracts. Check what security and incident reporting obligations you have already agreed to. Many organisations are further committed than they realise.
- Name someone. One person responsible for tracking this, liaising with the NCSC and coordinating readiness. Without a name it does not happen.
- Get incident reporting working. Being able to detect, assess and report a significant incident quickly is the obligation hardest to retrofit under time pressure.
None of this is wasted if the timetable slips again. It is ordinary good practice that happens to also be what the directive asks for.
