{{item.title}}
{{item.text}}
{{item.text}}
Ireland’s delay in transposing NIS2 should change the sequencing of readiness work, not the decision to begin it. When it comes into effect, management bodies will have greater accountability for how cyber risks are governed. Boards should therefore focus on critical services, dependencies, and evidence - not wait for complete legislative detail.
In July 2026, the European Commission referred Ireland to the Court of Justice of the European Union for failing to notify full transposition of the NIS2 Directive. Member states were required to transpose the Directive by 17 October 2024.
That delay creates uncertainty about aspects of the final Irish regime. However, it doesn’t change the direction of travel. The NIS2 Directive establishes cybersecurity risk management, reporting, supervision, and enforcement requirements across critical sectors. It also places explicit responsibilities on the management bodies of essential and important entities. The European Commission’s July 2026 referral underlines the pressure to complete implementation.
For Irish boards, the practical question is no longer whether to prepare. It’s how to use the period before full transposition to make proportionate decisions without overcommitting resources or building around assumptions that may change. The strongest approach is to begin with governance, critical services, and evidence.
NIS2 makes clear that cybersecurity risk cannot be delegated in full to IT or security teams. Under Article 20 of the Directive, management bodies of essential and important entities are expected to approve cybersecurity risk management measures, oversee their implementation, and undertake relevant training.
Ireland’s National Cyber Security Centre has translated this principle into practical expectations in its guidance for management board members. The guidance places accountability at senior management level and focuses on protecting the continuity of essential services.
This doesn’t mean that every board member must become a cybersecurity specialist. It means the board should be able to reach informed decisions about the organisation’s exposure, preparedness, and priorities.
The NCSC states that NIS2 has not yet been transposed into Irish law. It also notes that NIS1 remains operational for existing designated operators of essential services. The NCSC’s NIS2 information and FAQs provide the latest official position.
A readiness programme built around unverified assumptions could create unnecessary work. Waiting for complete certainty, however, would leave less time to resolve weaknesses that may require sustained operational change.
Boards can manage this tension by dividing proposed activity into three categories:
This sequencing allows an organisation to make progress without treating draft guidance as a final law.
An effective readiness assessment should begin with the outcomes the organisation must protect, not with a catalogue of security controls.
For a public body, that may mean maintaining access to an essential public service. For a private organisation, it could mean continuing a critical operational process or meeting an important obligation to customers. The board should understand which services matter most, what could interrupt them, and how long the organisation could operate without them.
This service-led view also exposes dependencies on infrastructure, cloud services, software, operational technology, specialist employees, and multiple external providers, that may otherwise remain hidden. A control assessment performed in isolation may miss how these elements combine during disruption.
NIS2 reflects this wider view of resilience. Article 21 covers areas including incident handling, business continuity, crisis management, supply-chain security, vulnerability handling, access control, and the assessment of risk management measures. These should be considered as connected capabilities rather than separate compliance activities. The full requirements are set out in the official text of the NIS2 Directive.
Many organisations have already invested in security frameworks, certifications, and controls. That work should not be discarded. The immediate task is to understand how it maps to the likely Irish requirements and where material gaps remain.
In June 2025, the NCSC published draft risk management measures and launched the Cyber Fundamentals Framework, or CyFun. The NCSC describes the draft measures as its view of the minimum measures likely to be required of essential and important entities. It presents CyFun as a voluntary, structured approach that organisations can use to implement and evidence security measures.
The distinction is important. CyFun can help an organisation organise and evidence its controls, but the NCSC states that using or obtaining assurance under the framework does not itself prove NIS2 compliance. Compliance will be determined by the relevant national competent authority under the eventual legislation.
Critical services increasingly depend on third parties. A supplier failure or compromise can affect operations even where an organisation’s internal controls remain intact.
NIS2 includes supply chain security among the cybersecurity risk management measures expected of entities in scope. The NCSC’s draft measures also include a specific supply chain policy.
This doesn’t require every supplier to receive the same level of scrutiny. A proportionate approach starts by identifying the third parties that support important services and considering the operational impact if they become unavailable or compromised.
Boards should be able to see which suppliers are critical, the nature of dependency, what assurance is available, where gaps remain, and who is responsible for addressing them. This makes supplier resilience a business-governance issue rather than a procurement checklist.
