Ireland hasn't finished transposing NIS2 yet. That doesn't leave you with nothing to do. We help Irish organisations work out whether they're in scope, find the real gaps in governance and security controls, and build the evidence to show those controls work, so you're ready when the National Cyber Security Bill is enacted and the NCSC opens registration.
Where Ireland stands
NIS2 is an EU directive, so it only bites on organisations once each Member State writes it into national law. In Ireland that law will be the National Cyber Security Bill. As at 23 September 2026, it has not been enacted. The Government has published a General Scheme (the draft outline of the Bill), and the Bill sits on the Autumn 2026 Legislation Programme for priority publication.
So, strictly, there's no Irish NIS2 statute to comply with yet. In practice the direction is clear. The Directive's obligations are fixed at EU level, the NCSC has published the risk-management and governance expectations it intends to supervise against, and the Commission has taken Ireland to the Court of Justice over the delay, asking for financial penalties until transposition is notified. The gap between enactment and supervision is unlikely to be generous.
That's why organisations that expect to be in scope are doing the work now: confirming scope, fixing the obvious gaps, and getting management sign-off in place before the registration portal opens.
The General Scheme is a draft. Authority designations, penalty amounts, registration deadlines and any Irish-specific additions will be whatever the enacted Act and its regulations say, and they can change as the Bill goes through the Oireachtas. We track the Bill and update this page when it moves.
16 Jan 2023
Directive (EU) 2022/2555 (NIS2) enters into force across the EU.
30 Aug 2024
Government publishes the General Scheme of the National Cyber Security Bill 2024, the draft framework for transposing NIS2 and putting the NCSC on a statutory footing.
17 Oct 2024
EU transposition deadline. Ireland, like most Member States, misses it.
Nov 2024 – May 2025
The Commission opens infringement proceedings (formal notice), then sends a reasoned opinion on 7 May 2025.
24 Jun 2025
NCSC publishes draft NIS2 Risk Management Measures and recommends the Cyber Fundamentals (CyFun) framework.
Jul 2026
NCSC publishes guidance on cyber governance for management boards in NIS2 entities. The Commission refers Ireland to the Court of Justice of the EU for failing to notify transposition.
Sep 2026
The Government's Autumn 2026 Legislation Programme lists the National Cyber Security Bill for priority publication.
Next
Bill published and passed by the Oireachtas, then commenced. The NCSC opens the NIS2 registration and incident reporting portals once the law is in place.
Organisations designated as Operators of Essential Services under the existing NIS regulations remain subject to them. The NCSC says NIS1 stays in full effect until NIS2 legislation replaces it.
The NCSC's NIS2 registration and incident reporting portals aren't live and won't be until the Bill is enacted. There's currently no requirement to register under NIS2 in Ireland.
The NCSC's draft Risk Management Measures describe what it sees as the minimum for essential and important entities. Its July 2026 board guidance sets out what management should be doing. Neither is law, but both show where supervision is heading.
Many Irish organisations first meet NIS2 through a supplier questionnaire or a contract clause from a customer that is in scope. That pressure exists today, whatever the Oireachtas timetable.
Ireland is planning a distributed model: the NCSC leads and supervises most sectors, with existing sector regulators taking their own. This is the structure proposed in Head 17 of the General Scheme, not final law.
| Authority | Proposed NIS2 remit |
|---|---|
| National Cyber Security Centre (NCSC) | Lead competent authority, national CSIRT and single point of contact; competent authority for sectors not given to another regulator |
| Commission for Communications Regulation (ComReg) | Digital infrastructure, ICT service management (B2B), digital providers, space |
| Central Bank of Ireland | Banking and financial market infrastructure (most of which falls under DORA instead, see below) |
| Irish Aviation Authority | Aviation |
| Commission for Railway Regulation | Rail |
| Sector bodies for road, maritime and health | As designated in the General Scheme; the final list is whatever the enacted Act says |
Financial entities within DORA (Regulation (EU) 2022/2554) follow DORA for ICT risk management and incident reporting, because DORA is the sector-specific law. If you're a bank, insurer or investment firm, start with our DORA compliance services rather than this page.
Initial screening
You can't answer this from your industry name alone. NIS2 scope turns on the services you provide (as listed in Annex I and II of the Directive), your size under the EU SME definition, a list of size-independent inclusions, and where you're established. Five questions get you a first read.
