Abstract network security visualization over a financial district skyline representing Ireland NIS2 and DORA compliance for the finance sector

Ireland’s NIS2 Gap: CBI Already Regulates AIB, Citi, and JPMorgan Dublin Under DORA While the Cyber Security Bill Waits

The Central Bank of Ireland has been enforcing digital operational resilience rules against every bank, investment firm, and insurer it supervises since 17 January 2025 [8]. Ask the same institutions about their NIS2 obligations, and the honest answer is that Irish law does not have any yet – the National Cyber Security Bill 2024, the legislation meant to transpose the Directive, is still working its way through the Oireachtas [5][7]. On 9 July 2026 the European Commission referred Ireland, alongside Spain, France, and the Netherlands, to the Court of Justice of the EU over the missed transposition deadline [6]. For a compliance officer at a Dublin-based financial entity, that leaves a genuinely confusing question: what actually applies to you today?

This guide answers it in three parts: what the Central Bank of Ireland (CBI) already enforces under DORA, what NIS2 obligation is still missing and why, and what changes the moment the Bill passes. It uses AIB, Bank of Ireland, Citi Ireland, and JPMorgan Dublin as worked examples throughout, because DORA-covered is not a hypothetical category for any of them – it is their current supervisory reality.

Does This Apply to You? The Two-Question Test

Two separate questions determine your position, and they don’t have the same answer.

Question If yes If no
Are you a credit institution, investment firm, payment institution, e-money institution, or insurer under DORA Article 2(1)? [3] DORA has applied to you in full since 17 January 2025 – CBI is your supervisor now, not a future authority [8] Check DORA’s 6 exemption categories in Article 2(3) below – you may fall into the residual group
Are you (or your parent group) an Operator of Essential Service in banking, energy, transport, health, or digital infrastructure under S.I. No. 360 of 2018? [4] Ireland’s original NIS1 regime already applies to you – it hasn’t been repealed, only awaiting replacement [4][5] You have no domestic NIS2-family obligation until the National Cyber Security Bill is enacted

CBI’s Two Hats: DORA Supervisor Today, NIS2 Authority Tomorrow

Ireland’s competent-authority framework designates the Central Bank of Ireland as the sectoral authority for banking and financial market infrastructure once the National Cyber Security Bill takes effect. That role does not exist in force yet. What CBI already runs, in full, is DORA supervision: ICT risk-management frameworks, incident classification and reporting, resilience testing, and third-party risk oversight, backed by the Registers of Information every in-scope entity must file through the CBI portal [8]. The same regulator, in other words, is already active under one framework and dormant under the other – and the two switch on at different times.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

That distinction matters practically. A compliance officer who treats “CBI is my NIS2 authority” as settled fact is half right – CBI is designated for the role, but nothing is legally enforceable against your firm under that designation until the Bill is signed into law.

Why Ireland Is Different: DORA Live, NIS2 Still Pending

Every other country in this series – Belgium, France, Germany, Italy, the Netherlands, Poland – has already transposed NIS2 into national law, so the live question there is whether DORA displaces an existing domestic obligation. Ireland hasn’t reached that starting point. The Directive required transposition by 17 October 2024; Ireland missed it, and the National Cyber Security Bill was still at pre-legislative scrutiny stage well into 2026 [5]. On 7 July 2026 the NCSC published governance guidance for management boards anyway, explicitly framing it as preparation ahead of a law not yet in force [7]. Two days later, the Commission’s CJEU referral confirmed how far behind schedule Ireland actually is [6].

None of this means Irish financial entities operate in a legal vacuum. S.I. No. 360 of 2018, the regulation that transposed the original NIS Directive, was never repealed – it designated banking as an Operator of Essential Service category alongside energy, transport, health, and digital infrastructure, and it remains the operative Irish law today [4]. A bank already classified as an OES under the 2018 regime carries that status forward; the gap is that NIS2’s wider scope (covering many more mid-sized financial entities than the old regime ever reached) has no domestic legal footing until the new Bill commences.

The Lex Specialis Mechanism: What DORA Displaces, and What It Doesn’t

NIS2 Article 4 sets a general rule: where a sector-specific EU law imposes cybersecurity risk-management or incident-reporting obligations that are at least equivalent to NIS2’s, the overlapping NIS2 provisions do not apply to those entities [1]. DORA’s own Recital 16 confirms it meets that bar for financial entities, describing itself as “lex specialis with regard to Directive (EU) 2022/2555” precisely because its ICT risk-management and incident-reporting requirements are more stringent than the general regime [2].

In practice, once Ireland’s NIS2 transposition is in force, a DORA-covered entity’s ICT risk framework can be relied on as evidence of NIS2 Article 21 equivalence for the overlapping domains – it does not automatically clear every NIS2 obligation. Registration with the future NIS2 authority, incident-notification routing, and any Ireland-specific supervisory reporting sit outside DORA’s lex specialis carve-out and would still need to be addressed directly once the Bill commences.

DORA-Covered in Practice: AIB, Citi Ireland, and JPMorgan Dublin

Naming real Dublin-based entities makes the DORA/NIS2 boundary concrete rather than abstract.

