NIS2 in Ireland — a Bill still before the Oireachtas, and the headquarters question that cannot wait.
Ireland has not yet enacted its NIS2 transposition. The National Cyber Security Bill 2024 remains before the Oireachtas, and on 8 July 2026 the Court of Justice was seised in the Commission's transposition-delay action against Ireland — alongside France and Spain. The NCSC, under the Department of the Environment, Climate and Communications, continues as the operative authority and published board-level guidance in July 2026 while the Bill progresses.
What does not wait is the scope question. Ireland hosts an outsized share of US technology multinationals' EU headquarters, which makes “does our Irish HQ pull the whole EU operation in?” the most consequential applicability question in the country. The answer is no — NIS2 applies per-entity in each member state — but determining each entity's position is work that can and should start now.
Who it applies to
Entities in the NIS2 sectors established in Ireland or offering services there. The Bill's current shape points to sectoral enforcement through existing regulators — ComReg for telecoms, the CRU for energy, the Central Bank for financial entities — alongside the NCSC. Scope analysis against the directive can be done today; registration deadlines and evidence duties wait for enactment.
The clock
Competent authority: NCSC-IE (under the Department of the Environment, Climate and Communications) — Bill pending. Transposition: National Cyber Security Bill 2024 (not yet enacted).
| When | What happens |
|---|---|
| 2024 | National Cyber Security Bill published · Oireachtas process opens |
| 8 Jul 2026 | Court of Justice seised in the transposition-delay action (with France and Spain) |
| Jul 2026 | NCSC publishes board-level guidance while the Bill progresses |
| Pending | Enactment · registration deadlines and sectoral enforcement designations follow |
Headquarters does not equal EU-wide scope
Ireland hosts an outsized share of US tech multinationals' EU headquarters, which makes the scope question particularly consequential: does an Irish headquarters mean NIS2 applies to our entire EU operation? The answer is no. NIS2 applies per-entity in each member state where you operate, not centrally through your headquarters. An Irish entity is assessed on its own facts; a French subsidiary is assessed on French facts; a German operation on German facts. The headquarters location does not create EU-wide scope, nor does it shield other national entities. Each entity stands alone in the assessment — and TruSecure holds that per-entity assessment, with the Bill's legislative status tracked as a dated fact that updates the plan the moment enactment lands.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Ireland transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Assess each national entity on its own facts | Applicability engine · per-entity size/sector/threshold check, independent of headquarters |
| Track the Bill and the Court of Justice action | Compliance workspace · legislative status held as a dated, monitored fact |
| Follow NCSC board-level guidance now | Governance workspace · board oversight and training records, dated |
| Prepare incident workflow to the directive's clocks | Incident workflow · 24 h / 72 h / 1-month stages pre-built |
| Map ComReg / CRU / Central Bank exposure if sectoral | Entity profile · planned sectoral routing recorded, updated at enactment |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Applicability
- confirmed · Irish entity of US parent, essential classification
- Headquarters coordination
- documented · group controls credited per-entity
- Legislative tracking
- Bill before the Oireachtas · CJEU action 8 Jul 2026
- Controls evidenced
- 51/67 · 16 open, each with an owner and a date
- Export
- sealed · sha256:9b3d...7e2c
Where teams usually start
With a demo walked through by TruSecure — your Irish entity assessed on its own facts, the planned sectoral routing recorded against the Bill's current shape, and the controls you already operate credited where they genuinely apply. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Ireland by NCSC-IE (under the Department of the Environment, Climate and Communications) — Bill pending. TruSecure determines applicability against Ireland's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.