# NIS2 Requirements in Ireland: What to Install and Run

> NIS2 requirements in Ireland mapped to the ten Article 21 measures: what an IT provider deploys against each, and the evidence a regulator asks for.

*Source: https://panoptic.ie/guides/nis2-requirements-ireland*

# NIS2 in Ireland: what to install and run

The ten Article 21 measures, what we deploy against each, and the evidence a regulator asks for. The deployment view, for a business of 20 to 250 staff.

[David Griffith](https://panoptic.ie/about#david-griffith), Managing Director · 22 September 2026

![Ten security measure icons in boxes labeled Risk, Incident handling, Backup, Supply chain, Patching, Effectiveness, Training, Encryption, Access control, and MFA on a dark background with text and cost information.](https://panoptic.ie/_astro/blog_nis2_requirements_ireland_61aa4a58a7_1s1zT2.png)

In short

NIS2 sets ten security measures under Article 21(2). This guide maps each one to the control an IT provider switches on (multi-factor authentication, managed endpoint protection, tested backups, logging, patching, access control) and to the evidence an auditor asks for. Ireland has not transposed NIS2 yet; the obligations already arrive through customer contracts and the NCSC's guidance.

This page is the deployment view of NIS2: the controls an IT provider switches on for each of the ten Article 21(2) measures, and the evidence a regulator or auditor asks for. It's written for a business with 20 to 250 staff working out what to buy. For [whether NIS2 applies to you](https://panoptic.ie/guides/nis2-compliance-ireland), or for the legal detail, see [the NCSC's NIS2 page](https://www.ncsc.gov.ie/nis2/).

## What is NIS2?

NIS2 is the EU's second Network and Information Security Directive, formally Directive (EU) 2022/2555. It replaces the original NIS Directive and applies from 18 October 2024, and each EU member state transposes it into its own national law. It sets minimum cybersecurity requirements for medium and large organizations in specified sectors, and it reaches smaller suppliers to those organizations through contract requirements, even where the supplier isn't in scope itself.

### Where Ireland stands on NIS2 compliance

Ireland hasn't transposed NIS2 into national law. The transposition deadline was October 17, 2024, and Ireland missed it. On July 8, 2026, the European Commission referred Ireland, along with Spain and France, to the Court of Justice of the EU for incomplete transposition ([IAPP](https://iapp.org/news/a/nis2-and-ireland-s-national-cyber-security-bill-what-management-boards-must-know-and-do), [Inside Privacy](https://www.insideprivacy.com/uncategorized/irish-ncsc-issues-cyber-governance-guidance-for-management-boards-ahead-of-nis2-implementation/)).

The transposing law is the National Cyber Security Bill 2024.. The NCSC published guidance for management boards on July 7, 2026, ahead of the Bill's enactment, and stated that NIS2 accountability sits with the highest level of executive management ([gov.ie](https://www.gov.ie/en/department-of-justice-home-affairs-and-migration/press-releases/ncsc-launches-cyber-governance-guidance-for-management-boards-in-nis2-organisations/)). The Government's own timeline points to enactment by the end of 2026, but no date is confirmed.

Ireland has no domestic NIS2 enforcement yet, but the NCSC is setting expectations that carry into how regulators and customer contracts read the directive. A large customer's security questionnaire references Article 21 today, regardless of the Bill's status.

### Essential entities and important entities

NIS2 sorts in-scope organizations into two tiers. Both tiers must meet the same ten security measures in Article 21(2). What differs is supervision and the maximum fine.

An important entity is typically a medium-sized organization: 50 to 250 staff, or turnover between €10 million and €50 million, in a sector listed in Annex I or Annex II. Sectoral regulators supervise important entities reactively, after an incident or a complaint.

An essential entity is typically larger: 250 or more staff, or turnover above €50 million with a balance sheet above €43 million, in an Annex I sector. Regulators supervise essential entities proactively, with scheduled audits ahead of any incident.

Annex I (the higher-criticality sectors) covers energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, ICT service management, public administration, and space. Annex II covers postal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers, and research organizations.

### The fines

The Directive sets ceilings of up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities (Article 34). Ireland's transposing law sets the figures that apply here, and the Bill has not been enacted, so treat these as the upper bound.

## NIS2 requirements checklist: the ten Article 21(2) measures

Article 21(2) requires in-scope entities to take "appropriate and proportionate technical, operational and organisational measures" across ten areas. The Directive is outcome-shaped: it states the outcome to reach and leaves the method to you. Use the table as a quick reference, then read each section for what we deploy and what an auditor asks for.

