Does NIS2 apply to my Irish business, and what does it require?

NIS2 is not yet Irish law, and Ireland was referred to the Court of Justice in July 2026 for that. Here is who it covers, what it requires, and why the businesses it does not cover are still being asked to answer for it.

An empty boardroom table with three closed folders, a pair of reading glasses and a conference phone at one end.

In short

NIS2 is not yet transposed in Ireland: the Commission referred Ireland to the Court of Justice on 8 July 2026, and the Government expects to notify transposition by the end of 2026. You are in scope if you operate in one of 18 listed sectors and employ 50 or more people, or turn over more than 10 million euro. Most Irish SMEs that ask about NIS2 are not in scope directly; they are pulled in by customer security questionnaires, because Article 21 makes an in-scope company responsible for its suppliers. The work is the same either way: written policies, MFA, tested backups, patching with evidence, a supplier assessment, and an incident contact sheet that answers the 24-hour reporting clock.

NIS2 is not yet Irish law. The deadline to transpose it was 17 October 2024, Ireland missed it, and on 8 July 2026 the European Commission referred Ireland to the Court of Justice along with Spain, France and the Netherlands, asking the Court for a lump sum and daily penalties until transposition is notified. The vehicle is the National Cyber Security Bill 2024, and the Government has signalled it expects to notify transposition by the end of 2026.

That gap is the thing most Irish businesses have misread. Waiting for the Bill sounds prudent and is not, for two reasons. Your customers are already asking. And the work NIS2 asks for takes longer than the notice period you will get.

This guide covers who is in scope, what the Directive requires, what changes on the day the Bill is enacted, and what is worth doing in the next 90 days. It is vendor-neutral. Where Panoptic does the work, it says so.

Does NIS2 apply to your business?

Two tests, and you need both. Sector, then size.

Sector. NIS2 lists 18 sectors across two annexes. Annex I covers energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II covers postal and courier services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, computers, electronics, machinery and motor vehicles), digital providers such as online marketplaces and search engines, and research organisations. The NCSC publishes the sector list as a reference sheet.

Size. Micro and small businesses, meaning under 50 staff and under €10m turnover, are generally out of scope. Medium businesses, meaning under 250 staff and under €50m turnover, are in scope as important entities. Large businesses, meaning 250 staff or more, or turnover above €50m with a balance sheet above €43m, are essential entities if they operate in an Annex I sector and important entities if they operate in an Annex II sector.

The two classes face the same security obligations. They differ in supervision. Essential entities can be audited proactively; important entities are supervised after something goes wrong. The maximum administrative fines differ too: up to €10m or 2% of worldwide turnover for essential entities, up to €7m or 1.4% for important entities, whichever is higher.

There are exceptions that pull small businesses in regardless of headcount, including sole providers of a service critical to a sector, and certain DNS, TLD and trust service providers. The NCSC covers these in its entities reference sheet.

The supply-chain route, which catches everyone else

Most of the Irish businesses that contact us about NIS2 are not in scope. They are in the supply chain of someone who is.

Article 21 requires in-scope entities to manage the security risk in their direct suppliers and service providers. In practice that becomes a questionnaire. A manufacturer in scope sends its 40-page security questionnaire to the 200 businesses it buys from, and the questionnaire does not check whether you are in scope. It checks whether you have MFA, whether you patch, whether you can produce a backup restore test, and whether you have someone to call at 3 a.m.

If you supply anyone in the 18 sectors, the practical answer to "does NIS2 apply to me" is yes, through the contract rather than the statute. That is already happening. It does not wait for the Bill.

What NIS2 asks for

Article 21(2) lists ten categories of risk-management measure. They are deliberately outcome-shaped rather than product-shaped, so no vendor can claim a box ticks itself.

  1. Risk analysis and information system security policies.
  2. Incident handling.
  3. Business continuity, including backup management, disaster recovery and crisis management.
  4. Supply chain security, covering the relationships with your direct suppliers.
  5. Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure.
  6. Policies to assess whether the risk-management measures work in practice.
  7. Basic cyber hygiene and cybersecurity training.
  8. Policies on cryptography and encryption.
  9. Human resources security, access control and asset management.
  10. Multi-factor authentication, secured communications, and secured emergency communications.

Read as a list, that is intimidating. Read as a description of a well-run IT environment, it is mostly things a competent managed IT provider already does, plus three that usually need deliberate work: the written policies, the evidence that the controls are effective, and the supply-chain assessment of your own suppliers.

The measures must be proportionate to your size and risk. A 30-person food producer is not expected to build what a bank builds. It is expected to have decided, in writing, what it does and why.

Incident reporting is where the clock is tightest

Article 23 sets a three-stage reporting sequence for a significant incident:

  • An early warning within 24 hours of becoming aware of it.
  • A fuller incident notification within 72 hours, with an initial assessment of severity and impact.
  • A final report within one month.

Twenty-four hours is not long if the first question in the room is who to phone. The single cheapest piece of NIS2 preparation is a one-page incident contact sheet, agreed in advance, that answers who declares an incident, who notifies, and who talks to customers.

What changes when the Bill is enacted

Three things, on current signals.

Registration. In-scope entities will self-register through a single national platform the NCSC will provide, giving sector, sub-sector, name, address and current contact details. Registration is how the regulator learns you exist, and it is the step with a hard date attached.

Supervision. Sectoral regulators become the competent authorities for their sectors. The NCSC handles large-scale incidents and crises and gets a statutory footing.

