vista infosec white

NIS2 Compliance Consultancy

NIS2 Compliance in Ireland: Consultancy, Assessment and Audit Support

Ireland hasn't finished transposing NIS2 yet. That doesn't leave you with nothing to do. We help Irish organisations work out whether they're in scope, find the real gaps in governance and security controls, and build the evidence to show those controls work, so you're ready when the National Cyber Security Bill is enacted and the NCSC opens registration.

  • Scope and classification: essential, important, or out of scope
  • Gap assessment against Article 21 and the NCSC's draft Risk Management Measures
  • Implementation support for the gaps that matter most
  • Independent NIS2 compliance audit of what's in place, with evidence you can put in front of a regulator
21+ years in security auditCREST-accreditedCERT-In empanelledPCI QSAISO 27001 certified ourselvesIn-house team, no subcontracting

Talk to a Compliance Expert

    Where Ireland stands

    NIS2 Compliance in Ireland: The Position Today

    NIS2 is an EU directive, so it only bites on organisations once each Member State writes it into national law. In Ireland that law will be the National Cyber Security Bill. As at 23 September 2026, it has not been enacted. The Government has published a General Scheme (the draft outline of the Bill), and the Bill sits on the Autumn 2026 Legislation Programme for priority publication.

    So, strictly, there's no Irish NIS2 statute to comply with yet. In practice the direction is clear. The Directive's obligations are fixed at EU level, the NCSC has published the risk-management and governance expectations it intends to supervise against, and the Commission has taken Ireland to the Court of Justice over the delay, asking for financial penalties until transposition is notified. The gap between enactment and supervision is unlikely to be generous.

    That's why organisations that expect to be in scope are doing the work now: confirming scope, fixing the obvious gaps, and getting management sign-off in place before the registration portal opens.

    What we are careful not to say

    The General Scheme is a draft. Authority designations, penalty amounts, registration deadlines and any Irish-specific additions will be whatever the enacted Act and its regulations say, and they can change as the Bill goes through the Oireachtas. We track the Bill and update this page when it moves.

    NIS2 in Ireland: key dates

    1. 16 Jan 2023

      Directive (EU) 2022/2555 (NIS2) enters into force across the EU.

    2. 30 Aug 2024

      Government publishes the General Scheme of the National Cyber Security Bill 2024, the draft framework for transposing NIS2 and putting the NCSC on a statutory footing.

    3. 17 Oct 2024

      EU transposition deadline. Ireland, like most Member States, misses it.

    4. Nov 2024 – May 2025

      The Commission opens infringement proceedings (formal notice), then sends a reasoned opinion on 7 May 2025.

    5. 24 Jun 2025

      NCSC publishes draft NIS2 Risk Management Measures and recommends the Cyber Fundamentals (CyFun) framework.

    6. Jul 2026

      NCSC publishes guidance on cyber governance for management boards in NIS2 entities. The Commission refers Ireland to the Court of Justice of the EU for failing to notify transposition.

    7. Sep 2026

      The Government's Autumn 2026 Legislation Programme lists the National Cyber Security Bill for priority publication.

    8. Next

      Bill published and passed by the Oireachtas, then commenced. The NCSC opens the NIS2 registration and incident reporting portals once the law is in place.

    What this means for Irish organisations right now

    NIS1 still applies

    Organisations designated as Operators of Essential Services under the existing NIS regulations remain subject to them. The NCSC says NIS1 stays in full effect until NIS2 legislation replaces it.

    No NIS2 registration yet

    The NCSC's NIS2 registration and incident reporting portals aren't live and won't be until the Bill is enacted. There's currently no requirement to register under NIS2 in Ireland.

    The guidance is already out

    The NCSC's draft Risk Management Measures describe what it sees as the minimum for essential and important entities. Its July 2026 board guidance sets out what management should be doing. Neither is law, but both show where supervision is heading.

    Customers aren't waiting

    Many Irish organisations first meet NIS2 through a supplier questionnaire or a contract clause from a customer that is in scope. That pressure exists today, whatever the Oireachtas timetable.

