Written answer
EU Directives
2494. Deputy Cathal Crowe asked the Minister for Justice, Home Affairs and Migration the current status of Ireland’s transposition of Directive (EU) 2022/2555 (the NIS2 Directive); the reasons for the delay in fully transposing the Directive, given that the deadline for transposition was 17 October 2024; whether Ireland is now facing financial penalties arising from this delay; the potential level of any lump-sum or daily financial penalties that may be imposed on the State; when the National Cyber Security Bill 2024 will be published and enacted to give full effect to the Directive; and if he will make a statement on the matter. [62443/26]
Comment on this
The NIS2 Directive came into force on January 16 2023 and EU Member States had until October 17 2024 to adopt and publish measures to transpose it in to national law. Work is now close to finalisation on the drafting of the National Cyber Security Bill, which will transpose the NIS2 Directive with a view to its publication in the autumn. The Bill will then commence its passage through the Houses of the Oireachtas.
The European Commission made a decision to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union (CJEU) in July 2026. In referring Ireland to the Court, the Commission recommended the imposition of a lump sum penalty and daily fines. The decision to impose these penalties, or any penalty, remains at the discretion of the Court.
The Commission was previously advised of the significant complexities in transposing this directive and the significant work completed to date by Ireland in relation to both drafting the Bill and practical measures in implementing NIS2.
In anticipation of having the legislation in place and to ensure that Ireland is ready to fully implement the Directive on the day of enactment of the Bill, we have taken significant steps to ensure that various implementing measures are in place. This includes a robust approach to sectoral regulation for the Directive with the designation of National Competent Authorities including the NSC to carry out enforcement and supervision, and who are already undertaking significant preparations to take on these new functions. The National Cyber Security Bill will also put the National Cyber Security Centre on a statutory footing. Within the NCSC, a National Cyber Security Incident Response Team or CSIRT-IE, an obligation under NIS2 has also been stood up.
This legislation represents a significant step in strengthening the State’s cyber security and resilience. It will enhance cyber security risk management in Ireland bringing with it significant improvements in our capacity to protect against and respond to major incidents. It also reflects the growing importance of cyber security as a matter of national interest not only for the protection of our most critical national infrastructure, but also for our economy, our democratic processes, and the safety of our citizens.