Size rule in one line: most Annex I and II entities are in scope only if they are at least medium-sized, meaning 50 or more staff, or annual turnover over €10m and a balance sheet over €10m. Partner and linked enterprises count towards those figures.
Your indicative result
Answer the questions to see a first read.
This screener follows Articles 2 and 3 of the Directive. It can't account for every exception, group structure or future Irish designation.
Confirm my scope with a consultantIndicative only, not legal advice. The NCSC also offers an Am I in Scope? tool, and says the decision on scope is yours to make, taking legal advice where needed.
180 staff, €40m turnover. Manufacturing medical devices is an Annex II service and the company is medium-sized, so it is likely an important entity.
60 staff, B2B managed IT and security services. ICT service management is Annex I; at medium size it is likely important, and the main-establishment rule decides which country supervises it.
35 staff selling software to hospitals. Probably outside direct scope, yet its hospital customers must manage supply-chain risk under Article 21, so NIS2-style requirements will arrive by contract.
Classification
People sometimes read "important" as "lighter". It isn't, in terms of what you have to do. Both categories carry the same security and reporting obligations. The difference is how you're supervised and how high the ceiling on fines goes.
| Essential entity | Important entity | |
|---|---|---|
| Who (Directive, Article 3) | Large entities providing Annex I services; qualified trust service providers, TLD registries and DNS providers of any size; medium or larger public electronic communications providers; central government; critical entities; entities a Member State identifies; existing NIS1 operators of essential services | Every other in-scope entity: medium-sized Annex I entities and medium or large Annex II entities, plus any the State identifies as important |
| Risk-management and reporting obligations | Article 21 measures, Article 23 incident reporting, Article 20 management duties | The same: Article 21, Article 23 and Article 20 apply in full |
| Supervision | Proactive (ex ante): on-site inspections, random checks, regular and targeted audits, security scans | Reactive (ex post): triggered by evidence, an indication or information suggesting non-compliance |
| Administrative fines (Article 34) | Member States must set a maximum of at least €10m or 2% of worldwide annual turnover, whichever is higher | Maximum of at least €7m or 1.4% of worldwide annual turnover, whichever is higher |
| Management consequences | Possible temporary ban on a CEO or legal representative from managerial functions (Article 32(5)) | Management can still be held liable under Article 20; the temporary-ban power is specific to essential entities |
| Irish detail | Final penalty levels and procedures will be set by the enacted Act | As for essential entities |
Fine figures are the minimum ceilings the Directive requires Member States to allow; Ireland's Act may set its own amounts at or above them. Supervision descriptions follow Articles 32 and 33.
Where you stand
A NIS2 compliance assessment tells you, area by area, how close your current set-up is to what Article 21 and the NCSC's draft Risk Management Measures expect. We interview the people who run the controls, read the documents, and then ask to see proof: a restore log, an access review, a supplier file. Documents that exist but aren't followed show up quickly.
If you already hold ISO 27001 or use CyFun, we map from what you have rather than starting again. A lot of NIS2 is covered; the gaps tend to be board oversight, reporting timelines and supplier assurance.
A written assessment report with a scope and classification note, a requirement-by-requirement maturity rating, the evidence we saw (and didn't), and a prioritised list of actions.
A certificate, or a regulator's view. It's an independent, evidence-based picture you can use to plan work and brief your board.
Implementation support
An assessment tells you what's missing. Our NIS2 consulting work is about closing it without building a paper programme nobody follows. We work alongside your security, IT, risk and legal teams, and we'd rather leave you with a process your staff can run than a folder of documents only we understand.
01
We map your services to Annex I and II, apply the size rules to your group structure, and write down the reasoning, so you have a defensible position if anyone asks.
02
Article 21(2)(a) to (j) mapped against your existing controls, ISO 27001 Annex A or CyFun, so each requirement has an owner and a status.
03
We draft or rework the policies NIS2 expects (risk, incident, continuity, supplier, cryptography, access) around how your teams actually operate.
04
Triage criteria for "significant incident", decision rights, and templates for the 24-hour early warning and 72-hour notification, then a tabletop exercise to test them.