    Who is expected to supervise NIS2 in Ireland (proposed)

    Ireland is planning a distributed model: the NCSC leads and supervises most sectors, with existing sector regulators taking their own. This is the structure proposed in Head 17 of the General Scheme, not final law.

    AuthorityProposed NIS2 remit
    National Cyber Security Centre (NCSC)Lead competent authority, national CSIRT and single point of contact; competent authority for sectors not given to another regulator
    Commission for Communications Regulation (ComReg)Digital infrastructure, ICT service management (B2B), digital providers, space
    Central Bank of IrelandBanking and financial market infrastructure (most of which falls under DORA instead, see below)
    Irish Aviation AuthorityAviation
    Commission for Railway RegulationRail
    Sector bodies for road, maritime and healthAs designated in the General Scheme; the final list is whatever the enacted Act says

    Financial entities within DORA (Regulation (EU) 2022/2554) follow DORA for ICT risk management and incident reporting, because DORA is the sector-specific law. If you're a bank, insurer or investment firm, start with our DORA compliance services rather than this page.

    Initial screening

    Does NIS2 Apply to Your Organisation?

    You can't answer this from your industry name alone. NIS2 scope turns on the services you provide (as listed in Annex I and II of the Directive), your size under the EU SME definition, a list of size-independent inclusions, and where you're established. Five questions get you a first read.

    Size rule in one line: most Annex I and II entities are in scope only if they are at least medium-sized, meaning 50 or more staff, or annual turnover over €10m and a balance sheet over €10m. Partner and linked enterprises count towards those figures.

    1Which best describes the services you provide in the EU?
    2How large is the organisation, including partner and linked enterprises?
    3Do any size-independent inclusions apply?
    4Are you a financial entity regulated under DORA?
    5Where is the organisation established?

    Your indicative result

    Answer the questions to see a first read.

    This screener follows Articles 2 and 3 of the Directive. It can't account for every exception, group structure or future Irish designation.

    Confirm my scope with a consultant

    Indicative only, not legal advice. The NCSC also offers an Am I in Scope? tool, and says the decision on scope is yours to make, taking legal advice where needed.

    Example: Cork medical device manufacturer

    180 staff, €40m turnover. Manufacturing medical devices is an Annex II service and the company is medium-sized, so it is likely an important entity.

    Example: Dublin managed service provider

    60 staff, B2B managed IT and security services. ICT service management is Annex I; at medium size it is likely important, and the main-establishment rule decides which country supervises it.

    Example: Galway software supplier

    35 staff selling software to hospitals. Probably outside direct scope, yet its hospital customers must manage supply-chain risk under Article 21, so NIS2-style requirements will arrive by contract.

    Classification

    Essential vs Important Entities

    People sometimes read "important" as "lighter". It isn't, in terms of what you have to do. Both categories carry the same security and reporting obligations. The difference is how you're supervised and how high the ceiling on fines goes.

    Essential entityImportant entity
    Who (Directive, Article 3)Large entities providing Annex I services; qualified trust service providers, TLD registries and DNS providers of any size; medium or larger public electronic communications providers; central government; critical entities; entities a Member State identifies; existing NIS1 operators of essential servicesEvery other in-scope entity: medium-sized Annex I entities and medium or large Annex II entities, plus any the State identifies as important
    Risk-management and reporting obligationsArticle 21 measures, Article 23 incident reporting, Article 20 management dutiesThe same: Article 21, Article 23 and Article 20 apply in full
    SupervisionProactive (ex ante): on-site inspections, random checks, regular and targeted audits, security scansReactive (ex post): triggered by evidence, an indication or information suggesting non-compliance
    Administrative fines (Article 34)Member States must set a maximum of at least €10m or 2% of worldwide annual turnover, whichever is higherMaximum of at least €7m or 1.4% of worldwide annual turnover, whichever is higher
    Management consequencesPossible temporary ban on a CEO or legal representative from managerial functions (Article 32(5))Management can still be held liable under Article 20; the temporary-ban power is specific to essential entities
    Irish detailFinal penalty levels and procedures will be set by the enacted ActAs for essential entities

    Fine figures are the minimum ceilings the Directive requires Member States to allow; Ireland's Act may set its own amounts at or above them. Supervision descriptions follow Articles 32 and 33.

