An Irish energy operator, water utility or transport network sits in an odd position right now. The cybersecurity obligations it will be held to are effectively settled, its regulator is already publishing what it expects, and the Irish law meant to impose all this has not been passed.
NIS2 is the directive behind that situation. For critical-infrastructure operators, the one option it does not leave open is waiting for the law to land before acting.
This piece is for Irish operators in scope: what "in scope" actually means here, what you will owe, and the gap most operators have not accounted for, the AI now running inside the systems NIS2 governs.
The Irish situation: in scope before the law is passed
Start with the thing that makes Ireland's position distinctive right now. NIS2 is an EU directive, and its substance is set at EU level - but a directive only bites once a Member State transposes it into national law. Ireland's vehicle for that is the National Cyber Security Bill, and as of writing it has not been enacted.
It would be a mistake to read that delay as breathing room. The obligations themselves are not in doubt, they are fixed by the directive - and the National Cyber Security Centre has already published governance guidance setting out what it expects of management boards, along with its Cyber Fundamentals framework as a route to demonstrating readiness.
In other words, the regulator has already signalled the approach it expects, through guidance that is recommended rather than yet binding - and intends to supervise against it once the law is in force.
An operator that treats the unenacted Bill as permission to wait is preparing to be caught flat-footed the moment it passes.
So the Irish situation is not "NIS2 is coming." It is "NIS2 applies to you, the expectations are published, and the enforcement scaffolding is being built around you as you read this."
Are you in scope, and as what?
For critical-infrastructure operators the scope question is usually answered quickly - but the tier matters, because it changes how hard you are supervised.
NIS2 covers entities across its listed sectors by sector and size, and most established critical-infrastructure operators - energy, transport, water, digital infrastructure and the like, sit clearly within it.
Within scope, NIS2 sorts entities into two tiers: essential and important. Critical-infrastructure operators in the most significant sectors will typically fall on the essential side, which carries the heavier consequences - proactive supervision rather than reactive, higher maximum penalties, and the sharper end of the personal-liability provisions.
One Irish wrinkle worth knowing: Ireland has adopted a federated supervisory model, with the NCSC as lead authority and specific sectors overseen by their own regulators.
Which regulator you answer to depends on your sector, so part of knowing your obligations is knowing who supervises you.
What you will owe
The obligations for an in-scope operator sit where they do across all of NIS2: the risk-management measures and the reporting duty, with board-level accountability over both.
The risk-management measures, under Article 21, are a broad set covering risk analysis, incident handling, business continuity, supply-chain security, access control, encryption, training and more - proportionate to the risk the operator carries.
For critical infrastructure the proportionality cuts one way: the more essential the service, the higher the bar. An operator whose disruption would have serious knock-on effects is expected to hold itself to a correspondingly high standard.
The reporting duty, under Article 23, runs on a staged timeline - an early warning, a fuller notification, and a final report, each within a set window from the point of awareness.
In Ireland this reporting will run through CSIRT-IE once the mechanisms are live; until the Bill is enacted, the formal registration and reporting portals are not yet operating, which is itself a reason to have the internal capability ready rather than assuming there is nothing to do yet.
Over both sits Article 20: the management body has to approve the measures, oversee them, and undertake training, and can be held accountable for failures. For a critical-infrastructure board, that is the provision that turns NIS2 from an operational programme into a personal one.
The gap: the AI inside the systems NIS2 governs
Here is the part that is easy to miss, because it is newer than the directive. NIS2's obligations attach to the network and information systems supporting your services. Increasingly, those systems contain AI, and the AI is often the part of the estate the operator has least visibility into.
A critical-infrastructure operator can have a mature, well-documented security programme and still have AI features running inside its tools that never went through that programme: an analytics platform that switched on a predictive model, a vendor tool that added an AI feature, an internal automation someone built.
Each is part of the systems NIS2 governs, each falls under the Article 21 measures, supply-chain security especially - and each is exactly the kind of thing a board is unknowingly vouching for when it approves the measures under Article 20.
This is not a reason to fear AI. It is a reason to make sure the AI in your estate is actually inside your NIS2 programme, not running alongside it unseen. The operators who will handle NIS2 well are the ones whose compliance covers what their systems are really doing, AI included - not the ones whose documentation describes an estate that stopped changing a year ago.
Where to start, as an Irish operator
The practical first move is not to wait, and not to boil the ocean either.
Establish three things, in order: whether you are in scope and in which tier, so you know the standard you are held to; who your competent authority is under Ireland's federated model, so you know whom you answer to; and where your Article 21 obligations currently stand against the NCSC's published expectations, so you have a gap list rather than a blank page.
That is a scoped, finishable exercise, and it can be done now, against guidance that already exists, without waiting for the Bill.
The operators who come out of Ireland's transposition well will not be the ones who waited for certainty. They will be the ones who treated the published expectations as the real deadline, and who made sure their picture of their own systems, AI included, was accurate before anyone asked them to prove it.
Frequently asked questions
Does NIS2 apply in Ireland if the law hasn't been enacted yet?
Montro's read: the obligations are set by the EU directive, and the National Cyber Security Centre has already published the governance and risk-management expectations it intends to supervise against - so critical-infrastructure operators should treat themselves as effectively in scope even though Ireland's transposing law, the National Cyber Security Bill, is not yet enacted.
Waiting for enactment is not the safe option, because the standard is already knowable and the enforcement framework is being built.
Which Irish regulator supervises NIS2?
Ireland has adopted a federated model. The National Cyber Security Centre is the lead competent authority and CSIRT-IE handles incident response, but certain sectors are overseen by their own sectoral regulators.
Which authority a given operator answers to depends on its sector, so identifying your competent authority is part of establishing your obligations.
Are Irish critical-infrastructure operators essential or important entities?
Most established critical-infrastructure operators in the most significant sectors will fall into the essential tier, which carries proactive supervision, higher maximum penalties and the sharper end of the personal-liability provisions.
Some operators, depending on sector and size, may be classified as important instead. The tier determines how closely you are supervised and how hard non-compliance is penalised, so it is worth establishing early.
How does AI affect NIS2 compliance for critical infrastructure?
AI features running inside your systems are part of the network and information systems NIS2 governs, so they fall under the Article 21 risk-management measures and the board's Article 20 oversight - including the supply-chain security dimension where the AI comes from a vendor.
The practical risk is that AI often enters the estate without going through the security programme, meaning a board can be approving measures that do not actually cover part of what its systems are doing. Ensuring the AI in your estate is inside your NIS2 programme, not running alongside it, is the gap most operators have not yet closed.





