Skip to main content
NIS2 · IRELAND

NIS2 in Ireland — a Bill still before the Oireachtas, and the headquarters question that cannot wait.

Ireland has not yet enacted its NIS2 transposition. The National Cyber Security Bill 2024 remains before the Oireachtas, and on 8 July 2026 the Court of Justice was seised in the Commission's transposition-delay action against Ireland — alongside France and Spain. The NCSC, under the Department of the Environment, Climate and Communications, continues as the operative authority and published board-level guidance in July 2026 while the Bill progresses.

What does not wait is the scope question. Ireland hosts an outsized share of US technology multinationals' EU headquarters, which makes “does our Irish HQ pull the whole EU operation in?” the most consequential applicability question in the country. The answer is no — NIS2 applies per-entity in each member state — but determining each entity's position is work that can and should start now.

Who it applies to

Entities in the NIS2 sectors established in Ireland or offering services there. The Bill's current shape points to sectoral enforcement through existing regulators — ComReg for telecoms, the CRU for energy, the Central Bank for financial entities — alongside the NCSC. Scope analysis against the directive can be done today; registration deadlines and evidence duties wait for enactment.

The clock

Competent authority: NCSC-IE (under the Department of the Environment, Climate and Communications) — Bill pending. Transposition: National Cyber Security Bill 2024 (not yet enacted).

NIS2 in Ireland · timeline
WhenWhat happens
2024National Cyber Security Bill published · Oireachtas process opens
8 Jul 2026Court of Justice seised in the transposition-delay action (with France and Spain)
Jul 2026NCSC publishes board-level guidance while the Bill progresses
PendingEnactment · registration deadlines and sectoral enforcement designations follow

Headquarters does not equal EU-wide scope

Ireland hosts an outsized share of US tech multinationals' EU headquarters, which makes the scope question particularly consequential: does an Irish headquarters mean NIS2 applies to our entire EU operation? The answer is no. NIS2 applies per-entity in each member state where you operate, not centrally through your headquarters. An Irish entity is assessed on its own facts; a French subsidiary is assessed on French facts; a German operation on German facts. The headquarters location does not create EU-wide scope, nor does it shield other national entities. Each entity stands alone in the assessment — and TruSecure holds that per-entity assessment, with the Bill's legislative status tracked as a dated fact that updates the plan the moment enactment lands.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Ireland transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Ireland requirements · how TruSecure answers them
What the law asksWhere it is answered
Assess each national entity on its own factsApplicability engine · per-entity size/sector/threshold check, independent of headquarters
Track the Bill and the Court of Justice actionCompliance workspace · legislative status held as a dated, monitored fact
Follow NCSC board-level guidance nowGovernance workspace · board oversight and training records, dated
Prepare incident workflow to the directive's clocksIncident workflow · 24 h / 72 h / 1-month stages pre-built
Map ComReg / CRU / Central Bank exposure if sectoralEntity profile · planned sectoral routing recorded, updated at enactment

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Ireland NIS2 readiness file · excerptSample data
Applicability
confirmed · Irish entity of US parent, essential classification
Headquarters coordination
documented · group controls credited per-entity
Legislative tracking
Bill before the Oireachtas · CJEU action 8 Jul 2026
Controls evidenced
51/67 · 16 open, each with an owner and a date
Export
sealed · sha256:9b3d...7e2c

Where teams usually start

With a demo walked through by TruSecure — your Irish entity assessed on its own facts, the planned sectoral routing recorded against the Bill's current shape, and the controls you already operate credited where they genuinely apply. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Ireland by NCSC-IE (under the Department of the Environment, Climate and Communications) — Bill pending. TruSecure determines applicability against Ireland's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

If our EU headquarters is in Ireland, does NIS2 apply to our whole EU operation through it?
No — NIS2 applies per-entity in each member state where you operate, not centrally through your Irish headquarters. Ireland hosts an outsized share of US tech multinationals' EU headquarters, which makes this a common scope question TruSecure resolves per-entity.