Ireland’s NIS2 Competent Authorities: NCSC, CBI, ComReg, CRU, and the Sector Routing Table Irish Entities Need Now
Ireland has designated eight different competent authorities to supervise NIS2 compliance — yet most Irish compliance teams still assume the National Cyber Security Centre (NCSC) handles everything. It doesn’t.
Under the National Cyber Security Bill 2024, Ireland adopts a federated model: the NCSC serves as lead authority and catch-all supervisor for the majority of sectors, but the Central Bank of Ireland (CBI), Commission for Communications Regulation (ComReg), and Commission for Regulation of Utilities (CRU) each own supervision for their respective sectors. Register with the wrong body, and your incident notifications and supervisory correspondence land with an authority that has no jurisdiction over you.
Ireland missed the EU’s October 17, 2024 transposition deadline. As of June 2026, the National Cyber Security Bill is in pre-legislative scrutiny and no registration portal is yet operational. NIS1 obligations remain active for existing Operators of Essential Services. But the regulatory architecture is already settled in the published General Scheme — and understanding it now is far less costly than scrambling when the portal opens.
This guide maps every Annex I and Annex II sector to its designated Irish competent authority, explains the difference between essential and important entity supervision, and identifies what Irish organisations can do before the registration portal goes live. For a broader overview of Ireland’s NIS2 framework, see NIS2 in Ireland.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Ireland’s Federated Competent Authority Model
Article 8 of the NIS2 Directive (EU) 2022/2555 requires each Member State to designate one or more competent authorities responsible for cybersecurity and to establish a single point of contact for cross-border cooperation. The Directive allows this through a single national body or through multiple sector-specific regulators — and Ireland chose the latter.
Most EU Member States centralised authority in one body: Belgium designated the Centre for Cybersecurity Belgium (CCB); France assigned primary authority to ANSSI. Ireland’s National Cyber Security Bill 2024 distributes supervisory responsibility across eight designated authorities. The NCSC acts as both Ireland’s single point of contact with EU institutions and as residual competent authority for sectors not assigned to a specialist regulator.
This federated design has one consequence that overrides all others: the authority you report a significant incident to, register with, and receive audit notices from depends entirely on your sector — not on company size, not on a single central helpdesk. Before taking any compliance action in Ireland, verify your sector assignment in the table below.
Complete Sector Routing Table — All Eight Irish Competent Authorities
The following assignments are drawn from the General Scheme of the National Cyber Security Bill 2024, published August 30, 2024. These are draft provisions; treat the enacted legislation as the definitive source when the Bill passes.
| Sector (NIS2 Annex) | Competent Authority | Supervision Model |
|---|---|---|
| Energy — electricity and gas (Annex I) | Commission for Regulation of Utilities (CRU) | Ex ante for essential entities |
| Drinking water (Annex I) | Commission for Regulation of Utilities (CRU) | Ex ante / ex post by entity size |
| Wastewater (Annex I) | Commission for Regulation of Utilities (CRU) | Ex ante / ex post by entity size |
| Digital infrastructure — DNS, cloud, CDN, data centres, trust services, IXPs (Annex I) | Commission for Communications Regulation (ComReg) | Ex ante for essential entities |
| Electronic communications networks and services (Annex I) | Commission for Communications Regulation (ComReg) | Ex ante / ex post by entity size |
| ICT service management — MSPs and MSSPs (Annex I) | Commission for Communications Regulation (ComReg) | Ex ante / ex post by entity size |
| Digital providers — online marketplaces, search engines, social networks (Annex II) | Commission for Communications Regulation (ComReg) | Ex post for important entities |
| Space (Annex I) | Commission for Communications Regulation (ComReg) | Ex ante / ex post by entity size |
| Banking (Annex I) | Central Bank of Ireland (CBI) | Ex ante for essential entities |
| Financial market infrastructure (Annex I) | Central Bank of Ireland (CBI) | Ex ante for essential entities |
| Aviation (Annex I) | Irish Aviation Authority (IAA) | Ex ante / ex post by entity size |
| Rail transport (Annex I) | Commission for Rail Regulation (CRR) | Ex ante / ex post by entity size |
| Maritime transport (Annex I) | Minister for Transport | Ex ante / ex post by entity size |
| Road transport (Annex I) | National Transport Authority (NTA) | Ex ante / ex post by entity size |
| Public administration (Annex I) | NCSC (Ireland) | Ex ante for essential entities |
| Healthcare (Annex I) | NCSC / health sector agencies | Ex ante for essential entities |
| Manufacturing, postal/courier, waste management, chemicals, food production, research (Annex II) | NCSC (Ireland) — catch-all | Ex post for important entities |
| All other Annex I and Annex II sectors not listed above | NCSC (Ireland) — catch-all | Varies by entity classification |
Three sector assignments warrant additional explanation.
