On 9 July 2026, the European Commission referred Ireland to the Court of Justice of the EU for failing to transpose NIS2. Spain, France, and the Netherlands were referred alongside it. This isn’t a warning letter. It’s the Commission asking the Court to impose a lump sum penalty plus ongoing daily fines until Ireland formally notifies full transposition.
For anyone who’s been half-tracking NIS2 and assuming it’ll land “eventually,” this is the moment to stop assuming and start planning against an actual timeline, even an uncertain one.
Where things actually stand
Ireland missed the original transposition deadline of 17 October 2024. It wasn’t alone, most member states did, but Ireland is now one of a shrinking group still without transposing legislation in force. The vehicle is the National Cyber Security Bill, whose general scheme was published back in August 2024. It’s still working through pre-legislative scrutiny. The 2024 general election disrupted the legislative calendar early on, and the bill has been moving slowly since.
The Commission opened infringement proceedings against Ireland (and 22 other states) in November 2024, escalated to a reasoned opinion in May 2025, and has now escalated again to a CJEU referral. The pattern in similar cases is that member states tend to adopt the legislation while proceedings are underway, at which point the Commission withdraws before judgment. Don’t read the CJEU referral as “nothing will happen for years”, read it as external pressure that’s now genuinely accelerating the timeline.
The relevant minister has indicated Ireland is targeting notification of transposition by the end of 2026. Take that as a direction of travel, not a commitment; this bill has already slipped past one publicly stated timeline.
What’s still in effect while we wait
The old NIS1 framework continues to apply to already-designated Operators of Essential Services. If you were in scope under NIS1, you still have obligations today. NIS2’s expanded scope, the sectors, the essential/important entity split, the tighter incident reporting windows, doesn’t bind you yet, because the national implementing law that would create those obligations doesn’t exist.
The NCSC has published interim guidance in the gap, including the CyFun framework (Cyber Fundamentals, originally developed in Belgium, which Ireland has joined as a co-owner scheme) as a maturity model organisations can use to self-assess now, ahead of formal registration requirements.
The scope, for anyone who hasn’t checked
When it lands, NIS2 in Ireland is expected to bring an estimated 4,500–6,000 organisations into scope, using the directive’s standard thresholds:
- Essential entities: ≥250 employees and €50m+ turnover, in specified critical sectors
- Important entities: ≥50 employees and €10m+ turnover, in a broader set of sectors
That’s a significant expansion from NIS1’s much narrower OES list. If you’re an MSP, note that MSPs themselves are explicitly in scope as a sector under NIS2, not just your clients.
What backup and DR teams should actually do about this now
The temptation with a delayed transposition is to deprioritise the work until the law is actually in force. That’s the wrong read for two reasons.
First, the requirements aren’t a surprise. The directive text has been stable since 2022. The Irish-specific detail that’s still moving is enforcement mechanics, competent authority structure, and exact registration timing, not the substance of what “good” looks like for risk management, incident response, business continuity, and supply chain security.
Second, cyber insurers, as covered on this blog previously, are already underwriting to NIS2-aligned control expectations regardless of Irish transposition status. The market isn’t waiting for the legislature.
Practical steps that hold up regardless of when the bill passes:
- Run a scope self-assessment now using the CyFun framework or the directive’s own thresholds. Don’t wait for the NCSC’s “Am I in scope?” tool. It’s listed above and won’t change between now and then.
- Map backup and recovery architecture against Article 21 risk management measures: MFA, supply chain risk, incident handling capability, business continuity and crisis management, and encryption.
- Treat your existing NIS1 obligations, if any apply, as the floor, not the target. The gap between NIS1 and NIS2 scope is where most organisations will discover they’re newly in-scope and unprepared.
- Watch the registration mechanism. When it launches, expect a short self-registration window (three months has been floated as the model in earlier drafts). Have your CRO number, NACE code, and a designated cybersecurity contact ready so you’re not scrambling when the portal opens.
Final thought
Ireland being taken to the CJEU over this isn’t really the story. The story is that the substance of NIS2, what regulators, insurers, and increasingly your own customers expect of your resilience posture, has already arrived, even though the statute hasn’t. Legislative delay is not the same as obligation delay. Treat this the way you’d treat any known deadline of uncertain date: build to the requirement now, and let the formal enforcement date be a compliance formality rather than the trigger to start.