05
Supplier tiering, a proportionate due-diligence questionnaire, contract clauses, and a review cycle for critical providers.
06
Short, sector-specific sessions so your management body can approve measures with some understanding of what it's signing, as Article 20 expects.
07
An evidence register that ties each requirement to where proof lives and who keeps it current.
08
Hands-on consulting while your team closes gaps, including technical work such as MFA roll-out planning or vulnerability-management process design.
Running ISO 27001, GDPR or DORA alongside NIS2? Our AuditFusion360 multi-framework approach tests shared controls once and maps the results across frameworks.
Method
A NIS2 gap assessment is the usual starting point, and how long it takes depends mostly on your size and how much documentation you already have. Eight steps, done in this order for a reason: there's no point testing evidence for a requirement that doesn't apply to you.
Confirm scope
Services, entities and group structure; essential or important.
Map applicable requirements
Article 20, 21 and 23 duties plus relevant NCSC measures.
Review existing controls
Interviews with control owners across IT, security, risk and operations.
Review documentation
Policies, procedures, registers and contracts, checked for currency and approval.
Test evidence
Samples of records: access reviews, backups, patching, training, supplier files.
Identify gaps
Missing, partial or ineffective controls, each tied to a requirement.
Prioritise risks
Ranked by regulatory exposure, security risk and effort.
Develop remediation plan
Owners, sequence and realistic timings your team can commit to.
Want to see the method in more depth first? Our NIS2 compliance checklist walks through the same areas.
Independent testing
A NIS2 compliance audit is where we stop advising and start testing. We take a sample period, check that each measure was designed properly and actually operated, and record the evidence behind every conclusion. Most clients use it once remediation is well under way, or before a board sign-off.
It's also practice for the real thing. Under Articles 32 and 33, competent authorities can require security audits by an independent body and ask for audit results and the underlying evidence. Organisations that have been through an independent NIS2 audit usually find those requests much easier to answer.
There is no general "NIS2 certification" in the Directive or in Ireland today. Compliance is decided by the competent authority. Anyone selling you a NIS2 certificate is selling something else.
We won't tell you that passing our audit makes you compliant. We will tell you exactly what we tested and what we found.
Article 21
Article 21(2) lists ten areas your measures must cover as a minimum. They have to be appropriate and proportionate to your risk, size and the impact an incident would have, taking into account the state of the art. That's a judgment call, and it's where most NIS2 conversations end up.
For some digital providers (cloud, data centre, managed service and managed security providers, among others), Commission Implementing Regulation (EU) 2024/2690 sets the technical detail directly. For everyone else in Ireland, the NCSC's draft Risk Management Measures are the best guide to how these ten areas will be read.
Risk analysis and information-system security policies
A risk method that's actually used to make decisions, and policies approved by management.
Incident handling
Detection, triage, escalation and learning, with defined criteria for what counts as significant.
Business continuity and crisis management
Backup management, disaster recovery and crisis management, with restores that have been tested, not assumed.
Supply-chain security
Security aspects of relationships with direct suppliers and service providers.
Security in acquisition, development and maintenance
Including vulnerability handling and disclosure.
Assessing effectiveness
Policies and procedures to check whether your measures work: testing, metrics, audit.
Cyber hygiene and training
Basic hygiene practices plus cybersecurity training for staff.
Cryptography and encryption
Policies on cryptography and, where appropriate, encryption.
HR security, access control and asset management
Joiners-movers-leavers, least privilege, and knowing what you own.
MFA and secured communications
Multi-factor or continuous authentication, secured voice, video and text, and secured emergency communications, where appropriate.
Summaries paraphrase Article 21(2), Directive (EU) 2022/2555. The legal text governs.
Supply chain
NIS2 makes you responsible for the security aspects of your relationships with direct suppliers and service providers. Article 21(3) goes further: when you decide what's appropriate, you have to take into account each supplier's specific vulnerabilities, the overall quality of their products and security practices, and their secure development procedures.
For a lot of Irish organisations, this is the largest piece of new work. It's also where NIS2 reaches beyond its own scope: suppliers that aren't in scope themselves get NIS2 requirements through contracts with customers that are.
We run supplier security reviews and third-party assessments as part of NIS2 work, and as a standalone third-party risk management service.
