TL;DR
- As of 2026, Ireland still has not transposed NIS2, and the National Cyber Security Bill 2024 remains unenacted.
- On 8 July 2026 the European Commission referred Ireland (with Spain and France) to the Court of Justice of the EU for incomplete transposition.
- Obligations are already reaching Irish firms via board-level NCSC guidance and NIS2 clauses in customer and supply-chain contracts.
- With an estimated 6,000 entities in scope, and Ireland central to the EU data centre and sovereignty debate, waiting is the riskiest option.
- 6clicks helps you get audit-ready now with continuous evidence, AI-powered control mapping, and single-source oversight across entities.
It's tempting for Irish organisations to relax: as of 2026, NIS2 still hasn't been transposed into Irish law. The National Cyber Security Bill 2024, the intended vehicle, remains unenacted, and on 8 July 2026, the European Commission referred Ireland (alongside Spain and France) to the Court of Justice of the EU for incomplete transposition. But the absence of a signed statute is not the same as the absence of obligation.
On 7 July 2026, Ireland’s National Cyber Security Centre published Guidance on Cyber Governance for Management Board Members in NIS2 Entities, stating that NIS2 assigns cybersecurity risk management accountability to “the highest level of executive management” and helping boards understand their cybersecurity responsibilities under the Directive.
Meanwhile, NIS2 requirements are already flowing through contracts and supply chains: EU customers and partners subject to NIS2 in other Member States are pushing incident reporting and control obligations onto their Irish vendors right now, regardless of Irish law.
Ireland hosts one of Europe’s major data-centre clusters, with Dublin recognised as part of the FLAP-D group of leading European data-centre markets. In 2025, data centres accounted for 23% of Ireland’s metered electricity consumption according to Ireland’s Central Statistics Office, which places the country at the heart of the EU's sovereignty and cloud debate. The proposed Cloud and AI Development Act (CADA, June 2026) and the wider tech-sovereignty package will directly shape how Irish infrastructure is built and governed.
The smart move is to get audit-ready before the law lands. In 2026, continuous assurance is the operating model: regulators, boards and buyers want proof your controls work right now, and automated evidence collection has become the standard way to deliver it. Organisations that wait for enactment will be scrambling; those that prepare now will already be able to demonstrate compliance.
6clicks lets Irish organisations get ahead of the National Cyber Security Bill, and satisfy the contract clauses already landing today:
Ready for Sovereignty? See how 6clicks moves you from documented to demonstrated compliance. Speak with our team.