We use Google Analytics to see which pages are read and how the site is used, so we know what to improve. This only runs if you accept. See our privacy notice for details.

Dáil

Written answer

EU Directives

390. Deputy Rose Conway-Walsh asked the Minister for Justice, Home Affairs and Migration the implications for Ireland’s national security from failing to implement the EU Network and Information Security (NIS) 2 Directive; and if he will make a statement on the matter. [54126/26]

Comment on this
Jim O'Callaghan Minister for Justice, Home Affairs and Migration Fianna Fáil

Work is close to finalisation on the drafting of the National Cyber Security Bill, which will transpose the NIS2 Directive and establish Ireland’s National Cyber Security Centre on a statutory basis, with a view to its publication in the autumn. The Bill will then commence its passage through the Houses of the Oireachtas. While there have been significant complexities in transposing this Directive into Irish law, considerable implementation milestones have been completed to date including :

• The launch of a National Competent Authority (NCA) Forum, led by our National Cyber Security Centre (NCSC) in 2024

• The development and publication of a NIS2 Risk Management Measures guidance booklet

• Ireland becoming a co-owner of the Cyber Fundamentals Framework (CyFun) which provides a structured, risk-based approach for essential and important entities to help them organise and evidence their NIS2 security measures

The NIS2 Directive is a revision of the Network and Information Security Directive (EU) 2016/1148 (NIS Directive), which is currently in force in the State via S.I. 360 of 2018. Until the NIS2 Directive is transposed and enacted, the NIS Directive will remain in full effect, covering the most critical operators of essential services and digital service providers in the State.

Additionally, work is at an advanced stage in my department on the preparation of Ireland's third National Cyber Security Strategy, a draft of which was published recently for public consultation. On completion, this will fulfil a requirement under the NIS2 Directive.

Comment on this