Ireland has been referred to the Court of Justice of the European Union for failing to fully transpose the NIS2 Cybersecurity Directive into national law — and this time, the European Commission is asking the Court to impose financial penalties.
The referral, confirmed in the Commission's July 2026 infringement package, puts Ireland alongside Spain, France and the Netherlands as the four member states still without a functioning national NIS2 law, nearly two years after the transposition deadline passed. For Irish businesses across critical sectors, the story isn't really about Brussels and the courts. It's about the fact that a directive Ireland hasn't yet passed into law is already reshaping what “adequate” cybersecurity looks like, and the businesses that wait for the legislation to catch up will be the ones scrambling when it does.
The NIS2 Directive (EU 2022/2555) was due to be transposed into Irish law by 17 October 2024. When that deadline passed, the Commission issued a letter of formal notice in November 2024, followed by a reasoned opinion in May 2025. With still no transposition in place by mid-2026, Ireland's case, logged as INFR(2024)0279, was referred to the Court of Justice in July 2026.
This is the formal escalation stage of an EU infringement process, and it's not without consequence. Ireland's National Cyber Security Bill, which would transpose NIS2 and place the National Cyber Security Centre on a statutory footing, is still moving through the Oireachtas. Justice Minister Jim O'Callaghan has indicated he expects transposition to be notified by the end of 2026, but until that happens, the exposure keeps growing.
The Commission's referral includes a request for financial sanctions: a lump-sum penalty plus daily fines for every day the delay continues. Professional services firm Aon has estimated Ireland's exposure at roughly €2.8 million using the Commission's own methodology, with the daily fines still accumulating for as long as the law remains unfinished.
This isn't Ireland's first time facing this kind of bill. A similarly delayed transposition of the European Electronic Communications Code previously cost the State €4.5 million. There's a pattern here, and it's an expensive one, ultimately borne by taxpayers rather than by the organisations NIS2 was designed to regulate.
Here's the part that matters most for Irish organisations: NIS2's substance doesn't disappear just because the Irish legislation is delayed. The directive expands cybersecurity obligations, stronger risk management, mandatory incident reporting, and direct accountability for management bodies, across 18 critical sectors including energy, transport, health, digital infrastructure, and public administration.
Once the National Cyber Security Bill passes, affected organisations won't get a long runway to comply. Regulators across the EU have made clear that enforcement will follow quickly once national laws are in place, and organisations that haven't started building the required risk management framework, incident response processes, and governance structures will be starting from zero under time pressure. Suppliers and partners in NIS2-regulated supply chains are already being asked by larger customers to demonstrate their security posture, regardless of where Ireland's legislation stands.
In other words: the compliance clock for your business started well before Ireland's clock for passing the law.
The most effective way to prepare for NIS2 is to build the management system it will require before it's mandatory. NIS2's core expectations, risk assessment, access control, incident detection and reporting, business continuity, and supply chain security, map closely onto ISO/IEC 27001, the internationally recognised standard for information security management systems.
Organisations that already hold, or are working towards, ISO 27001 certification are typically far closer to NIS2 readiness than those starting with a blank page. Certification gives you:
Waiting for the National Cyber Security Bill to be enacted before acting isn't a strategy, it's a delay that compounds the delay Ireland is already being penalised for.
At CG Business Consulting, we help organisations across Ireland get NIS2-ready and achieve ISO 27001 certification, often within 12 weeks. We'll help you understand exactly where your current security posture stands against NIS2's requirements, and what's needed to close the gap before enforcement arrives.
Book a free 30-minute consultation with one of our experts today to discuss your business's specific needs and get a clear, practical plan for NIS2 and ISO 27001 readiness. Get in touch with our information security team to arrange your consultation.
💬 Contact us now to begin your journey