Directive NIS2 European Union
IE · Member state

NIS2 in Ireland


What binds you in Ireland is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Not complete
Competent authority
NCSC Ireland
National CSIRT
VAT on your purchase
23%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


Referred to the Court of Justice

The European Commission referred this member state to the Court of Justice of the European Union in its July 2026 infringement package for failing to fully transpose NIS2, asking the Court to impose a lump sum and daily penalty payments.

This does not suspend your obligations. The directive still binds the member state, and entities are expected to be working to article 21(2) regardless of how late the national text is.

Status of the national text · Still in legislative procedure

National assessment framework

CyberFundamentals Framework — CyFun® 2025

version 2, published by Centre for Cybersecurity Belgium (CCB). Built on NIST Cybersecurity Framework 2.0.

Ireland has adopted CyberFundamentals as its national assessment and certification scheme and is a joint owner of the scheme.

A label is not compliance

Holding a CyberFundamentals label does not by itself prove NIS2 compliance. Ireland's NCSC puts it plainly: the framework "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Compliance is owed under the national transposition law; CyFun is the instrument most commonly used to demonstrate it, not a substitute for it.

CyFun in full — levels, controls and what it does not cover →

Who supervises you

NCSC Ireland is the competent authority designated by Ireland. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to CSIRT-IE, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Ireland legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

Transposition is not complete here

That is not a reason to wait. The article 21 measures are fixed and will not change; only the procedural detail is pending. Organisations that waited are now compressing an 18-month programme into whatever time the national law leaves them. The European Commission opened infringement procedures in 2025 against member states that missed the 17 October 2024 deadline.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0