Management accountability. NIS2 puts approval of the risk-management measures on management bodies and requires them to be trained on it. This is the provision that moves cyber risk from an IT line item to a board minute, and it is the reason your directors should read at least this section.

Until the Bill is enacted, Ireland remains in a transitional phase in which the earlier NIS 1 framework continues to apply. NIS 1 obligations have not gone away for the entities that already had them.

CyFun: the framework the NCSC points to

The NCSC recommends the CyberFundamentals framework, known as CyFun, as a voluntary way to organise and evidence your controls against NIS2. It is built on the NIST Cybersecurity Framework, it has three assurance levels (Basic, Important, Essential) so it scales to your size, and its self-assessment tool is free.

Two things to know. Formal Irish certification does not exist yet: the NCSC expects a national certification scheme by 2027. And CyFun is not proof of NIS2 compliance on its own, because your sectoral regulator decides what compliance means in your sector. It is the best available structure for doing the work and showing it.

We have written a separate walkthrough: CyFun explained, with the self-assessment step by step.

Sector notes

Manufacturing, food and wholesale. The most common Irish path into scope, and the one businesses least expect, because "we make packaging" does not feel like critical infrastructure. Check Annex II before you assume you are out.

Financial services and insurance. Usually in scope through Annex I, and usually already carrying DORA obligations, which are stricter and take precedence for the entities they cover. If DORA applies to you, start there. See what DORA covers.

Legal and accountancy practices. Rarely in scope directly. Almost always pulled in through client security questionnaires, and holding exactly the kind of data that makes a questionnaire fail. See IT support for accountants and solicitors.

Healthcare and dental. Annex I covers healthcare providers. Practice size usually puts a single practice below the threshold, but group practices and clinical suppliers should check carefully. See IT support for dental practices.

What to do in the next 90 days

Six steps, in order. None of them requires the Bill to be enacted first.

  1. Decide whether you are in scope, in writing, with the sector annex and the size test recorded. If you are out of scope, record why. That note is the answer to the next customer questionnaire.
  2. Run the CyFun self-assessment at the assurance level that matches your size. It takes a morning and produces a gap list.
  3. Fix the cheap gaps first. MFA everywhere, patching with reporting, encrypted backup with a tested restore, EDR on every endpoint, and security awareness training. These cover a large share of Article 21 and most of what questionnaires ask.
  4. Write the incident contact sheet. Who declares, who notifies, who calls customers, and the 24-hour clock.
  5. Assess your own suppliers. Article 21(4) makes their security your problem. Start with the ones who hold your data or have access to your systems.
  6. Put it on a board agenda and minute the decision. Management approval is an obligation, not a formality.

Related guides

Related services

Where to start

If you want the scope decision and the gap list done rather than read about, that is a NIS2 readiness assessment: we run the sector and size test, complete the CyFun self-assessment with you, and hand back a prioritised gap list with costs against each item. Offices in Cork and Kilkenny, working with SMEs across Ireland.

Book a 15-minute call

Is NIS2 law in Ireland yet?

No. The transposition deadline was 17 October 2024 and Ireland missed it. On 8 July 2026 the European Commission referred Ireland to the Court of Justice of the EU, together with Spain, France and the Netherlands, and asked the Court to impose a lump sum and daily penalties until transposition is notified. The National Cyber Security Bill 2024 is the vehicle, and the Government expects to notify transposition by the end of 2026. Until then Ireland remains in a transitional phase in which the earlier NIS 1 framework continues to apply.

Does NIS2 apply to small businesses?

Generally not directly. Businesses with fewer than 50 staff and less than 10 million euro turnover are outside the size threshold, with narrow exceptions for sole providers of a critical service and certain DNS, TLD and trust service providers. Small businesses are commonly pulled in indirectly, because Article 21 requires in-scope entities to manage the security risk in their direct suppliers. That arrives as a customer security questionnaire rather than as a legal obligation.

What is the difference between an essential and an important entity?

Sector and size. Large entities in an Annex I sector, meaning 250 staff or more or turnover above 50 million euro with a balance sheet above 43 million euro, are essential entities. Medium entities, and entities in Annex II sectors, are important entities. Both carry the same security obligations. Essential entities can be supervised proactively and face maximum fines of 10 million euro or 2 per cent of worldwide turnover; important entities are supervised after an incident and face 7 million euro or 1.4 per cent.

How quickly do you have to report an incident under NIS2?

Article 23 sets three stages. An early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours including an initial severity and impact assessment, and a final report within one month. The 24-hour stage is the one businesses fail, because it is short enough that the decision about who declares an incident has to be made in advance.

Does CyFun certification make you NIS2 compliant?

No, and the NCSC is explicit about this. CyFun is a voluntary framework the NCSC recommends for organising and evidencing your controls, built on the NIST Cybersecurity Framework, with Basic, Important and Essential assurance levels. Your sectoral competent authority decides what compliance means in your sector. Formal Irish certification does not exist yet either: the NCSC expects a national certification scheme by 2027. The self-assessment tool is free and is the best available starting point.

What should an Irish SME do about NIS2 right now?

Six things, none of which need the Bill. Decide in writing whether you are in scope and record the reasoning. Run the free CyFun self-assessment at the level that matches your size. Close the cheap gaps first: MFA everywhere, patching with reporting, encrypted backup with a tested restore, EDR on every endpoint, and awareness training. Write a one-page incident contact sheet for the 24-hour clock. Assess the suppliers who hold your data or reach your systems. Put the result on a board agenda, because management approval of the measures is itself an obligation.

All guides

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.