Skip to main content
Not transposedNIS2

NIS2 in Ireland

Ireland has not enacted the National Cyber Security Bill. NIS1 obligations continue to apply and the NCSC has confirmed the NIS2 registration and reporting portals stay closed until the Bill passes. The Commission referred Ireland to the CJEU on 8 July 2026.

Transposition law
National Cyber Security Bill (not yet enacted)
In force since
Pending
Competent authority
National Cyber Security Centre (NCSC-IE)
Max fine (Essential)
€10 million or 2% of global annual turnover
Max fine (Important)
€7 million or 1.4% of global annual turnover
Law adopted
Not adopted

Key Deadlines

EU transposition deadline missed
17 October 2024
Referred to the Court of Justice of the EU
8 July 2026
National Cyber Security Bill enacted
Pending

Competent Authority

National Cyber Security Centre (NCSC-IE)
Lead competent authority and national CSIRT
https://www.ncsc.gov.ie

NCSC-IE emphasizes advisory guidance, threat intelligence sharing, and cooperative risk reviews, moving to strict audits post-enactment.

Registration Process

Registration guidelines will be published on ncsc.gov.ie when the National Cyber Security Bill becomes law.

📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

Key Requirements

  • 1Registration with NCSC-IE upon portal activation
  • 2Vulnerability management programs and risk reduction policies
  • 324-hour warning for significant network anomalies

National Additions

Ireland hosts many multinational tech headquarters, leading to specific supervision rules for cloud and digital services providers

FAQ: NIS2 in Ireland

Do NIS2 obligations apply in Ireland today?
Not yet. The National Cyber Security Bill has not been enacted, so NIS2 does not directly bind Irish entities. Organisations already designated under NIS1 remain subject to those obligations. The NCSC has stated that the NIS2 registration and reporting portals will not go live until the legislation passes, though it has issued cyber governance guidance for boards to prepare in the meantime.
Where should multinational digital providers register?
Under the main establishment principle, if your European head office is in Dublin, you must register with the NCSC-IE.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026.