| Measure                                       | What we deploy                                                     | In place? |
| --------------------------------------------- | ------------------------------------------------------------------ | --------- |
| 1. Risk analysis and security policy          | Asset and risk register, reviewed quarterly                        | ☐         |
| 2. Incident handling, logging, and monitoring | EDR, alerting, and a written incident response plan                | ☐         |
| 3. Business continuity and backup             | Image-based backup, cloud failover, and tested restores            | ☐         |
| 4. Supply chain security                      | Scored, reviewed supplier list                                     | ☐         |
| 5. Patching and vulnerability handling        | Patch management with reporting, scanning, and penetration testing | ☐         |
| 6. Measuring effectiveness                    | Quarterly review of every measure                                  | ☐         |
| 7. Staff training and cyber hygiene           | Phishing simulation and security awareness training                | ☐         |
| 8. Encryption                                 | Encryption policy, applied to backups, devices, and mail           | ☐         |
| 9. Access control and asset management        | Role-based permissions, asset inventory, and offboarding           | ☐         |
| 10. Multi-factor authentication (MFA)         | MFA enforced across accounts, plus dark web monitoring             | ☐         |

### 1. Risk analysis and security policy

**The obligation.** A documented process for identifying risks to your systems, and a written security policy those risks feed into.

**What we deploy.** An asset and risk register, reviewed quarterly through the Technology Success Program with a named advisor.

**What an auditor asks for.** The register, the date of the last review, and evidence the policy changed in response to a finding.

### 2. Incident handling, logging, and monitoring

**The obligation.** A process to detect, respond to, and report significant incidents, including a way to hit the Article 23 reporting deadlines.

**What we deploy.** Endpoint detection and response (EDR) across your devices, with logging and alerting that reaches a person, and a written incident response plan with named roles.

**What an auditor asks for.** The incident response plan, a log of past incidents, and proof the plan has been tested.

### 3. Business continuity, including backup and disaster recovery

**The obligation.** The ability to keep operating, or restore operations, after a disruptive incident, including backup management and crisis planning.

**What we deploy.** Image-based backup with cloud failover, and a restore we test on a fixed schedule.

**What an auditor asks for.** A restore test log with dates and outcomes. A backup that has never been restored isn't evidence of anything.

### 4. Supply chain security

**The obligation.** A process to assess and manage cybersecurity risk in your direct suppliers and service providers, including your IT provider.

**What we deploy.** A supplier list scored by data access and system reach, reviewed at onboarding and kept current.

**What an auditor asks for.** The supplier list, the scoring method, and evidence you followed up on a supplier that scored poorly.

### 5. Patching and vulnerability handling

**The obligation.** Security built into how you buy, build, and patch systems, plus a process for handling disclosed vulnerabilities.

**What we deploy.** Patch management with reporting, vulnerability scanning, and, where scoped, penetration testing with a ranked remediation list.

**What an auditor asks for.** Patch compliance reports and the most recent scan or test results, with the remediation items closed.

### 6. Measuring the effectiveness of your security

**The obligation.** A periodic check that each security measure works as intended. Installation is not evidence.

**What we deploy.** Quarterly reviews of the measures above, on the same Technology Success Program cadence.

**What an auditor asks for.** The review record and any changes it produced.

### 7. Staff training and cyber hygiene

**The obligation.** Basic hygiene practices and staff training, because most incidents start with a person.

**What we deploy.** Phishing simulation followed by security awareness training, run on a recurring basis so it stays current for new starters.

**What an auditor asks for.** Simulation results over time and training completion records by staff member.

### 8. Encryption

**The obligation.** A policy on when and how you use encryption, appropriate to the data you hold.

**What we deploy.** Encrypted backups as standard, and encryption settings reviewed as part of Microsoft 365 hardening.

**What an auditor asks for.** The encryption policy document and configuration evidence, for example which drives and mail flows are encrypted, and since when.

### 9. Access control and asset management

**The obligation.** Control over who can access what, managed through the employment lifecycle, and a known inventory of assets.

**What we deploy.** Role-based permissions in Microsoft 365, an asset inventory kept current through managed IT, and an offboarding checklist so access is removed the day someone leaves.

**What an auditor asks for.** The asset inventory, the access control list, and an offboarding record for a recent leaver.

### 10. Multi-factor authentication (MFA) and secured communications

**The obligation.** Multi-factor authentication where appropriate, and secure options for voice, video, text, and emergency communication.

**What we deploy.** MFA enforced across Microsoft 365, sign-in rules that block risky logins, and dark web monitoring that alerts you when a staff email address turns up in a breach database.

**What an auditor asks for.** MFA coverage reports and sign-in logs showing enforcement.

## Incident reporting: the 24-hour and 72-hour clock

If you're an essential or important entity, Article 23 sets a three-stage reporting sequence for a significant incident.

You must send an early warning within 24 hours of becoming aware of the incident. You must follow with a fuller notification within 72 hours, including your severity and impact assessment. You must submit a final report within one month.

The 24-hour early warning is the tightest constraint most businesses underestimate. It requires an incident contact sheet prepared in advance. We build that sheet as part of onboarding.

## What changes once the Bill is enacted

Once the National Cyber Security Bill is law, in-scope entities register with the NCSC through a self-registration platform, giving sector, name, address, and contact details. Sectoral regulators become the day-to-day competent authorities for supervision; the NCSC leads on large-scale, cross-sector incidents. Approval of your risk-management measures becomes a management body responsibility, with required training for management.