Banking and financial services: The CBI supervises under NIS2, but financial entities are also subject to the EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which applied directly from January 17, 2025 without national transposition. Entities subject to DORA are considered to use equivalent measures for NIS2 Article 21 ICT risk management purposes — DORA operates as lex specialis for that area. However, NIS2 registration and incident notification obligations continue to apply through the CBI.
Digital infrastructure and ICT services: ComReg’s scope is broader than the “telecoms” label suggests. If your organisation operates cloud computing services, manages a content delivery network, provides DNS resolution, runs a data centre open to third parties, or delivers managed security services (MSSP) to business clients, ComReg is your competent authority — not the NCSC.
Healthcare: The General Scheme indicates that health sector supervision will involve relevant health sector agencies in coordination with the NCSC. Entities in this sector should monitor both NCSC and HSE guidance channels for formal designation notices.
NCSC Ireland — Lead Authority and Catch-All Supervisor
The National Cyber Security Centre holds three distinct roles under the National Cyber Security Bill 2024.
Competent authority for unlisted sectors. Any Annex I or Annex II sector not assigned to a specialist regulator — manufacturing, postal and courier services, chemicals, food production, waste management, and research — registers with and reports to the NCSC. This makes the NCSC the single largest competent authority by number of entities, because Annex II “other critical” sectors represent the majority of Irish businesses that will fall into NIS2 scope for the first time.
Lead Competent Authority. For large-scale incidents affecting multiple sectors or crossing EU borders, the NCSC coordinates the national response. All sector-specific competent authorities share threat intelligence and incident data through an NCA Forum chaired by the NCSC. In this role, the NCSC also acts as Ireland’s single point of contact with EU institutions under Article 8 of the NIS2 Directive.
Computer Security Incident Response Team (CSIRT-IE). The NCSC operates Ireland’s national CSIRT, handles the 24-hour early warning protocol, and coordinates with EU-CyCLONe for cross-border cyber incidents of significant scale.
The NCSC has published substantive NIS2 guidance ahead of the Bill’s enactment. Draft Risk Management Measures Guidance was published on June 24, 2025, providing practical mapping of NIS2 Article 21 obligations. An “Am I in Scope?” self-assessment tool is live at ncsc.gov.ie. The registration and incident reporting portals are not yet operational; both will launch when the Bill is enacted. For entities in NCSC-supervised sectors, ncsc.gov.ie is the primary source to monitor for portal launch dates.
Ireland’s Delayed Transposition — Current Status and Practical Implications
Ireland’s NIS2 transposition has a specific legal status as of June 2026 that affects every obligation discussed in this guide.
The National Cyber Security Bill 2024 was approved for priority drafting by the Irish government on July 24, 2024. The General Scheme was published August 30, 2024. The Bill then entered pre-legislative parliamentary scrutiny — a mandatory committee examination stage before formal introduction to the Oireachtas. Ireland missed the EU’s October 17, 2024 transposition deadline as a result, and the European Commission has initiated infringement proceedings against Ireland for non-transposition.