Who your suppliers are
A single inventory covering IT, OT, cloud, SaaS and outsourced services, with owners.
Which ones are critical
Tiered by what fails if they fail, not by spend.
How secure they are
Proportionate due diligence: questionnaires for most, evidence (ISO 27001, SOC 2, pen test summaries) for the critical few.
What the contract says
Security obligations, incident notification to you, audit rights, subcontracting and exit.
Their vulnerabilities
Tracking advisories for the products and providers you rely on.
Their incidents
How a supplier's breach reaches your incident process and, if significant, your own reporting clock.
Article 23
An incident is significant if it has caused, or could cause, severe operational disruption or financial loss for you, or considerable material or non-material damage to others. When that happens, NIS2 sets a staged reporting timeline to your CSIRT or competent authority.
Within 24 hours
Early warning
Of becoming aware of a significant incident. Say whether it may be caused by unlawful or malicious acts and whether it could have a cross-border impact.
Within 72 hours
Incident notification
Of becoming aware. Update the early warning with an initial assessment of severity and impact, and indicators of compromise where available.
On request
Intermediate report
Status updates if the CSIRT or competent authority asks for them.
Within one month
Final report
Of the incident notification: a detailed description, the likely root cause, mitigation applied and any cross-border impact. If the incident is still ongoing, a progress report instead, then a final report within a month of handling it.
The NCSC (CSIRT-IE) will run a dedicated NIS2 incident reporting portal once the Bill is enacted; it isn't live yet. Designated operators under NIS1 report under the existing rules, and any organisation can report an incident to the NCSC voluntarily now.
Not the deadlines, but the decision before them: who decides an incident is significant, on what criteria, at 2am on a Sunday. We build that decision into your runbook and test it with a tabletop. More detail in our guide to the NIS2 incident reporting timeline.
You may also have to inform recipients of your services, without undue delay, about significant incidents likely to affect them (Article 23(1)) and, separately, notify the Data Protection Commission if personal data is breached under GDPR.
Article 20
Article 20 moves cybersecurity from the IT agenda to the board agenda. In July 2026 the NCSC published guidance for management board members of NIS2 entities (in the public sector, that includes Accounting Officers) setting out how it expects boards to approve, oversee and understand cyber risk.
In our experience, boards don't need to become technical. They need three things: a clear view of the organisation's top cyber risks, a short set of measures they can track, and enough training to challenge what they're told. We run board briefings built around your sector and your actual gap-assessment findings.
Some organisations bring in a virtual CISO to own that reporting line; see our CISO advisory service.
The management body approves the cybersecurity risk-management measures taken to comply with Article 21.
It oversees their implementation, which means regular, informed reporting, not a once-a-year slide.
Members of the management body must follow training so they can identify risks and assess security practices. Entities are encouraged to offer similar training to staff.
Management bodies can be held liable for infringements of Article 21 by the entity. Irish rules on how will be set by the Act.
Roadmap
Thirteen steps, grouped into four phases. The last one never finishes: NIS2 expects measures to be reviewed as risks, systems and suppliers change. Treat it as a management cycle, not a one-off project with an end date.
Understand
Assess
Build
Prove and sustain
↻Step 13 feeds back into step 1: re-check scope when you add services, acquire a company or cross a size threshold.
Audit readiness
When a supervisor or auditor asks how you meet a requirement, the answer that works is a document plus a record that shows it happened. Below is the kind of evidence we typically look for. Not every item applies to every organisation; what you need depends on your size, risk and classification.
Governance
Risk and assets
Incidents and continuity
Access and technical
Suppliers and people
A tip from audit work: date everything, and record who approved it. "We have a DR plan" is a statement. "The DR plan v3.1, approved by the COO on 12 March, tested on 4 June with a 3-hour restore of the ERP system" is evidence.
Related: our guide to NIS2 documentation requirements and policies.
