Léim ar aghaidh chuig an bpríomhábhar
Gnáthamharc

Legislative Process

Dáil Éireann Debate, Tuesday - 17 February 2026

Tuesday, 17 February 2026

Ceisteanna (918)

Matt Carthy

Ceist:

918. Deputy Matt Carthy asked the Minister for Justice, Home Affairs and Migration if it is intended that there will be lead-in or transitional period applied before enforcement in respect of the legislative transposition of the NIS2 Directive; and if he will make a statement on the matter. [12570/26]

Amharc ar fhreagra

Freagraí scríofa

The NIS2 Directive came into force on January 16 2023 and EU Member States had until October 17 2024 to adopt and publish measures to transpose it in to national law. As this period has now passed, the National Cyber Security Bill which is the legislative vehicle for the transposition of the NIS2 Directive, cannot provide for a further period of time for transposition of the Directive.

In anticipation of having the legislation enacted, significant steps have already been taken including:

• The designation of nine National Competent Authorities (“NCA”) to carry out enforcement and supervision of the NIS2 Directive.

• The establishment of a National Competent Authority Forum (“NCA Forum”) which forms part of the central approach to ensure a consistent regulatory approach to the implementation of the NIS2 Directive.

• The launch of the “Am I in Scope” tool on the dedicated NIS2 part of the National Cyber Security Centre’s website. This tool is designed to assist entities in determining if they are in scope for regulation under NIS2 so they can take measures to prepare for the forthcoming legislation.

• The publication of the NIS2 Risk Management Measures Guidance booklet by the NCSC. This is a detailed 65-page guide setting out what essential and important entities are expected by the Irish State to do under NIS2 to manage cyber security risk.

• Ireland joined the Cyber Fundamentals Framework (CyFun), originally developed in Belgium, as a scheme co-owner. The CyFun framework provides a structured, risk-based approach for essential and important entities to help entities organise and evidence their NIS2 security measures. Ireland is taking steps to ratify this framework as a nationally certified scheme which can be used by companies to demonstrate compliance with NIS2 requirements.

This legislation represents a significant step in strengthening the State’s cyber security and resilience. It will enhance cyber security risk management in Ireland bringing with it significant improvements in our capacity to protect against and respond to major incidents. It also reflects the growing importance of cyber security as a matter of national interest not only for the protection of our most critical national infrastructure, but also for our economy, our democratic processes, and the safety of our citizens.

Roinn