There is no enacted statutory instrument governing NIS2 in Ireland. The NIS1 framework — the European Union (Measures for a High Common Level of Security of Network and Information Systems) Regulations 2018 — continues to apply to existing Operators of Essential Services until the NIS2 legislation supersedes it. For the NIS2 transposition timeline across all EU Member States, see the NIS2 transposition tracker.
What this means for Irish entities right now:
- No registration portal exists. You cannot register as a NIS2 entity in Ireland today.
- No NIS2 incident reporting portal exists. Existing NIS1 Operators of Essential Services should continue using NIS1 reporting channels; entities newly in scope under NIS2 have no mandatory reporting obligation until the Bill is enacted.
- Once the Bill is enacted and the portal opens, organisations in scope will have approximately three months to submit their registration.
- First substantive supervisory audits are projected for 2027, roughly 18 months after enactment.
The delay does not eliminate preparation value. Competent authorities, including ComReg, have stated publicly that supervision and enforcement will begin promptly once the Bill passes. Gap analyses, policy documentation, and RACI matrices take considerably longer to complete under audit pressure than in advance. The entity registration guide covers the full registration process in detail.
Essential vs Important — Thresholds and Supervision Types
NIS2 creates two compliance tiers, and the boundary between them determines whether your competent authority audits you before or after something goes wrong. For a detailed comparison, see the essential vs important entity guide.
Entity classification thresholds:
| Classification | Size Criteria | Automatic Inclusions |
|---|---|---|
| Essential Entity | 250+ employees OR €50M+ annual turnover AND balance sheet ≥ €43M | Qualified trust service providers, TLD registries, DNS providers (regardless of size); existing NIS1 OES |
| Important Entity | 50–249 employees OR €10–50M turnover | Large enterprises providing Annex II services only |
| Out of scope | Fewer than 50 employees AND under €10M turnover | May be individually designated by the Minister if providing critical services |
Essential entities face ex ante (proactive) supervision. This means your competent authority can inspect your systems and documentation before any evidence of non-compliance exists. Proactive supervision includes on-site inspections and random checks, regular security audits by independent bodies commissioned by the authority, ad hoc audits triggered by significant incidents, security scans, and demands for documentation at any time. The authority does not need a complaint or a breach to begin examining your organisation.
Important entities face ex post (reactive) supervision. Your competent authority will not conduct proactive inspections. Supervisory action is triggered by evidence of non-compliance — but “evidence” includes credible third-party reports, incident disclosures, outputs from network scans run by the authority, and referrals from other regulators. The absence of proactive audits does not mean the absence of risk.
The practical consequence for essential entities: gap analyses, policy documentation, and control registers need to be audit-ready from day one of the registration portal opening, not six months after. For more on what competent authorities can require, see NIS2 supervisory measures.
Incident Reporting — Which Authority Receives Your Notification?
Ireland implements the NIS2 Article 23 tiered notification framework. A significant incident — one that has caused or is capable of causing severe operational disruption or substantial financial loss, as defined in Commission Implementing Regulation (EU) 2024/2690 — must be reported in three stages:
| Stage | Deadline | Required Content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Whether the incident is suspected to be malicious; whether cross-border impact is possible |
| Incident notification | Within 72 hours | Initial severity assessment; indicators of compromise; provisional root cause; mitigation steps taken or underway |
| Final report | Within 30 days (monthly updates if incident is ongoing) | Full root cause analysis; impact assessment; cross-border effects; applied and planned long-term mitigation |
The critical routing point: report to your designated competent authority, not to the NCSC by default. A banking entity reports to the CBI. A cloud services provider reports to ComReg. An automotive manufacturer reports to the NCSC. Sector authorities share incident data with the NCSC under the NCA Forum structure — but the initial notification must go to the sector regulator.
Until the Bill is enacted and the incident reporting portal is live, there is no mandatory NIS2 reporting mechanism for entities not already subject to NIS1 obligations. Full Article 23 criteria and reporting templates are covered in the Article 23 incident notification guide.
