Skip to main content

On 24 August the Irish Times reported that Ireland is facing a lump sum penalty of roughly €2.8 million, plus daily fines accruing until the day it complies, for failing to transpose the EU’s NIS2 cybersecurity directive. The European Commission referred Ireland to the Court of Justice of the European Union on 8 July, alongside Spain, France and the Netherlands. The Netherlands has since transposed. Ireland has not.

The transposition deadline was 17 October 2024. We are twenty two months past it. The Minister for Justice, Home Affairs and Migration, Jim O’Callaghan, expects to be in a position to notify transposition by the end of 2026.

The coverage has treated this as a story about the State’s embarrassment. The consequence that matters lands on private companies, though, and hardest on the ones who have read “not yet law” as “not yet my problem”. The obligations have already started arriving. They are coming through a different door than the one everyone is watching.

TL;DR

  • Ireland was referred to the CJEU on 8 July 2026 for failing to fully transpose NIS2. Aon estimates exposure of around €2.8 million as a lump sum, with daily penalties accruing on top until transposition is notified.
  • The National Cyber Security Bill 2024 is still not enacted. Transposition is targeted for the end of 2026, which means the run-up between enactment and enforcement will be short.
  • Most Irish SMEs, SaaS companies and agencies will never be in direct scope. They will be pulled in as suppliers, through the supply chain security obligations that in-scope customers are contractually required to push down.
  • That pull-through is already live, because customers in other member states are already regulated. Irish legislative delay does not shelter you from a Dutch or German customer’s obligations.
  • The 24 hour early warning and 72 hour notification requirements are engineering problems, not legal ones. Detection and escalation capability takes quarters to build, not the weeks a registration window will give you.

What the referral actually is

When a member state fails to notify the Commission that it has transposed a directive, the Commission can go straight to the Court and ask for financial sanctions in the same action. That is what happened here. The request is for a lump sum, covering the breach to date, plus a daily penalty payment that runs until the state notifies complete transposition.

Ireland has form. A three year delay transposing the European Electronic Communications Code produced a €4.5 million fine. Nobody involved is treating the current exposure as theoretical.

Here is the part that is relevant to you, and that the coverage has skipped. The sanction is levied on the State, not on companies. But a daily accruing penalty is not something a government department manages at a leisurely pace. It converts an open-ended legislative timeline into a live cost with a running meter attached. The practical effect of the fine is to compress the enactment date, and with it the gap between “the Bill passes” and “you are registered, assessed and reporting”. The delay looked like breathing room. The fine is what turns it into a squeeze.

The Bill you have probably not read

The National Cyber Security Bill 2024 was published on 30 August 2024. It makes the NCSC Ireland’s lead competent authority and national CSIRT, and gives it powers including scanning for vulnerable internet-facing systems and, at an entity’s request, deploying monitoring sensors.

The penalty ceilings follow the directive: up to €10 million or 2% of worldwide annual turnover for essential entities, €7 million or 1.4% for important ones. The provisions most Irish boards have not internalised are the other ones, though: restrictions on holding director or management roles, and personal liability where an individual causes non-compliance. NIS2 puts cyber risk on the management body itself, which has to approve the risk measures and undergo training. That is not an obligation you discharge by buying a product.

The door most Irish companies will come through

The scope question dominates every NIS2 explainer: energy, transport, water, health, digital infrastructure, managed service providers, down the annexes. It is the wrong question for most of our clients, who will read those lists, correctly conclude they are not on them, and stop.

NIS2 requires in-scope entities to manage the security of their supply chain, explicitly including the security-related aspects of their relationships with direct suppliers and service providers. An in-scope entity cannot satisfy that by securing itself. It has to push requirements outward, to everyone who touches its systems or its data.

So the way NIS2 reaches a thirty person SaaS company in Dublin is not a letter from the NCSC. It is a procurement questionnaire from a hospital group, then a contract renewal carrying a new security schedule, an incident notification clause with a timeline shorter than yours, an audit right, and a requirement to notify on change of subprocessor. There is no regulator to appeal to, because this is not regulation reaching you. It is a customer, and the only leverage available is commercial.

And this is happening now, not after the Bill passes. Every in-scope entity in a member state that has already transposed is already under these obligations. If you sell to a Dutch utility, a German logistics operator or a French bank, Ireland’s legislative timetable is irrelevant to your contract terms. We have seen this land in renewals over the past year, usually as a surprise, usually with a deadline attached.

The 24 hour clock is an engineering problem

NIS2 reporting runs on a fixed schedule: an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, and a final report within a month.

The word doing the work there is “aware”. Detection sets the clock running, and detection is not a policy. It is centralised logging, alerting a human actually sees, and an escalation path with named people and out-of-hours numbers. Without that you do not have a slow 24 hour clock. You have an unmeetable one, plus the second problem of arguing about when you should reasonably have known.

Compliance vendors will sell you the documentation layer for this in a fortnight. The documentation is not the hard part. The hard part is being able to tell, on a Sunday morning, that something is wrong.

What to build with the lead time

The state’s delay handed Irish businesses an accidental run-up. Here is what is worth spending it on, roughly in order of how long each takes to get right.

  1. Asset and data inventory, including third parties. You cannot report on an incident affecting a system you cannot enumerate, and you cannot answer a supply chain questionnaire without this. Include the unglamorous things: CI runners, observability vendors, model APIs, the analytics tag someone added in 2023.
  2. Identity hygiene. Multi-factor authentication everywhere, phishing-resistant where you can manage it, no shared administrative accounts, and an access review you actually run on a schedule. The directive names MFA explicitly, and it is the single control that most reliably shortens a security questionnaire.
  3. Detection and escalation you have tested. Centralised logs, alerts routed to a human, an on-call rota, and a written escalation path. Then run a tabletop exercise against it, because an untested escalation path is a diagram, not a capability.
  4. A supplier register with security terms in it. You are going to be asked, and you have to ask, of your own suppliers. Doing both from one register is far less work than doing them separately.
  5. Backups you have restored. Business continuity and crisis management are named obligations. A backup you have never restored is a hypothesis, and it is usually a wrong one.
  6. A board-level paper trail. Minute the approval of your risk management measures. Log the training. Given the personal liability provisions in the Bill, this is the cheapest item on the list and the one most often skipped.

The uncomfortable bit

Enactment plus a registration window will be measured in months. Building tested detection, a real access review habit and a restore drill is measured in quarters. That gap is the actual risk in this story, and it is not a legal risk. It is a delivery risk, which means it is ours as much as it is your compliance team’s.

The companies that will struggle are not the ones ignoring NIS2. They are the ones who read “the Bill has not passed” as permission to start later, and who will then try to buy the engineering work in the same quarter they are trying to buy the paperwork.

REPTILEHAUS builds the technical side of this: centralised logging and observability, identity and access architecture, CI/CD pipelines that produce an audit trail as a by-product rather than a retrofit, and dependency audits for teams filling in security schedules they did not write. If NIS2 clauses have started appearing in your contracts, get in touch and we will tell you which parts are an afternoon and which parts are a quarter.

📷 Photo by Scott Graham on Unsplash