## CyFun: the tool NIS2 doesn't name

The NCSC recommends CyberFundamentals (CyFun), the Belgian Centre for Cybersecurity's (CCB) framework, as the practical way to organize and evidence your controls against NIS2. CyFun isn't mandatory and isn't proof of NIS2 compliance on its own, because your sectoral regulator decides what compliance means in your sector. Ireland plans to base its national certification scheme on CyFun, with certification expected by 2027, though that date hasn't been confirmed. Read our full explanation in the [NIS2 compliance guide for Irish SMEs](https://panoptic.ie/guides/nis2-compliance-ireland) and the refreshed [CyFun guide for Irish SMEs](https://panoptic.ie/blog/cyfun-nis2-compliance-guide-irish-smes).

## Where to go next

Read [does NIS2 apply to my business](https://panoptic.ie/guides/nis2-compliance-ireland) if you haven't confirmed your scope, or use the NCSC's [Am I in scope tool](https://www.ncsc.gov.ie/nis2/amiinscope/) directly. Read the full [NIS2 compliance guide for Irish SMEs](https://panoptic.ie/guides/nis2-compliance-ireland) for the longer walkthrough, including the 90-day action plan. Read the refreshed [CyFun guide](https://panoptic.ie/blog/cyfun-nis2-compliance-guide-irish-smes) for how the self-assessment works. Or contact us for a NIS2 readiness assessment: we determine your scope, complete your CyFun self-assessment, and hand you a prioritized gap list with costs.

## Sources

- [NCSC: NIS2](https://www.ncsc.gov.ie/nis2/)
- [NCSC: Am I in scope?](https://www.ncsc.gov.ie/nis2/amiinscope/)
- [NIS2 and Ireland's National Cyber Security Bill: what management boards must know and do, IAPP](https://iapp.org/news/a/nis2-and-ireland-s-national-cyber-security-bill-what-management-boards-must-know-and-do)
- [Irish NCSC issues cyber governance guidance for management boards ahead of NIS2 implementation, Inside Privacy](https://www.insideprivacy.com/uncategorized/irish-ncsc-issues-cyber-governance-guidance-for-management-boards-ahead-of-nis2-implementation/)
- [NCSC launches cyber governance guidance for management boards in NIS2 organisations, gov.ie](https://www.gov.ie/en/department-of-justice-home-affairs-and-migration/press-releases/ncsc-launches-cyber-governance-guidance-for-management-boards-in-nis2-organisations/)
- [NIS2, Ireland's risk management measures and Cy-Fun, Mason Hayes & Curran](https://www.mhc.ie/latest/insights/nis2-irelands-risk-management-measures-and-cy-fun)
- [NCSC: CyFun, ncsc.gov.ie](https://www.ncsc.gov.ie/CyFun/)
- [CyFun 2025 is here, CCB Belgium](https://ccb.belgium.be/news/cyfunr-2025-here)
- [NIS2 Article 21: cybersecurity risk-management measures, nis-2-directive.com](https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html)
- [NIS2 Directive: compliance guide, fines and scope, Codific](https://codific.com/nis-2-directive-compliance-guide-fines-scope/)
- Panoptic internal: existing [NIS2 compliance guide](https://panoptic.ie/guides/nis2-compliance-ireland.md) and [cyber security services](https://panoptic.ie/services/cyber-security.md)

What are the NIS2 requirements?

Ten security measures under Article 21(2): risk analysis and policy, incident handling, business continuity and backup, supply chain security, patching and vulnerability handling, measuring effectiveness, staff training, encryption, access control and asset management, and MFA. See the checklist above.

Who needs to be NIS2 compliant?

An organization with 50 or more staff, or turnover above €10 million, in a sector listed in Annex I or Annex II. Smaller businesses can still be required to meet the same measures through a customer's contract. See [does NIS2 apply to my business](https://panoptic.ie/nis2/does-it-apply-to-my-business).

Has Ireland implemented NIS2?

Not yet. Ireland missed the October 17, 2024 transposition deadline, and the National Cyber Security Bill 2024 hasn't been enacted. The European Commission referred Ireland to the Court of Justice of the EU on July 8, 2026 for the delay.

What are the required elements for NIS2 incident reports?

An early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification within 72 hours that includes your severity and impact assessment. A final report follows within one month.

What does NIS2 stand for?

The second Network and Information Security Directive, formally Directive (EU) 2022/2555. It replaces the original NIS Directive and sets minimum cybersecurity requirements across the EU.

Is NIS2 a European directive?

Yes. NIS2 is EU law, adopted in December 2022, that each member state transposes into its own national legislation.

What is CyFun?

CyberFundamentals, a free framework from Belgium's Centre for Cybersecurity that the NCSC recommends for organizing and evidencing your controls against NIS2. It isn't proof of compliance on its own. Read the full [CyFun guide](https://panoptic.ie/blog/cyfun-nis2-compliance-guide-irish-smes).

[All guides](https://panoptic.ie/guides)

## Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.

[Talk to us ](https://panoptic.ie/contact)[See how we onboard](https://panoptic.ie/how-we-onboard)