    Where you stand

    NIS2 Compliance Assessment

    A NIS2 compliance assessment tells you, area by area, how close your current set-up is to what Article 21 and the NCSC's draft Risk Management Measures expect. We interview the people who run the controls, read the documents, and then ask to see proof: a restore log, an access review, a supplier file. Documents that exist but aren't followed show up quickly.

    If you already hold ISO 27001 or use CyFun, we map from what you have rather than starting again. A lot of NIS2 is covered; the gaps tend to be board oversight, reporting timelines and supplier assurance.

    Scope and governance

    • Entity classification and the services that drive it
    • Management-body approval and oversight of security measures
    • Board training records
    • Roles, responsibilities and reporting lines

    Risk and policy

    • Risk analysis method and current risk register
    • Information-security policy set
    • Asset inventory and ownership
    • Cryptography and encryption policy

    Resilience

    • Incident handling and escalation
    • Business continuity, backup and disaster recovery
    • Crisis management and communications
    • Reporting readiness for 24h / 72h / one-month deadlines

    Technical controls

    • Access control and privileged access
    • MFA coverage and exceptions
    • Vulnerability handling and disclosure
    • Secure acquisition, development and maintenance

    Third parties

    • Supplier inventory and criticality
    • Security clauses in contracts
    • Assurance you receive from suppliers
    • Concentration and exit risks

    Effectiveness

    • How you measure whether controls work
    • Security testing results and remediation
    • Cyber hygiene and staff training
    • Internal audit coverage

    What you get

    A written assessment report with a scope and classification note, a requirement-by-requirement maturity rating, the evidence we saw (and didn't), and a prioritised list of actions.

    What it isn't

    A certificate, or a regulator's view. It's an independent, evidence-based picture you can use to plan work and brief your board.

    Implementation support

    NIS2 Compliance Consultancy for Irish Organisations

    An assessment tells you what's missing. Our NIS2 consulting work is about closing it without building a paper programme nobody follows. We work alongside your security, IT, risk and legal teams, and we'd rather leave you with a process your staff can run than a folder of documents only we understand.

    01

    Scope determination

    We map your services to Annex I and II, apply the size rules to your group structure, and write down the reasoning, so you have a defensible position if anyone asks.

    02

    Requirement mapping

    Article 21(2)(a) to (j) mapped against your existing controls, ISO 27001 Annex A or CyFun, so each requirement has an owner and a status.

    03

    Policies that people use

    We draft or rework the policies NIS2 expects (risk, incident, continuity, supplier, cryptography, access) around how your teams actually operate.

    04

    Incident processes

    Triage criteria for "significant incident", decision rights, and templates for the 24-hour early warning and 72-hour notification, then a tabletop exercise to test them.

    05

    Supply-chain security

    Supplier tiering, a proportionate due-diligence questionnaire, contract clauses, and a review cycle for critical providers.

    06

    Board briefing and training

    Short, sector-specific sessions so your management body can approve measures with some understanding of what it's signing, as Article 20 expects.

    07

    Evidence preparation

    An evidence register that ties each requirement to where proof lives and who keeps it current.

    08

    Remediation support

    Hands-on consulting while your team closes gaps, including technical work such as MFA roll-out planning or vulnerability-management process design.

    Running ISO 27001, GDPR or DORA alongside NIS2? Our AuditFusion360 multi-framework approach tests shared controls once and maps the results across frameworks.

    Method

    NIS2 Gap Assessment

    A NIS2 gap assessment is the usual starting point, and how long it takes depends mostly on your size and how much documentation you already have. Eight steps, done in this order for a reason: there's no point testing evidence for a requirement that doesn't apply to you.

    1. 1

      Confirm scope

      Services, entities and group structure; essential or important.

    2. 2

      Map applicable requirements

      Article 20, 21 and 23 duties plus relevant NCSC measures.

    3. 3

      Review existing controls

      Interviews with control owners across IT, security, risk and operations.

    4. 4

      Review documentation

      Policies, procedures, registers and contracts, checked for currency and approval.

