Skip to content

Europe

Independent · Brussels & Berlin

Technology · Cybersecurity regulation

Ireland faces millions in EU fines over cybersecurity law delay

Four member states referred to the EU's top court for missing the NIS2 transposition deadline, with Ireland exposed to an estimated €2.8m lump sum plus daily penalties

By , Technology Editor

Published

8 min read

Ireland is staring at a financial penalty of roughly €2.8 million, plus accruing daily fines, for failing to write EU cybersecurity rules into domestic law nearly two years after the deadline to do so. The European Commission has referred the Republic, along with Spain, France and the Netherlands, to the Court of Justice of the European Union (CJEU) over the delay.

The referral concerns the NIS2 Directive, which member states were required to transpose into national law by 17 October 2024. Professional services firm Aon, which calculated the penalty estimate using the Commission's own sanctions methodology, warned this week that Ireland remains non-compliant and that daily penalties will keep mounting until the legislation is enacted.

What NIS2 demands of member states

The Network and Information Security Directive, known as NIS2, replaces the original 2016 NIS Directive and represents a substantial upgrade in how the EU approaches cybersecurity regulation. Where its predecessor covered a relatively narrow set of operators of essential services, NIS2 casts a far wider net. It brings additional sectors, including food production, chemicals, manufacturing, space and public administration, under mandatory cybersecurity obligations. It also tightens rules on incident reporting, requiring organisations to flag significant cyber incidents within tight timeframes, and it introduces personal liability for senior management bodies that fail to oversee cybersecurity risk adequately.

For Ireland, the directive will significantly expand the number of organisations subject to cybersecurity regulation. Companies that have never considered themselves part of the critical infrastructure landscape will discover they have new reporting obligations and governance requirements. Supply chains are also in scope: a medium-sized Irish firm providing services to a regulated entity may find itself subject to contractual cybersecurity clauses it has never had to meet before.

Why the transposition has stalled

The Irish Government has pointed to the complexity of the legislation as the reason for the delay. The National Cyber Security Bill, which would transpose the directive, has been working its way through the Oireachtas but has not yet completed its legislative journey. The bill must pass through several remaining stages before it can be signed into law.

Complexity is a legitimate complaint. NIS2 requires member states to define which entities fall within its scope, set proportionate regulatory regimes for different sizes and sectors, and establish enforcement mechanisms with meaningful penalties. The directive also allows member states some discretion in how they implement certain provisions, which means drafting legislation that is both compliant and workable takes time.

That said, Ireland is not alone in missing the deadline, which suggests the directive posed genuine difficulties across multiple legal traditions. Spain, France and the Netherlands are in the same position. But most member states did manage to transpose on time, which rather undermines the argument that the task was simply too difficult. The question is whether the delay reflects genuine legislative complexity or a lack of political urgency.

The awkward timing of the EU presidency

Ireland currently holds the rotating presidency of the Council of the European Union, a role that involves setting the Council's agenda, chairing ministerial meetings and representing the Council in negotiations with the European Parliament. It is an uncomfortable position for a member state that has been referred to the CJEU for non-compliance with EU law.

Aon noted the presidency in its warning, suggesting it presents an opportunity for Ireland to complete transposition and give organisations certainty about the framework that will govern cybersecurity across critical sectors. The implication is clear: a country leading the Council's legislative work should not be one of the laggards in implementing its decisions.

The presidency rotates every six months. Ireland took over from Poland in July 2026 and will hand to whichever state follows. The timing means that for the second half of 2026, Ireland is both steering EU legislative business and subject to infringement proceedings for failing to implement a major piece of that same body of law.

How the penalties are calculated

The €2.8 million figure is not a fixed fine handed down by the Court. It is an estimate derived from the Commission's standard methodology for calculating lump-sum penalties in infringement cases. The methodology takes account of the seriousness of the infringement, its duration, and the member state's ability to pay, which is itself a function of gross national income. Aon applied this methodology to estimate Ireland's exposure.

On top of the lump sum, daily penalties would accrue for every day Ireland remains in breach after a court ruling. These daily fines can reach substantial figures, particularly for prolonged non-compliance. The Commission typically proposes both a lump-sum penalty for the period of infringement up to the judgment and a daily penalty for non-compliance thereafter. The CJEU has the final say on the amounts.

A pattern of slow transposition

This is not the first time Ireland has faced financial penalties for dragging its feet on EU legislation. The State was previously hit with a €4.5 million fine for a three-year delay in transposing the European Electronic Communications Code. That directive, which updated the EU's telecoms rules, was adopted in 2018 and should have been transposed by December 2020. Ireland did not complete transposition until well after the deadline.

The recurrence raises questions about Ireland's legislative capacity and prioritisation. For a small state that has benefited enormously from EU membership, both in terms of structural funds and the single market, repeated non-compliance is an awkward look. It also carries direct financial costs that ultimately fall on taxpayers.

There are structural reasons why Ireland sometimes struggles. The Oireachtas sits relatively few days compared with many European parliaments. Government bills compete for limited parliamentary time. Coalition governments, which have been the norm in Ireland for decades, can slow legislation as parties negotiate over provisions. But these are explanations, not excuses. Other small states with similar constraints managed to transpose NIS2 on time.

What companies should be doing now

Leann Moroney, associate director for cyber risk management at Aon Ireland, was blunt about the implications. "NIS2 represents one of the most significant changes to cybersecurity regulation in recent years and will have implications for thousands of organisations across Ireland, either directly or through their supply chains," she said.

Moroney also cautioned against waiting for the legislation to be enacted before taking action. "Cyber threats are not waiting for legislation, and businesses shouldn't either," she said. "The direction of travel is already clear, and cyber risk needs to be treated as a board-level priority now."

That advice is sound, even if it comes from a firm that sells cyber risk advisory services. The core requirements of NIS2 are already known. Organisations that provide essential or important services, as the directive defines them, will need risk management measures, incident reporting procedures and governance structures that hold management to account. The Irish transposition will add domestic detail, but the substance is unlikely to diverge significantly from the directive text.

Companies that delay preparations risk finding themselves non-compliant the moment the legislation takes effect. Given that the transposition has already been delayed by nearly two years, there is a reasonable chance the Irish legislation will set a relatively short compliance window once enacted, precisely to avoid further infringement proceedings.

The CJEU referral process

A referral to the CJEU is not the beginning of the infringement process. It is the culmination. The Commission typically begins with a formal notice, giving the member state a chance to respond. If the response is unsatisfactory, the Commission issues a reasoned opinion. Only if the member state still fails to comply does the Commission refer the case to the Court. By the time a case reaches Luxembourg, the member state has already had multiple opportunities to act.

The Court can impose both a lump-sum penalty for the period of non-compliance and daily penalties until the member state conforms. The Commission's infringement proceedings are tracked publicly on its infringement proceedings database, where the current status of cases against each member state can be checked.

Sources

  1. The Irish Times

    irishtimes.com · 2026-08-24

People mentioned

  • Leann Moroney

    Associate director for cyber risk management, Aon Ireland

Organisations

European Commission · Court of Justice of the European Union · Aon Ireland

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.