Does NIS2 apply to my small business in Ireland?
Most small Irish businesses are outside NIS2, but clients in scope will pass its supply-chain rules on to you. Where the law stands and what to do now.
For most small businesses in Ireland, not directly. NIS2 applies mainly to medium-sized and large organisations in critical sectors, but if you supply one of them, its security rules are likely to reach you through contracts and supplier questionnaires.
Where the law stands in Ireland
NIS2 is an EU directive (Directive (EU) 2022/2555). Each member state has to write it into national law, and the deadline for doing that was 17 October 2024. Ireland missed it. The Irish law that will bring NIS2 into effect is the National Cyber Security Bill, and at the time of writing (late September 2026) it has not yet been enacted.
On 8 July 2026 the European Commission referred Ireland to the Court of Justice of the EU for failing to transpose the directive, and asked the Court to impose financial penalties. That adds pressure to pass the Bill, although no commencement date has been set.
Until the law is in place, the NCSC says the original NIS rules still apply to the most critical operators, and there is no requirement to register under NIS2. The registration and incident reporting portals will open once the legislation is enacted.
Who NIS2 applies to
The Commission describes NIS2 as covering 18 critical sectors. They include energy, transport, banking, health, drinking water, digital infrastructure, managed IT services, public administration, postal services, waste management, food, and the manufacture of certain products such as medical devices, electronics and machinery.
Size matters too. The NCSC's NIS2 FAQ explains that the directive generally applies to medium-sized and large enterprises, not to micro or small ones. Under the EU definition, a small enterprise has fewer than 50 staff and an annual turnover or balance sheet total of no more than €10 million. A business in that category is usually outside direct scope, even if it works in a listed sector.
There are exceptions that apply regardless of size, including:
- DNS service providers and top-level domain registries
- Trust service providers
- Providers of public electronic communications networks or services
- An organisation that is the sole provider of a service essential to society or the economy
- Organisations identified as critical entities under the separate EU CER Directive
The NCSC does not confirm whether an organisation is in scope. It expects businesses to assess themselves and offers an "Am I in Scope?" tool on ncsc.gov.ie. If you are near the size thresholds, part of a larger group, or in one of the exception categories, check your position with an adviser.
How it reaches small businesses anyway
One of the ten security measures NIS2 requires is supply chain security. Organisations in scope must manage the security risks that come from their direct suppliers and service providers. The NCSC's FAQ notes that suppliers are not directly subject to NIS2 but may face indirect obligations, usually through contracts.
That affects businesses such as an IT support firm looking after a logistics company, an accountancy practice working for a hospital group, a manufacturer supplying parts to an energy company, or an agency handling a utility's customer data.
NIS2 also makes the management boards of in-scope organisations responsible for approving and overseeing cyber security, and the NCSC has published governance guidance for those boards. So the push for supplier checks often comes from the top of your client's organisation.
What you are likely to see:
- A security questionnaire before a new contract or a renewal
- Requests for copies of your policies, often starting with your information security policy
- Questions about multi-factor authentication, backups, updates and staff training
- Contract clauses requiring you to tell the client about security incidents within a set time
- A right for the client to review or audit your controls
The ten measures in plain terms
Clients often base their questions on the ten measures in Article 21 of NIS2. For a small supplier, they translate roughly as:
- Risk analysis and security policies: know your main risks and write down your rules
- Incident handling: a plan for who does what when something goes wrong
- Business continuity: backups, recovery and a plan to keep trading
- Supply chain security: checking your own suppliers, too
- Security when buying or building systems, including handling known weaknesses
- Checking that your measures work
- Basic cyber hygiene and staff training
- Use of encryption
- Staff security, access control and a list of your devices and systems
- Multi-factor authentication and secure communications
A 10-person firm is not expected to run the same programme as a hospital. NIS2 itself says measures should be proportionate to the size of the organisation and its risks, and your client should apply the same logic to you.
What to do now
- Check your own scope: your sector, your staff numbers and your turnover. Use the NCSC tool if you are unsure.
- List your clients that are in NIS2 sectors. Those are the ones most likely to send questionnaires or new contract terms at renewal.
- Put the basics in place: MFA on email and remote access, backups with at least one copy kept separate and a tested restore, automatic updates, and short security training for staff.
- Write it down. Short, accurate policies that match how you work, signed and dated, answer most first-round questions. Our guide on whether a small business needs an IT security policy covers which ones matter most.
- Decide how you would report an incident: who notices, who decides, who tells the client, and how quickly. Remember that for personal data breaches, GDPR already requires notice to the Data Protection Commission within 72 hours where there is a risk to people, whatever happens with NIS2.
- Keep a simple evidence folder: screenshots of MFA settings, a record of your last restore test, and a training attendance list.
- Watch the Bill. When it passes, expect clients to review supplier arrangements.
If you also sell to the UK
The UK is outside the EU, so NIS2 does not apply there. The UK has its own NIS Regulations and a Cyber Security and Resilience Bill, which was at report stage in the House of Lords in mid-September 2026. UK clients often ask suppliers about similar controls, so the same groundwork serves both.
Next step
To see where your gaps are, take the free security check. If questionnaires are already arriving, PolicyPack Pro includes an answer bank for common supplier questionnaire questions and maps each document to the ten NIS2 security measures.
Get your policies in place this week
12 tailored IT and cybersecurity policies, a business continuity plan and a compliance kit, in Word and PDF, from €149.
See the policy pack