    5. 5

      Test evidence

      Samples of records: access reviews, backups, patching, training, supplier files.

    6. 6

      Identify gaps

      Missing, partial or ineffective controls, each tied to a requirement.

    7. 7

      Prioritise risks

      Ranked by regulatory exposure, security risk and effort.

    8. 8

      Develop remediation plan

      Owners, sequence and realistic timings your team can commit to.

    Outputs

    Scope findings and classification rationaleRequirement mappingGap registerRisk-prioritised findingsEvidence observationsRemediation roadmap

    Want to see the method in more depth first? Our NIS2 compliance checklist walks through the same areas.

    Independent testing

    NIS2 Audit Services in Ireland

    A NIS2 compliance audit is where we stop advising and start testing. We take a sample period, check that each measure was designed properly and actually operated, and record the evidence behind every conclusion. Most clients use it once remediation is well under way, or before a board sign-off.

    It's also practice for the real thing. Under Articles 32 and 33, competent authorities can require security audits by an independent body and ask for audit results and the underlying evidence. Organisations that have been through an independent NIS2 audit usually find those requests much easier to answer.

    What a NIS2 audit from us covers

    • Governance and management oversight
    • Policy set and approvals
    • Risk management process
    • Control design
    • Control implementation and operation
    • Evidence quality and completeness
    • Technical security controls, with testing where agreed
    • Incident readiness and reporting
    • Business continuity and recovery
    • Supply-chain risk
    • Status of earlier remediation

    NIS2 isn't a certificate you buy

    There is no general "NIS2 certification" in the Directive or in Ireland today. Compliance is decided by the competent authority. Anyone selling you a NIS2 certificate is selling something else.

    What does exist

    • CyFun: Ireland is a co-owner of this Belgian framework. The NCSC recommends it and says certification against it will be optional, with a national scheme expected to take 18–24 months to set up.
    • ISO/IEC 27001: recognised by the NCSC as another route. We prepare you; certificates are issued by an accredited certification body we partner with.
    • Our audit report: an independent opinion on your controls, mapped to NIS2 articles. Useful evidence, not regulatory approval.

    We won't tell you that passing our audit makes you compliant. We will tell you exactly what we tested and what we found.

    Article 21

    Cybersecurity Risk-Management Measures

    Article 21(2) lists ten areas your measures must cover as a minimum. They have to be appropriate and proportionate to your risk, size and the impact an incident would have, taking into account the state of the art. That's a judgment call, and it's where most NIS2 conversations end up.

    For some digital providers (cloud, data centre, managed service and managed security providers, among others), Commission Implementing Regulation (EU) 2024/2690 sets the technical detail directly. For everyone else in Ireland, the NCSC's draft Risk Management Measures are the best guide to how these ten areas will be read.

    (a)

    Risk analysis and information-system security policies

    A risk method that's actually used to make decisions, and policies approved by management.

    (b)

    Incident handling

    Detection, triage, escalation and learning, with defined criteria for what counts as significant.

    (c)

    Business continuity and crisis management

    Backup management, disaster recovery and crisis management, with restores that have been tested, not assumed.

    (d)

    Supply-chain security

    Security aspects of relationships with direct suppliers and service providers.

    (e)

    Security in acquisition, development and maintenance

    Including vulnerability handling and disclosure.

    (f)

    Assessing effectiveness

    Policies and procedures to check whether your measures work: testing, metrics, audit.

    (g)

    Cyber hygiene and training

    Basic hygiene practices plus cybersecurity training for staff.

    (h)

    Cryptography and encryption

    Policies on cryptography and, where appropriate, encryption.

    (i)

    HR security, access control and asset management

    Joiners-movers-leavers, least privilege, and knowing what you own.

    (j)

    MFA and secured communications

    Multi-factor or continuous authentication, secured voice, video and text, and secured emergency communications, where appropriate.

    Summaries paraphrase Article 21(2), Directive (EU) 2022/2555. The legal text governs.

    Supply chain

    Supply-Chain Security

    NIS2 makes you responsible for the security aspects of your relationships with direct suppliers and service providers. Article 21(3) goes further: when you decide what's appropriate, you have to take into account each supplier's specific vulnerabilities, the overall quality of their products and security practices, and their secure development procedures.

    For a lot of Irish organisations, this is the largest piece of new work. It's also where NIS2 reaches beyond its own scope: suppliers that aren't in scope themselves get NIS2 requirements through contracts with customers that are.

    We run supplier security reviews and third-party assessments as part of NIS2 work, and as a standalone third-party risk management service.

    Who your suppliers are

    A single inventory covering IT, OT, cloud, SaaS and outsourced services, with owners.

    Which ones are critical

    Tiered by what fails if they fail, not by spend.

    How secure they are

    Proportionate due diligence: questionnaires for most, evidence (ISO 27001, SOC 2, pen test summaries) for the critical few.

    What the contract says

    Security obligations, incident notification to you, audit rights, subcontracting and exit.

    Their vulnerabilities

    Tracking advisories for the products and providers you rely on.

    Their incidents

    How a supplier's breach reaches your incident process and, if significant, your own reporting clock.

    Article 23

    NIS2 Incident Reporting

    An incident is significant if it has caused, or could cause, severe operational disruption or financial loss for you, or considerable material or non-material damage to others. When that happens, NIS2 sets a staged reporting timeline to your CSIRT or competent authority.

    Within 24 hours

    Early warning

    Of becoming aware of a significant incident. Say whether it may be caused by unlawful or malicious acts and whether it could have a cross-border impact.

    Within 72 hours

    Incident notification

    Of becoming aware. Update the early warning with an initial assessment of severity and impact, and indicators of compromise where available.

    On request

    Intermediate report

    Status updates if the CSIRT or competent authority asks for them.

    Within one month

    Final report

    Of the incident notification: a detailed description, the likely root cause, mitigation applied and any cross-border impact. If the incident is still ongoing, a progress report instead, then a final report within a month of handling it.

    How this works in Ireland today

    The NCSC (CSIRT-IE) will run a dedicated NIS2 incident reporting portal once the Bill is enacted; it isn't live yet. Designated operators under NIS1 report under the existing rules, and any organisation can report an incident to the NCSC voluntarily now.

    Where teams usually struggle

    Not the deadlines, but the decision before them: who decides an incident is significant, on what criteria, at 2am on a Sunday. We build that decision into your runbook and test it with a tabletop. More detail in our guide to the NIS2 incident reporting timeline.

    You may also have to inform recipients of your services, without undue delay, about significant incidents likely to affect them (Article 23(1)) and, separately, notify the Data Protection Commission if personal data is breached under GDPR.

    Article 20

    What NIS2 Asks of Boards and Senior Management

    Article 20 moves cybersecurity from the IT agenda to the board agenda. In July 2026 the NCSC published guidance for management board members of NIS2 entities (in the public sector, that includes Accounting Officers) setting out how it expects boards to approve, oversee and understand cyber risk.

    In our experience, boards don't need to become technical. They need three things: a clear view of the organisation's top cyber risks, a short set of measures they can track, and enough training to challenge what they're told. We run board briefings built around your sector and your actual gap-assessment findings.

    Some organisations bring in a virtual CISO to own that reporting line; see our CISO advisory service.

    Approve

    The management body approves the cybersecurity risk-management measures taken to comply with Article 21.

    Oversee

    It oversees their implementation, which means regular, informed reporting, not a once-a-year slide.

    Train

    Members of the management body must follow training so they can identify risks and assess security practices. Entities are encouraged to offer similar training to staff.

    Be accountable

    Management bodies can be held liable for infringements of Article 21 by the entity. Irish rules on how will be set by the Act.

    Roadmap

    A Practical NIS2 Implementation Roadmap

    Thirteen steps, grouped into four phases. The last one never finishes: NIS2 expects measures to be reviewed as risks, systems and suppliers change. Treat it as a management cycle, not a one-off project with an end date.

