Written answer
EU Directives
2496. Deputy Matt Carthy asked the Minister for Justice, Home Affairs and Migration further to Parliamentary Question No. 12569/26, the expected timeline for the legislative transposition of the NIS2 Directive; and if he will make a statement on the matter. [62759/26]
Comment on this
Work is close to finalisation on the drafting of the National Cyber Security Bill, which will transpose the NIS2 Directive and establish Ireland’s National Cyber Security Centre on a statutory basis, with a view to its publication in the autumn. The Bill will then commence its passage through the Houses of the Oireachtas. While transposition of the Directive is complex, considerable implementation milestones have been completed to date including:
• The launch of a National Competent Authority (NCA) Forum, led by our National Cyber Security Centre (NCSC) in 2024
• The development and publication of a NIS2 Risk Management Measures guidance booklet
• Ireland becoming a co-owner of the Cyber Fundamentals Framework (CyFun) which provides a structured, risk-based approach for essential and important entities to help them organise and evidence their NIS2 security measures
The NIS2 Directive is a revision of the Network and Information Security Directive (EU) 2016/1148 (NIS Directive), which is currently in force in the State (S.I. 360 of 2018). Until the NIS2 Directive is transposed and enacted, the NIS Directive will remain in full effect, covering the most critical operators of essential services and digital service providers in the State.
Additionally, work is at an advanced stage in my department on the preparation of Ireland's third National Cyber Security Strategy. On completion, this will fulfil a requirement under the NIS2 Directive.