Entity CBI authorisation DORA Article 2(1) category
AIB Group / Bank of Ireland Irish-headquartered credit institutions, CBI-supervised (a) Credit institution
Citibank Europe plc (Citi Ireland) Dublin-headquartered, CBI banking licence under the Central Bank Act 1971, jointly ECB/SSM-supervised [12] (a) Credit institution
J.P. Morgan SE, Dublin Branch CBI register ref. C150776, authorised Credit Institution [9] (a) Credit institution
J.P. Morgan Dublin plc CBI register ref. C185156, authorised Investment Firm (e) Investment firm

All four are DORA-covered under Article 2(1)’s credit-institution and investment-firm categories – there is no size threshold to check, no exemption to weigh. Dublin’s position as a financial hub (home to 20 of the world’s top 25 financial services firms and 17 of the top 20 global banking institutions [10]) means this pattern repeats across dozens of entities operating from what was originally branded the International Financial Services Centre – DORA’s full weight, already live, regardless of where NIS2 stands.

The Residual Gap: Who DORA Excludes and What Still Applies

DORA Article 2(3) exempts six categories, and each one lands in a different position under Irish law today [3][4]:

DORA-excluded category Irish position today
Sub-threshold AIFMs (Art. 3(2), AIFMD) No domestic NIS2 obligation unless separately designated as an OES under S.I. 360/2018
Certain (re)insurers under Solvency II Art. 4 Same – falls outside both DORA and the current OES list unless independently designated
Small IORPs (≤15 members) Outside DORA; unlikely to meet OES criteria given the size cap
Persons exempted under MiFID Art. 2/3 Outside DORA; NIS2 exposure depends on the entity’s actual activity, not its MiFID status
Micro/SME insurance intermediaries Outside DORA by design; a common gap for smaller Irish brokers
Post office giro institutions Outside DORA; not a live category in Ireland’s financial sector

The practical trap is assuming a DORA exemption means no cybersecurity compliance obligation at all. It means no DORA obligation. Whether S.I. 360/2018 or the eventual NIS2 transposition reaches a given excluded entity is a separate question entirely – see the Article 2(3) exclusion checklist for the fuller six-category breakdown used across this series.

What Changes When the National Cyber Security Bill Passes

Once transposition completes, three things activate that don’t exist under Irish law today: a domestic registration obligation with the designated authority, an enforceable incident-notification duty running in parallel with DORA’s own reporting track, and the penalty regime itself. NIS2 Article 34 sets the ceilings the Bill will need to match or exceed: essential entities face fines of at least EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher; important entities face at least EUR 7,000,000 or 1.4% [11]. None of this is enforceable in Ireland yet – it becomes live only once the Bill is signed and commenced, expected by the government’s own account before the end of 2026 [6].

Reader Playbook by Role

Role What to do now
CISO / IT Security Lead Map your existing DORA ICT risk framework against NIS2 Article 21’s ten measures – the overlap is substantial and the gap analysis doesn’t need to wait for the Bill
Compliance Officer Confirm your entity’s DORA Article 2(1)/(3) status in writing, and separately check whether S.I. 360/2018 already designates you (or your parent group) as an OES
Board / Executive Treat the NCSC’s July 2026 governance guidance as the baseline expectation now, not a future item – boards are already expected to own cyber risk oversight [7]

Compliance Checklist: Now vs. When the Bill Passes

  • Now: confirm DORA scope status under Article 2(1)/(3); file Registers of Information if in scope; check S.I. 360/2018 OES designation for your sector
  • Now: gap-map your DORA ICT risk framework against NIS2 Article 21’s measures so no rework is needed later
  • When the Bill commences: register with the designated NIS2 authority within the statutory window it sets
  • When the Bill commences: confirm which incident-notification track (DORA, NIS2, or both) applies to a given event, and route accordingly

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Frequently Asked Questions

Does DORA mean my Irish financial entity has no NIS2 obligation at all?
Not automatically. DORA’s lex specialis status under NIS2 Article 4 covers overlapping ICT risk-management and incident-reporting requirements once NIS2 is actually in force in Ireland [1][2]. Registration and jurisdiction-specific reporting sit outside that carve-out, and none of it is live yet regardless.

My firm is exempt from DORA under Article 2(3) – am I exempt from everything?
No. A DORA exemption only removes the DORA obligation. Whether S.I. 360/2018’s existing OES designation or the future NIS2 regime reaches your entity depends on your sector and size, not your DORA status [3][4].

When will Ireland’s NIS2 obligations actually take effect?
Not yet, as of this writing. The National Cyber Security Bill 2024 was still short of enactment when the European Commission referred Ireland to the CJEU on 9 July 2026; the Irish government’s own stated expectation is to notify transposition by the end of 2026 [6].

Sources

  1. NIS2 Directive Article 4 (lex specialis) – nis-2-directive.com
  2. DORA Regulation (EU) 2022/2554, Recital 16 – digital-operational-resilience-act.com
  3. DORA Article 2 (scope and exemptions) – digital-operational-resilience-act.com
  4. S.I. No. 360/2018, NIS Regulations 2018 – Irish Statute Book
  5. NIS2 Directive Transposition in Ireland – nis-2-directive.com
  6. EU refers Ireland to CJEU over NIS2 non-transposition, 9 July 2026 – The Record
  7. NCSC cyber governance guidance for management boards, 7 July 2026 – Global Policy Watch
  8. Digital Operational Resilience Act (DORA) – Central Bank of Ireland
  9. Financial Service Provider Register, J.P. Morgan SE Dublin Branch – Central Bank of Ireland Register
  10. IFSC Facts & Figures – IFSC.ie
  11. NIS2 Directive Article 34 (penalties) – nis-2-directive.com
  12. Citibank Europe plc – Wikipedia
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: