Skip to main content
Normal View

Cybersecurity Policy

Dáil Éireann Debate, Wednesday - 11 February 2026

Wednesday, 11 February 2026

Questions (218)

Emer Currie

Question:

218. Deputy Emer Currie asked the Minister for Justice, Home Affairs and Migration for an update on Ireland's position on the European Commission's recently published proposals for a new EU Cyber Security Act. [10528/26]

View answer

Written answers

The revised Cybersecurity Act, known as the Cybersecurity Act 2 (CSA2), was published on 20 January 2026. The aim of the proposal is fourfold:

A full reform of the mandate of the European Union Agency for Cybersecurity (ENISA), emphasising its key role in providing effective support for policy implementation and added value in terms of supporting operational cooperation among Member States.

A reformed European cybersecurity certification framework (ECCF), with the aim of delivering a more effective and efficient tool that both promotes trust among businesses, the general public and public authorities and eases compliance with relevant Union legislation.

The creation of a harmonised framework to tackle non-technical risks affecting ICT supply chains, reducing the current fragmentation of approaches across Member States.

Targeted amendments to the NIS2 Directive with the aim of simplifying compliance with and ensuring streamlined and coherent implementation of specific aspects of the cyber security framework, including with regard to scope, definitions, ransomware reporting and supervision of entities providing cross-border services.

My Department’s initial view is to welcome the CSA2, although the text will require more detailed scrutiny. At a high level, the proposal contains a number of positive developments for Ireland. ENISA provides support for policy implementation and supports operational cooperation among Member States. As a smaller Member State, Ireland will benefit from the CSA2’s particular emphasis on these functions as the core parts of ENISA’s mandate. The reform of the ECCF will better enable the harmonisation of the recognition of the level of cyber security of ICT solutions across the Union, allowing Irish vendors and service providers to reach more customers throughout the EU. A reformed ECCF will also make it a more effective and efficient tool for the development of cyber security certification schemes that promote trust among businesses, the general public and public authorities.

A harmonised approach to the security of the ICT supply chains can address the current fragmentation of the internal market caused by different approaches at national level, avoid critical dependencies and de-risk ICT supply chains from high-risk suppliers, in this way securing critical infrastructure. The 5G Toolbox is the framework by which Ireland secures its next-generation electronic communications networks. This was a voluntary framework developed by the EU to address high-risk suppliers. However, the implementation of these frameworks by Member States has not been uniform across the EU. The measures in the CSA2 are intended to create a joint EU approach to the security of the ICT supply across Member States. Ireland gave effect to 5G toolbox via Part 3 of the Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023, for which responsibility lies with my Department.

Finally, the CSA2 builds on the work of the Digital Omnibus package for simplification. The CSA2 proposes targeted intervention through amendments to the NIS2 Directive to simplify specific aspects of the cyber security framework, including scope adaptations, maximum harmonisation for implementing acts, compliance proof through certification, and adoption of the set of guidelines to enhance legal certainty and harmonised implementation.

Ireland is expected to achieve the general approach on the file by the end of its Presidency of the EU Council in December. My Department will be leading on supporting this work and the Irish team with responsibility for chairing the negotiations during the Irish Presidency.

Share