At a glance
A condensed view of the main areas, the questions we'd ask in a first meeting, and where we can help. Use it to run your own quick self-check before you call anyone.
| NIS2 area | What it covers | Questions to ask | Potential evidence | How VISTA can support |
|---|---|---|---|---|
| Governance | Roles, policies and approval of security measures | Who owns NIS2? Has management approved our measures? | Approval minutes, RACI, policy register | Governance design, policy drafting |
| Risk management | Art. 21(2)(a): risk analysis and system security policies | Is our risk assessment current and used to choose controls? | Risk register, treatment plans, method | Risk assessment facilitation |
| Incident handling | Art. 21(2)(b) and Art. 23 reporting | Could we issue an early warning within 24 hours? | Runbooks, incident log, exercise reports | Runbooks, reporting templates, tabletop exercises |
| Business continuity | Art. 21(2)(c): backup, DR, crisis management | When did we last restore a critical system end to end? | BCPs, restore test records, crisis plans | BIA review, DR test design and observation |
| Supply chain | Art. 21(2)(d) and 21(3) | Which suppliers could stop our essential services? | Supplier inventory, assessments, contracts | Supplier tiering, due diligence, contract clauses |
| Vulnerability management | Art. 21(2)(e): handling and disclosure | How fast do we fix critical vulnerabilities, and can we prove it? | Scan reports, patch SLAs, disclosure policy | Vulnerability assessment, CREST penetration testing |
| Access control | Art. 21(2)(i): HR security, access, assets | Are leavers removed promptly? Are admin rights reviewed? | Access reviews, JML records, asset list | Access control review, configuration assessment |
| MFA | Art. 21(2)(j): MFA and secured communications | Where is MFA not enforced, and why? | MFA coverage report, exception register | MFA gap analysis and roll-out planning |
| Training | Art. 21(2)(g) and Art. 20(2) | Has the board been trained? Do staff get regular awareness? | Training records, content, attendance | Board briefings, staff awareness |
| Management oversight | Art. 20(1): oversee implementation | What does the board see each quarter? | Board reports, KPIs, follow-up actions | Board reporting pack, vCISO support |
Delivery
Our NIS2 services are open to organisations anywhere in Ireland: tech, data-centre and financial-services operators in Dublin, medical device and life-sciences manufacturers around Cork, Galway and Limerick, or manufacturing and logistics businesses in the south-east around Waterford.
To be straightforward about it: VISTA Infosec doesn't have an office in Ireland. EU engagements are contracted through Zulon Audits OÜ, our EU entity in Tallinn, and delivered by our in-house team. Most NIS2 work runs remotely during Irish business hours, with on-site workshops, interviews or evidence reviews when they're genuinely useful and agreed in advance.
Remote-first
Workshops, interviews and evidence review over secure video and our portal.
Irish hours
Scheduling on Irish time, including board sessions.
EU evidence
Evidence can be processed and stored in the EU on request.
On-site by agreement
For board briefings, tabletop exercises or site walk-throughs.
Scope by sector
These are the sectors named in the Directive's annexes. Being in one doesn't put you in scope automatically: what matters is the specific service you provide, your size, and whether an inclusion applies. Ireland may also add sectors when it transposes.
*Financial entities covered by DORA apply DORA's ICT risk-management and incident-reporting rules instead of NIS2's. Public administration scope depends on national designation.
Why us
Our core work for more than 21 years has been independent security and compliance audit: PCI DSS as a QSA company, plus ISO 27001 and SOC 2 engagements. We know what a tester asks for, and we build your NIS2 evidence with that in mind.
CREST-accredited and CERT-In empanelled, so the technical side of Article 21, from penetration testing to configuration reviews and red-team exercises, is done by our own people, not subcontracted.
Team credentials include CISSP, CISA, CRISC and ISO 27001 Lead Auditor. We're ISO 27001 certified ourselves, so we run the same kind of management system we assess.
No Irish office, no NIS2 certificate, no guarantees about a regulator's view. What you get is a clear method, documented evidence and advice you can check against the law.
A short call to talk through your services, size and current controls. We'll tell you honestly whether you need us.
Commercials
We don't publish a price list, because a 60-person MSP and a multi-site manufacturer need very different amounts of work. After a short scoping call and questionnaire, we give you a fixed fee for a defined scope, with timelines, before any work starts.
Most organisations start with a gap assessment, which is the smallest commitment and tells you how much implementation work there actually is.
Request a NIS2 AssessmentBeyond the template
Checklists are a good start. We publish one. But two organisations can tick the same box and be in very different positions: one has an incident plan that has been exercised, the other has a document written for an ISO audit three years ago.
