What to tell a client with an Irish entity about NIS2
Ireland has not transposed NIS2, so there are no national duties yet — what is live instead, what to do meanwhile, and what not to put in a memo.
20 September 2026

The question you actually get asked
An ops director emails: our Dublin entity is in one of the NIS2 sectors, the group is well over the size test, are we in scope and what do we do. The accurate answer is an awkward one to give — as things stand, Ireland has not put NIS2 into national law, so there is no Irish NIS2 obligation to be in scope of. The direction is settled; the dates are not.
That gap is where the work is. A client who hears "not yet" and files it usually hears nothing again until a commencement order lands with a registration window measured in weeks.
Every country-level statement below comes from our national NIS2 profile data, which was checked against primary sources on 17 September 2026. Transposition status is the single most perishable field in that file. Re-check the source before any of it goes into a client deliverable.
What the Irish profile holds, blanks included
The Irish entry is mostly empty, and the emptiness is the finding.
| Field | Ireland |
|---|---|
| Law | National Cyber Security Bill (not enacted) |
| Status | Pending |
| In force | Not confirmed |
| Competent authority | National Cyber Security Centre (NCSC), proposed |
| Early warning | Not confirmed |
| Full notification | Not confirmed |
| Final report | Not confirmed |
| Registration required | Not confirmed |
| Registration deadline | Not confirmed |
| Registration portal | Not confirmed — not live |
| Size thresholds | No national deviation recorded |
Read the nulls precisely. "Not confirmed" is not "no duty" and it is not "24 hours, same as everyone else". It means the national text that would set the number does not exist yet in enacted form, so there is nothing to cite. Filling those cells from another member state's law, or from the directive's own numbers, produces a memo that looks authoritative and is not.
Three things are confirmed. The Irish NCSC states that registration and reporting portals open once the law is in place. NIS1 still applies to existing operators of essential services. And on 8 July 2026 the Commission referred Ireland to the Court of Justice for failing to transpose the rules.
Two things are true at once
The first: your client has no Irish NIS2 registration duty, no Irish 24-hour early warning duty, and no Irish authority to notify under NIS2 today, because none of those exist in Irish law. If a vendor questionnaire asks whether the Irish entity is registered under NIS2, the honest answer is that Irish registration is not yet available.
The second: the transposition deadline passed in October 2024, the Bill is drafted, the proposed authority has published what it intends to do, and the Commission has taken Ireland to the Court of Justice. Advising a client to wait for the commencement order is advising them to do a scoping exercise, an asset inventory and an incident-reporting procedure under time pressure.
What is actually live: NIS1
The part most often dropped from the memo. NIS1 still applies to existing operators of essential services in Ireland. If your client was an OES under the earlier regime, it has current obligations under that regime — not suspended, not in transition, just in force. A client that converted its NIS1 paperwork into an unfinished NIS2 project and let the former lapse has gone backwards.
So the first question for an Irish entity is not "are we in scope of NIS2" but "were we an OES under NIS1, and is that file current". Those are different clients with different answers.
The spread, so the client sees why one answer will not do
Ireland is one end of a range. Three other entries in the same profile set show the rest of it.
| Country | Law | Status | Registration deadline in the national text |
|---|---|---|---|
| IE | National Cyber Security Bill | Not enacted | Not confirmed |
| BE | Law of 26 April 2024 and Royal Decree of 9 June 2024 | In force 18 October 2024 | By 18 March 2025 or within 5 months of identification (art. 13); digital infrastructure and digital providers by 18 December 2024 (art. 14) |
| DE | NIS2UmsuCG, BSIG 2025 | In force 6 December 2025 | Within 3 months of first qualifying; changes within 2 weeks (§33 BSIG) |
| AT | NISG 2026 (BGBl. I Nr. 94/2025) | Adopted, applies from 1 October 2026 | Within 3 months of entry into force, by 1 January 2027; later entrants within 3 months (§29(3)) |
Belgium has had a live registration duty and a live portal for well over a year, with an earlier fixed date for digital infrastructure and digital providers than for everyone else. Germany's duty runs from the moment an entity first qualifies, so it has no single calendar date at all. Austria is the instructive middle case for an Irish conversation: the law is adopted with a known application date, NISG 2018 governs until then, and the registration deadline is already fixed at 1 January 2027. Adopted-but-not-applying gives a client something to plan against. Ireland does not have that yet.
The practical consequence for a group operating in several of these states: NIS2 status is an entity-and-country attribute, never a group-level one.
What to do in the meantime
None of this depends on the Irish text, which is why it is safe to do now.
Fix the scoping inputs, not the conclusion. Sector, headcount, turnover, and the group structure that determines whether partner and linked enterprise figures roll up. The directive's default size test is the Recommendation 2003/361/EC size-cap rule, and no national deviation is recorded for Ireland. Collect the numbers per entity per country; the classification itself waits for the statute.
Do the work that is identical in every transposition. Risk-management measures, access control and multi-factor authentication, cryptography, supply-chain requirements for critical ICT vendors, business continuity and crisis management, and an asset register naming actual suppliers. A client who has it will register and carry on; a client who does not will spend the registration window writing policies.
Build the incident procedure with the authority and clocks left as gaps. Who detects, who decides it is reportable, who is authorised to notify, what goes in the first message, how the record is kept — all jurisdiction-independent. Leave the authority, the channel and the deadlines as explicit unfilled slots, marked unconfirmed pending transposition. That is a far better deliverable than a procedure quietly populated with German numbers.
Get management to approve the measures, on the record. The directive puts responsibility for approving risk-management measures on management bodies. That sign-off is easier to obtain before there is a deadline than after.
Watch the Bill, and tell the client you are watching it. Put a review date in the file. The single fact that changes everything — enactment and commencement — is one line of news.
What not to claim
- Do not state an Irish early-warning, notification or final-report deadline. There is none to state, and the directive's own figures are not Irish law.
- Do not tell a client they can register in Ireland. The portals are not live.
- Do not name an Irish competent authority as though it were appointed under NIS2. The NCSC is the proposed authority.
- Do not describe the Irish entity as "compliant with NIS2". There is nothing national to comply with, and claiming compliance against a regime that does not exist is the kind of sentence a corporate customer's counsel will find.
- Do not assume Ireland will copy any neighbour's numbers. Belgium, Germany and Austria run three different registration clocks from three different trigger events.
- Do not let the NIS1 file lapse while the NIS2 project waits.
A last point of method. Entity class under NIS2 is a legal qualification with supervisory consequences, and it belongs to the consultant who signs the file, not to a tool and not to the client's IT lead. Clausebench prepares the documentation required by the regime and keeps the national profile in one place; for Ireland it proposes nothing, because there is nothing to propose.
Facts in this post were checked on 17 September 2026 against the sources linked above. Check them again before you rely on them.