    Understand

    1. 01Determine scope
    2. 02Identify entity classification
    3. 03Map requirements

    Assess

    1. 04Assess current controls
    2. 05Identify gaps
    3. 06Prioritise risks

    Build

    1. 07Implement controls
    2. 08Strengthen supply-chain security
    3. 09Establish incident processes
    4. 10Build evidence

    Prove and sustain

    1. 11Review management oversight
    2. 12Test effectiveness
    3. 13Maintain ongoing compliance

    Step 13 feeds back into step 1: re-check scope when you add services, acquire a company or cross a size threshold.

    Audit readiness

    NIS2 Audit and Evidence Readiness

    When a supervisor or auditor asks how you meet a requirement, the answer that works is a document plus a record that shows it happened. Below is the kind of evidence we typically look for. Not every item applies to every organisation; what you need depends on your size, risk and classification.

    Governance

    • Management approvals of measures
    • Board training records
    • Security roles and reporting

    Risk and assets

    • Risk assessments and treatment plans
    • Security policies with review dates
    • Asset inventories

    Incidents and continuity

    • Incident procedures and incident records
    • Business continuity plans
    • Backup evidence and disaster recovery tests

    Access and technical

    • Access-control and privileged access reviews
    • MFA coverage evidence
    • Vulnerability management and patch records
    • Security testing reports and remediation records

    Suppliers and people

    • Supplier assessments
    • Contracts with security clauses
    • Staff training evidence

    A tip from audit work: date everything, and record who approved it. "We have a DR plan" is a statement. "The DR plan v3.1, approved by the COO on 12 March, tested on 4 June with a 3-hour restore of the ERP system" is evidence.

    Related: our guide to NIS2 documentation requirements and policies.

    At a glance

    NIS2 Requirements Matrix

    A condensed view of the main areas, the questions we'd ask in a first meeting, and where we can help. Use it to run your own quick self-check before you call anyone.

    NIS2 areaWhat it coversQuestions to askPotential evidenceHow VISTA can support
    GovernanceRoles, policies and approval of security measuresWho owns NIS2? Has management approved our measures?Approval minutes, RACI, policy registerGovernance design, policy drafting
    Risk managementArt. 21(2)(a): risk analysis and system security policiesIs our risk assessment current and used to choose controls?Risk register, treatment plans, methodRisk assessment facilitation
    Incident handlingArt. 21(2)(b) and Art. 23 reportingCould we issue an early warning within 24 hours?Runbooks, incident log, exercise reportsRunbooks, reporting templates, tabletop exercises
    Business continuityArt. 21(2)(c): backup, DR, crisis managementWhen did we last restore a critical system end to end?BCPs, restore test records, crisis plansBIA review, DR test design and observation
    Supply chainArt. 21(2)(d) and 21(3)Which suppliers could stop our essential services?Supplier inventory, assessments, contractsSupplier tiering, due diligence, contract clauses
    Vulnerability managementArt. 21(2)(e): handling and disclosureHow fast do we fix critical vulnerabilities, and can we prove it?Scan reports, patch SLAs, disclosure policyVulnerability assessment, CREST penetration testing
    Access controlArt. 21(2)(i): HR security, access, assetsAre leavers removed promptly? Are admin rights reviewed?Access reviews, JML records, asset listAccess control review, configuration assessment
    MFAArt. 21(2)(j): MFA and secured communicationsWhere is MFA not enforced, and why?MFA coverage report, exception registerMFA gap analysis and roll-out planning
    TrainingArt. 21(2)(g) and Art. 20(2)Has the board been trained? Do staff get regular awareness?Training records, content, attendanceBoard briefings, staff awareness
    Management oversightArt. 20(1): oversee implementationWhat does the board see each quarter?Board reports, KPIs, follow-up actionsBoard reporting pack, vCISO support

    Delivery

    NIS2 Services Across Ireland

    Our NIS2 services are open to organisations anywhere in Ireland: tech, data-centre and financial-services operators in Dublin, medical device and life-sciences manufacturers around Cork, Galway and Limerick, or manufacturing and logistics businesses in the south-east around Waterford.

    To be straightforward about it: VISTA Infosec doesn't have an office in Ireland. EU engagements are contracted through Zulon Audits OÜ, our EU entity in Tallinn, and delivered by our in-house team. Most NIS2 work runs remotely during Irish business hours, with on-site workshops, interviews or evidence reviews when they're genuinely useful and agreed in advance.

