Léim ar aghaidh chuig an bpríomhábhar
Gnáthamharc

EU Directives

Dáil Éireann Debate, Wednesday - 1 October 2025

Wednesday, 1 October 2025

Ceisteanna (115)

Barry Ward

Ceist:

115. Deputy Barry Ward asked the Minister for Justice, Home Affairs and Migration the measures currently in place to comply with Ireland's obligations under the network and information security directive (NIS2 Directive) (EU) 2022/2555; and if he will make a statement on the matter. [52591/25]

Amharc ar fhreagra

Freagraí scríofa

The NIS2 Directive entered into force in January 2023 and the enactment of the National Cyber Security Bill, which is the legislative vehicle transposing the NIS2 Directive is a priority for my Department.

My Department is currently engaging with the Office of Parliamentary Council, the Attorney General’s Office, the National Cyber Security Centre (NCSC) and other relevant Government Departments and Agencies on the drafting of the Bill, which is at an advanced stage.

The NIS2 Directive is a revision of the Network and Information Security Directive (EU) 2016/1148 (NIS Directive), which is currently in force in the State via S.I. 360 of 2018. Until the NIS2 Directive is transposed and enacted, the NIS Directive will remain in full effect, covering the most critical operators of essential services and digital service providers in the State.

In anticipation of having the legislation in place and to ensure that Ireland is ready to implement the directive on the day of enactment of the Bill, we have taken significant steps to ensure various implementing measures are in place. This includes a robust approach to sectoral regulation for the Directive and the designation of nine National Competent Authorities (NCA) to carry out enforcement and supervision of the Directive. The NCSC has been designated as the lead NCA for the Directive and will offer guidance and support to the other competent authorities while they prepare to take on their new functions under the Bill.

To that end, a National Competent Authority Forum, led by the NCSC, has been stood up which allows NCAs to meet on a regular basis to discuss important issues about the implementation of the Directive. The NCSC has also published guidance documents on the implementation of the Directive including a tool to allow companies determine whether they will come into scope of the Directive.

Additionally work is ongoing in my Department on the preparation of Ireland's third National Cyber Security Strategy which fulfils another requirement under the Directive.

Roinn