
Ireland’s NIS2 Delay Leaves 3,000 Organisations in Limbo
Published by AINave Editorial
Ireland’s NIS2 implementation delay has left a practical gap between the EU directive and the rules Irish organisations can plan against. NIS2 was due to enter Irish law in October 2024, but it had not done so by 5 October 2026, when the article was published. The European Commission referred Ireland, France, Spain and the Netherlands to the EU Court of Justice in August over their failure to transpose the directive, leaving Ireland exposed to potential EU fines, according to the Irish Independent.
The uncertainty reaches beyond the organisations directly covered
Ireland’s National Cyber Security Centre estimates that more than 3,000 Irish organisations will be covered once the law takes effect. The article names energy, food, manufacturing, transport, healthcare and banking among the critical sectors involved. Customers and suppliers connected to those organisations also form part of the wider exposure, though the article does not give a complete list of entities or the criteria that will determine coverage.
For companies preparing for the change, the issue is not simply whether they will fall under the law. The article’s author, a technology and data-protection lawyer who advises Irish companies and multinationals, says uncertainty and the prospect of a short interval between publication of a bill and the law taking effect complicate decisions about internal procedures, incident response, contract terms and senior security hires. The author says this uncertainty has impeded investment, but provides no quantified measure of that effect. The immediate operational problem is that organisations may need to make plans without knowing the final Irish rules or how much time they will have to implement them.
The delay also affects the NCSC’s authority
The National Cyber Security Centre has more than 90 employees and a remit to support and coordinate cyber defences. Yet the article says its powers to intervene and investigate remain significantly curtailed without NIS2. The new law is also expected to put the NCSC on a statutory footing as an independent body, a change the author says has not yet happened.
That makes the delay consequential for both regulated organisations and the public body tasked with coordinating national cyber defence. The article does not detail the proposed powers, so the scale of the change cannot be assessed from its account alone.
The author points to competing legislative priorities, including the technically demanding AI Act, as part of the drafting challenge, but does not give a definitive explanation for the delay. Nor does the article set out the final NIS2 obligations or an Irish commencement timetable. Until those details are clear, organisations face a double planning problem: preparing for a broad cybersecurity law while lacking certainty about its exact scope and start date.






