    Remote-first

    Workshops, interviews and evidence review over secure video and our portal.

    Irish hours

    Scheduling on Irish time, including board sessions.

    EU evidence

    Evidence can be processed and stored in the EU on request.

    On-site by agreement

    For board briefings, tabletop exercises or site walk-throughs.

    Scope by sector

    Sectors and Entities That May Be Affected

    These are the sectors named in the Directive's annexes. Being in one doesn't put you in scope automatically: what matters is the specific service you provide, your size, and whether an inclusion applies. Ireland may also add sectors when it transposes.

    Annex I: sectors of high criticality

    • Energy (electricity, district heating and cooling, oil, gas, hydrogen)
    • Transport (air, rail, water, road)
    • Banking*
    • Financial market infrastructures*
    • Health
    • Drinking water
    • Wastewater
    • Digital infrastructure
    • ICT service management (B2B)
    • Public administration
    • Space

    Annex II: other critical sectors

    • Postal and courier services
    • Waste management
    • Manufacture, production and distribution of chemicals
    • Production, processing and distribution of food
    • Manufacturing: medical devices and IVDs; computer, electronic and optical products; electrical equipment; machinery; motor vehicles; other transport equipment
    • Digital providers (online marketplaces, search engines, social networks)
    • Research organisations

    *Financial entities covered by DORA apply DORA's ICT risk-management and incident-reporting rules instead of NIS2's. Public administration scope depends on national designation.

    Why us

    Why VISTA Infosec

    Auditors, not only advisers

    Our core work for more than 21 years has been independent security and compliance audit: PCI DSS as a QSA company, plus ISO 27001 and SOC 2 engagements. We know what a tester asks for, and we build your NIS2 evidence with that in mind.

    Technical depth in-house

    CREST-accredited and CERT-In empanelled, so the technical side of Article 21, from penetration testing to configuration reviews and red-team exercises, is done by our own people, not subcontracted.

    Qualified practitioners

    Team credentials include CISSP, CISA, CRISC and ISO 27001 Lead Auditor. We're ISO 27001 certified ourselves, so we run the same kind of management system we assess.

    Honest about limits

    No Irish office, no NIS2 certificate, no guarantees about a regulator's view. What you get is a clear method, documented evidence and advice you can check against the law.

    Start with a scoping call

    A short call to talk through your services, size and current controls. We'll tell you honestly whether you need us.

    Commercials

    NIS2 Consultancy and Audit Cost

    We don't publish a price list, because a 60-person MSP and a multi-site manufacturer need very different amounts of work. After a short scoping call and questionnaire, we give you a fixed fee for a defined scope, with timelines, before any work starts.

    Most organisations start with a gap assessment, which is the smallest commitment and tells you how much implementation work there actually is.

    Request a NIS2 Assessment

    What drives the scope

    • Organisation size and entity type
    • Number of locations and business units
    • Technology environment (cloud, on-premise, OT)
    • Current security maturity
    • Existing ISO 27001, CyFun or SOC 2 work
    • Number of critical suppliers
    • State of policies and documentation
    • Assessment scope and sampling
    • Technical testing required
    • Depth of implementation support and remediation effort

    Beyond the template

    Why a Generic NIS2 Checklist May Not Be Enough

    Checklists are a good start. We publish one. But two organisations can tick the same box and be in very different positions: one has an incident plan that has been exercised, the other has a document written for an ISO audit three years ago.

    NIS2 is proportionate by design, so what counts as appropriate depends on your entity type, sector, size, services, jurisdiction, technology, existing controls, suppliers and risk exposure. A checklist can't weigh those. An evidence-based assessment can, and it gives you something a checklist never will: proof.

    Generic checklistEvidence-based assessment
    "Do you have an incident response plan?"Was it tested, when, who was involved, and what changed afterwards?
    "Is MFA enabled?"Where is it not enforced, who approved the exceptions, and are they reviewed?
    "Do you assess suppliers?"Which suppliers are critical, and what evidence did you get from them?
    Same questions for everyoneScoped to your classification, services and risk

    FAQ

    NIS2 Compliance in Ireland: Frequently Asked Questions

    What is NIS2?

