Written answer
EU Directives
2498. Deputy Malcolm Byrne asked the Minister for Justice, Home Affairs and Migration the supports in place from the State for companies and organisations to ensure the implementation of the NIS2 Directive. [60482/26]
Comment on this
Work is close to finalisation on the drafting of the National Cyber Security Bill, which will transpose the NIS2 Directive and establish Ireland’s National Cyber Security Centre (NCSC) on a statutory basis, with a view to its publication in the autumn. The Bill will then commence its passage through the Houses of the Oireachtas.
Ahead of that, significant supports for companies and organisations to ensure compliance and the implementation of the NIS2 Directive have been put in place.
This includes the establishment of a dedicated NIS2 webpage which offers updates on the legislative status and practical steps for in-scope organisations. While full transposition is pending, the NCSC has advised organisations to treat NIS2 as a benchmark and start closing security gaps immediately.
There are also practical supports for organisations by way of readiness assessments. The NCSC encourages organisations to assess their current cyber security posture against NIS2’s risk management and reporting obligations via NIS2 Risk Management Measure Guidance, incident reporting and senior leadership engagement. A new resource, titled ‘Guidance on Cyber Governance for Management Board Members in NIS2 Entities’ is specifically designed to support Accounting Officers and Management Board members to fulfil their leadership responsibilities and protect the continuity of essential services with confidence.
Furthermore, there are dedicated sector-specific and SME supports in place. The NCSC is prioritising support for critical infrastructure and digital service providers which includes sectors like energy, transport, healthcare, and digital infrastructure, as they are most likely to be in scope for NIS2. The NCSC has also provided tailored guidance for SMEs. Resources include checklists and toolkits for gap analysis as well as training and workshops to raise awareness and build capacity.
There are a variety of other publicly available NIS2 Directive Resources available on the NCSC website, include a ‘NIS2 Quick Reference Guide’, and FAQ page, and 'Am I in Scope?’ to allow entities ascertain if they are within the scope of NIS2.
Finally, Ireland has joined the Cyber Fundamental Framework, which provides a structured, risk-based approach for essential and important entities to help entities organise and evidence their NIS2 security measures.