IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

NIS2 in Ireland: CyFun, the NCSC and What Applies Today

Ireland is in an unusual position: it has committed to a national cybersecurity assessment framework before the law requiring it has passed. That makes "what do I actually have to do right now?" a genuinely confusing question. This page answers it plainly, and separates what is in force from what is announced.

What actually applies today

This is the part most coverage skips. Ireland was required to transpose NIS2 by October 2024 and has not completed it. The National Cyber Security Bill 2024 had its General Scheme published in August 2024, the general election interrupted the timetable, and the Bill remains at committee stage.

The Bill is not enacted

Until it is, NIS2 obligations are not yet directly enforceable in Irish law. Commentary expects passage during 2026.

Registration portals are not live

The NCSC has said NIS2 registration and reporting portals will not open until the legislation is enacted. There is currently nothing to register with.

NIS1 obligations continue

Organisations already designated under the original NIS Directive remain subject to those obligations in the meantime. This is the one part that is enforceable today.

Preparation is voluntary but sensible

The NCSC encourages in-scope entities to use the framework internally and begin preparing rather than waiting for the portal to open.

Ireland adopted CyFun, and co-owns it

CyberFundamentals began as a Belgian framework published by the Centre for Cybersecurity Belgium. Ireland has not merely referenced it, it has adopted it. The NCSC states that "Ireland will be adopting CyFun as its national assessment and certification scheme and have become joint owners of the scheme." Read our full CyberFundamentals guide .

CyFun is not the only route

Worth being clear, because vendors selling CyFun tooling rarely say it. The NCSC describes CyFun as a recognised means by which entities can demonstrate compliance, but explicitly not the sole route. ISO/IEC 27001, IEC 62443 and direct assessment by the National Competent Authority all remain acceptable.

CyFun

National scheme, three assurance levels, self-assessment available now, certification expected around 2027.

ISO/IEC 27001

Internationally portable, mature certification market, available today. The pragmatic choice for organisations that already hold it or trade widely outside Ireland.

IEC 62443

Relevant where operational technology and industrial control systems are in scope.

Direct NCA assessment

Assessment by the competent authority itself, rather than via a framework.

The three assurance levels

CyFun classifies entities by size, sector, risk exposure and the potential impact of an incident. Ireland uses Basic, Important and Essential.

Basic

The entry level and the realistic starting point for most SMEs, including suppliers pulled in through customer requirements rather than by direct designation.

Important

For entities classified as important under NIS2. More rigorous implementation and evidence.

Essential

For essential entities: critical infrastructure and large public sector bodies. Fullest implementation.

A five-country scheme, not a Belgian one

CyFun is now the national scheme in five EU member states, which changes what adopting it means. The Scheme Owner Group is Belgium, Ireland, Romania, Malta and Cyprus. France recognises the framework and is exploring adoption but uses its own ReCyF framework, so it is not a member.

What to do while the Bill is pending

Waiting for the portal is the wrong instinct, because preparation is the long pole and legislation is not. The work below is useful regardless of when the Bill passes, and none of it is wasted if you later choose ISO 27001 instead.

Establish whether you are likely in scope

Check your sector against NIS2 Annexes I and II and the size thresholds. Note that managed service providers are Annex I but are not exempt from the size test.

Run the self-assessment

The CyFun self-assessment is available now. The NCSC currently points to the tooling and supports published by the Belgian CCB while Irish-specific resources are developed.

Fix the gaps, not the paperwork

A self-assessment that produces a list of open controls is useful. One that produces a score and nothing else is not.

Expect supplier questions before regulation

In practice the first real deadline for most organisations is not the regulator, it is a customer sending a security questionnaire with a contract clause attached.

How Easy Cyber Protection helps

ECP is a CyFun-native audit-readiness platform. It implements all four CyFun levels on the CyFun 2025 framework, produces the evidence trail an assessor reads, and is built to be delivered by an IT partner across a client portfolio rather than bought per organisation.

CyFun 2025 native — all levels implemented from the framework itself, not mapped in afterwards
Evidence, not just scores — per-control evidence with owners and review dates
Built for IT partners — multi-client, white-label, priced per client by size
Portable across the five — the same control set applies in Ireland, Belgium, Romania, Malta and Cyprus

Frequently Asked Questions

Is NIS2 law in Ireland yet?

Not yet. Ireland was required to transpose NIS2 by October 2024, but the National Cyber Security Bill 2024 remains at committee stage. Until it is enacted, NIS2 obligations are not directly enforceable in Irish law, and the NCSC has confirmed that registration and reporting portals will not go live before then. Organisations already designated under the original NIS Directive remain subject to those obligations in the meantime.

Do I have to use CyFun in Ireland?

No. CyFun certification in Ireland is voluntary. The NCSC describes it as a recognised means of demonstrating compliance but explicitly not the only one: ISO/IEC 27001, IEC 62443 and direct assessment by the competent authority all remain acceptable. For the public administration sector, CyFun is described as the preferred method.

When will CyFun certification be available in Ireland?

Around 2027. The NCSC has said standing up a certification system takes 18 to 24 months because of the legal agreements, resourcing and accreditation infrastructure involved. Self-assessment, by contrast, is available now.

Should I wait for the Bill before doing anything?

No, and the reason is practical rather than legal. Preparation takes months; legislation passing takes a day. The NCSC encourages entities to use the framework internally and begin preparing now. Most of that work also counts towards ISO 27001 if you later choose that route instead.

How does Ireland differ from Belgium on CyFun?

Belgium is further along. It transposed NIS2 in April 2024, has roughly 4,000 registered entities, a live registration portal, and four bodies authorised to verify CyFun at Basic and Important level. Ireland has adopted the same framework but has not enacted its legislation, has no registration portal open, and has no certification bodies yet. The framework and its controls are the same; the surrounding machinery is not.

My company is small. Does any of this reach me?

Possibly, but usually not through direct designation. NIS2 size thresholds mean many small organisations are out of direct scope. The route that does reach them is Article 21(2)(d): in-scope customers must manage supply chain risk, so they send security questionnaires to their suppliers. That obligation is contractual rather than regulatory, and it tends to arrive before any regulator does.

Related Articles

Sources

  1. CyFun — National Cyber Security Centre Ireland — Irish adoption, levels and timeline
  2. CyFun FAQ — NCSC Ireland
  3. CyberFundamentals Framework — scheme governance and participating countries
  4. National Cyber Security Bill 2024 — Houses of the Oireachtas
  5. NIS2 Directive (EU) 2022/2555 — Official Journal of the European Union