Many organisations can describe the activities they undertake to manage cyber risk. Fewer can readily show how key decisions were made, whether measures operate effectively, or how identified weaknesses are tracked.
That gap matters because governance depends on evidence. Policies alone don’t show that responsibilities are understood. An incident plan doesn’t show that it will work. A supplier questionnaire doesn’t demonstrate that material dependency has been addressed.
Evidence should be created as part of delivery rather than assembled shortly before an audit or regulatory request. The aim is to maintain a concise, traceable record showing what the organisation decided, what it implemented, and how it knows the measures are working.
Ireland holds the Presidency of the Council of the European Union from 1 July to 31 December 2026. Security is one of the Presidency programme’s three central themes.
In its June 2026 assessment, the NCSC said the Presidency gives Ireland’s political, diplomatic and cyber domains higher strategic value. Its assessment of cyber threats to Ireland’s EU Presidency identifies threats including financially motivated attacks, espionage, and disruptive activity.
This context reinforces the case for practical resilience work, particularly where organisations provide public, critical, or digitally dependent services. Not every organisation faces the same threat profile, but boards should nevertheless consider whether changes in the external environment affect their risk assessment, incident scenarios, or dependencies.
A readiness review has limited value if it produces a long list of controls without helping leaders decide what to do next.
The board should receive a prioritised view of the organisation’s position: the services that require the strongest protection, the risks that could cause the greatest disruption, the current level of assurance, and the actions that need leadership support.
Some improvements may be uncomplicated, such as clarifying incident escalation routes or recording the basis for a risk decision. Others — reducing a critical supplier dependency, modernising a vulnerable system, or redesigning continuity arrangements — may require investment and a longer delivery horizon.
That’s why preparation should begin before the final Irish legislation is available. Earlier visibility gives leaders more room to make considered choices, align cyber investment with business risk, and build evidence through normal delivery. Early preparation should leave the organisation with stronger governance, fewer unknowns, and a defensible plan when the final regime takes effect.
"NIS2 isn’t just raising the bar for cybersecurity controls; it’s raising the bar for leadership accountability. Irish boards can use the period before full transposition to clarify accountability, identify critical dependencies, and address the resilience gaps that matter most."
Pat Moran, PartnerAsk the legal, risk, and cyber teams to assess whether the organisation is likely to fall within the Irish NIS2 regime. Record the services, sector, size, and jurisdictional assumptions behind the assessment. Where the position remains uncertain, identify the issue that requires final legislation or competent authority guidance. Revisit the assessment when the Irish regime changes rather than treating the initial conclusion as permanent.
Identify the services whose disruption would cause the most serious operational, public, or customer impact. Map the systems, data, people, and third parties needed to deliver them. Use this analysis to prioritise control reviews, continuity planning, testing, and investment. This gives the board a business-led view of cyber exposure and prevents the readiness programme from becoming a broad technical inventory.
Introduce regular cyber resilience reporting through the appropriate board or executive committee. Keep it focused on material risks, critical-service dependencies, incidents, control effectiveness, outstanding actions, and decisions required. Agree who owns each risk and what should trigger escalation. Board reporting should make accountability clearer and support action, not simply provide assurance that activity is under way.
Segment suppliers according to their importance to priority services and the potential effect of disruption. For the most critical providers, assess the available assurance, contractual protections, incident arrangements, and continuity options. Identify concentrations or dependencies that the organisation may be unable to replace quickly. Give leadership a prioritised remediation plan rather than an undifferentiated supplier register.
Run a realistic incident exercise involving senior decision-makers and the relevant operational, technology, risk, legal, and communications teams. Test escalation, authority, continuity, and external communication — not only the technical response. Record the decisions made, weaknesses identified, owners, and completion dates. Use the results to improve the response model and demonstrate that governance arrangements operate beyond the written policy.
NIS2 preparation is likely to involve choices about scope, governance, critical services, suppliers, and evidence. PwC can help you assess your current position, identify the issues that matter most, and develop a proportionate readiness plan aligned with your wider cyber resilience priorities. Contact our team to discuss the practical implications for your organisation.
{{item.text}}
{{item.text}}
Menu