Penalties — Administrative Fines and Director Liability
The General Scheme of the National Cyber Security Bill 2024 sets out the following maximum administrative penalties. These are draft provisions; the enacted amounts may differ from the General Scheme figures.
| Entity Type | Maximum Administrative Fine |
|---|---|
| Essential Entities | Greater of €10 million or 2% of worldwide annual turnover |
| Important Entities | Greater of €7 million or 1.4% of worldwide annual turnover |
| Public Sector Entities | Not subject to financial fines; subject to binding statutory directions and Oireachtas scrutiny |
Ireland’s draft legislation also introduces personal liability for directors and senior officers. Under the General Scheme, an individual manager, director, company secretary, or officer can be held personally liable if an infringement occurs with their consent or connivance, or is attributable to their wilful neglect. Additional enforcement powers include binding instructions to cease infringing conduct, mandatory public disclosure of infringements, suspension of certifications or authorisations, and applications to the High Court to restrict individuals from management roles.
The personal liability provision is significant for Irish board-level governance. NIS2 Article 20 of the Directive separately requires management bodies to approve and oversee cybersecurity risk management measures — board sign-off on policy documentation is not optional, and Irish law will attach enforcement teeth to that obligation once enacted.
Frequently Asked Questions
Who is Ireland’s NIS2 competent authority for my sector?
Use the routing table above. NCSC is the default for any sector not assigned to a specialist regulator. Banking and financial markets → CBI. Digital infrastructure, cloud computing, telecoms, MSPs/MSSPs → ComReg. Energy, water, wastewater → CRU. Aviation → IAA. Rail → CRR. Maritime → Minister for Transport. Road transport → NTA.
When do I need to register?
There is no registration requirement until the National Cyber Security Bill is enacted. Once the portal opens, entities in scope will have approximately three months to submit their registration. Monitor ncsc.gov.ie for portal launch notifications. When registration opens, you will need to provide your organisation name, address, contact details including IP ranges, sector and subsector, and the EU Member States in which you provide services. Changes to any of these details must be notified within two weeks of the change.
Is my company subject to NIS2 in Ireland?
If you operate in an Annex I or Annex II sector with 50 or more employees or €10M or more in annual turnover, you are likely in scope. The NCSC’s “Am I in Scope?” self-assessment tool at ncsc.gov.ie is the recommended first step. For the full NIS2 scope assessment, see the detailed guide.
Does DORA replace NIS2 for financial entities?
No — but DORA takes precedence for ICT risk management in financial services. Financial entities subject to DORA are considered to be meeting NIS2 Article 21 requirements via DORA’s equivalent provisions for that specific area. However, NIS2 registration obligations and incident reporting through the CBI continue to apply independently. Entities subject to both frameworks should map their controls against the stricter requirement of each.
Will the sector routing table change when the Bill is enacted?
The sector assignments in the General Scheme are unlikely to change materially during the legislative process. However, treat the enacted legislation as the definitive source and monitor your competent authority’s website for formal designation notices.
Key Takeaways
Ireland’s NIS2 framework is federated, not centralised. The correct competent authority depends on sector, and getting it wrong means your registration and incident reports go to a body with no jurisdiction over you. The National Cyber Security Bill 2024 remains in pre-legislative scrutiny, and no registration portal is yet operational — but the sector assignments in the General Scheme are settled, entity thresholds are clear, and the ex ante versus ex post supervision distinction determines how urgently documentation needs to be in place.
The most productive action now is to identify which of the eight competent authorities will supervise your organisation, conduct a scoping assessment against Annex I and Annex II, and begin a gap analysis against Article 21’s ten security obligation areas. When the portal opens, you will have three months — not three years. For the full Article 21 compliance checklist, see the NIS2 compliance checklist.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 — National Cyber Security Centre Ireland
- NIS2 FAQ — National Cyber Security Centre Ireland
- NIS2 FAQs — Commission for Communications Regulation (ComReg)
- Article 8 — Directive (EU) 2022/2555 (NIS2), nis2resources.eu
- NIS2 Implementation: General Scheme of the National Cyber Security Bill 2024 — McCann FitzGerald
- Ireland NIS2 Transposition Status — nis-2-directive.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