NIS2 is proportionate by design, so what counts as appropriate depends on your entity type, sector, size, services, jurisdiction, technology, existing controls, suppliers and risk exposure. A checklist can't weigh those. An evidence-based assessment can, and it gives you something a checklist never will: proof.
| Generic checklist | Evidence-based assessment |
|---|---|
| "Do you have an incident response plan?" | Was it tested, when, who was involved, and what changed afterwards? |
| "Is MFA enabled?" | Where is it not enforced, who approved the exceptions, and are they reviewed? |
| "Do you assess suppliers?" | Which suppliers are critical, and what evidence did you get from them? |
| Same questions for everyone | Scoped to your classification, services and risk |
FAQ
NIS2 is Directive (EU) 2022/2555, the EU law setting cybersecurity risk-management, incident-reporting and governance obligations for organisations in critical sectors. It replaced the 2016 NIS Directive, covers far more sectors, and applies once each Member State transposes it into national law.
Not yet. As at 23 September 2026, the National Cyber Security Bill that will transpose NIS2 has not been enacted. The Government published the General Scheme in August 2024 and lists the Bill for priority publication in its Autumn 2026 Legislation Programme. In July 2026 the European Commission referred Ireland to the Court of Justice of the EU for failing to notify transposition. Until the Bill is enacted, the existing NIS1 regulations continue to apply to designated operators of essential services.
No. The NCSC has said its NIS2 registration and incident reporting portals will only go live once the legislation is in place, and there is currently no requirement to register. Many organisations are using the time to confirm scope and classification so registration is quick when it opens.
It depends on the services you provide, your size and where you are established, not just your industry. Most entities in Annex I or II sectors are in scope only if they are at least medium-sized (50 or more staff, or turnover and balance sheet above €10 million), but some, such as DNS providers, trust service providers and public electronic communications providers, can be in scope regardless of size. The NCSC expects organisations to make the determination themselves, with legal advice where needed.
Both must meet the same risk-management, incident-reporting and management-body obligations. Essential entities, generally large organisations in Annex I sectors plus certain specific types, are supervised proactively and face higher maximum fines. Important entities are supervised reactively, typically when there is evidence of non-compliance, with lower maximum fines.
Under the proposals in the General Scheme, the National Cyber Security Centre will be the lead competent authority and national CSIRT, supervising most sectors, while sector regulators such as ComReg, the Central Bank of Ireland, the Irish Aviation Authority and the Commission for Railway Regulation take their own sectors. The final allocation will be set by the enacted Act.
A NIS2 compliance consultant helps you confirm scope and classification, compares your current controls with NIS2 requirements, and supports you in closing the gaps: policies, incident processes, supplier security, board training and evidence. At VISTA Infosec the same in-house team can later carry out an independent audit, with the audit scope agreed separately.
A gap assessment is diagnostic: it maps requirements to your current position and produces a gap register and remediation roadmap. An audit is later and more formal: it tests whether measures were designed properly and operated effectively over a period, and records the evidence behind each conclusion.
There is no general NIS2 certification. Compliance is determined by the competent authority. In Ireland the NCSC recommends the Cyber Fundamentals (CyFun) framework, and certification against it will be optional once a national scheme is established; ISO/IEC 27001 certification is also recognised as a way to organise controls. Neither is a statutory presumption of NIS2 compliance.
For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, intermediate reports on request, and a final report within one month of the incident notification. In Ireland the dedicated NIS2 reporting portal will open once the Bill is enacted.
It depends on your size, classification, locations, technology, current maturity and how much implementation support you want. VISTA Infosec agrees a fixed fee for a defined scope after a short scoping call and questionnaire. A gap assessment is usually the smallest first step.
Yes. We support organisations across Ireland, mostly remotely during Irish business hours, with on-site sessions by agreement. VISTA Infosec does not have an Irish office; EU engagements are contracted through our EU entity, Zulon Audits OÜ.
Expert Auditors. Faster Certification.
European Operations
European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
Visit Zulon Audits →
VISTA InfoSec LLC,347 Fifth Ave,
Suite 1402-526, New York, NY 10016
© Copyright 2026. VISTA InfoSec. All Rights Reserved. | Disclosure Policy | Privacy Policy | Sitemap
Enquire Now
WhatsApp us