    NIS2 is Directive (EU) 2022/2555, the EU law setting cybersecurity risk-management, incident-reporting and governance obligations for organisations in critical sectors. It replaced the 2016 NIS Directive, covers far more sectors, and applies once each Member State transposes it into national law.

    Has Ireland implemented NIS2 yet?

    Not yet. As at 23 September 2026, the National Cyber Security Bill that will transpose NIS2 has not been enacted. The Government published the General Scheme in August 2024 and lists the Bill for priority publication in its Autumn 2026 Legislation Programme. In July 2026 the European Commission referred Ireland to the Court of Justice of the EU for failing to notify transposition. Until the Bill is enacted, the existing NIS1 regulations continue to apply to designated operators of essential services.

    Do we need to register for NIS2 in Ireland now?

    No. The NCSC has said its NIS2 registration and incident reporting portals will only go live once the legislation is in place, and there is currently no requirement to register. Many organisations are using the time to confirm scope and classification so registration is quick when it opens.

    Does NIS2 apply to my company?

    It depends on the services you provide, your size and where you are established, not just your industry. Most entities in Annex I or II sectors are in scope only if they are at least medium-sized (50 or more staff, or turnover and balance sheet above €10 million), but some, such as DNS providers, trust service providers and public electronic communications providers, can be in scope regardless of size. The NCSC expects organisations to make the determination themselves, with legal advice where needed.

    What is the difference between an essential and an important entity?

    Both must meet the same risk-management, incident-reporting and management-body obligations. Essential entities, generally large organisations in Annex I sectors plus certain specific types, are supervised proactively and face higher maximum fines. Important entities are supervised reactively, typically when there is evidence of non-compliance, with lower maximum fines.

    Who will supervise NIS2 in Ireland?

    Under the proposals in the General Scheme, the National Cyber Security Centre will be the lead competent authority and national CSIRT, supervising most sectors, while sector regulators such as ComReg, the Central Bank of Ireland, the Irish Aviation Authority and the Commission for Railway Regulation take their own sectors. The final allocation will be set by the enacted Act.

    What does a NIS2 compliance consultant do?

    A NIS2 compliance consultant helps you confirm scope and classification, compares your current controls with NIS2 requirements, and supports you in closing the gaps: policies, incident processes, supplier security, board training and evidence. At VISTA Infosec the same in-house team can later carry out an independent audit, with the audit scope agreed separately.

    What is the difference between a NIS2 gap assessment and a NIS2 audit?

    A gap assessment is diagnostic: it maps requirements to your current position and produces a gap register and remediation roadmap. An audit is later and more formal: it tests whether measures were designed properly and operated effectively over a period, and records the evidence behind each conclusion.

    Can an organisation become NIS2 certified?

    There is no general NIS2 certification. Compliance is determined by the competent authority. In Ireland the NCSC recommends the Cyber Fundamentals (CyFun) framework, and certification against it will be optional once a national scheme is established; ISO/IEC 27001 certification is also recognised as a way to organise controls. Neither is a statutory presumption of NIS2 compliance.

    What are the NIS2 incident reporting deadlines?

    For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, intermediate reports on request, and a final report within one month of the incident notification. In Ireland the dedicated NIS2 reporting portal will open once the Bill is enacted.

    How much does NIS2 compliance consultancy cost?

    It depends on your size, classification, locations, technology, current maturity and how much implementation support you want. VISTA Infosec agrees a fixed fee for a defined scope after a short scoping call and questionnaire. A gap assessment is usually the smallest first step.

    Can VISTA Infosec support organisations in Dublin, Cork, Galway, Limerick and Waterford?

    Yes. We support organisations across Ireland, mostly remotely during Irish business hours, with on-site sessions by agreement. VISTA Infosec does not have an Irish office; EU engagements are contracted through our EU entity, Zulon Audits OÜ.

    Expert Auditors. Faster Certification.

     

    European Operations
    European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
    Visit Zulon Audits →