Law / Ireland

National Cyber Security Bill, Incident Response Powers and Reporting Obligations

Head 15, General Scheme, National Cyber Security Bill 2024

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

Proposed: draft date not recorded.

In committee, dated 15 July 2025, as of 12 September 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

Where it has got to

The text described here is General Scheme (Heads of Bill) of the National Cyber Security Bill 2024, published 30 August 2024.

Locally, this stage is pre-legislative scrutiny of the General Scheme, before formal introduction as a Bill.

The stage above is recorded at www.oireachtas.ie.

More on this stage

An earlier round of pre-legislative scrutiny by the Joint Committee on Transport and Communications on 17 October 2024 produced no published report before the 33rd Dail was dissolved; the Joint Committee on Justice, Home Affairs and Migration received a fresh briefing on 15 July 2025 to resume that scrutiny of the same General Scheme.

The Government's Summer 2026 Legislation Programme still lists the Bill as priority drafting with work ongoing, and on 8 July 2026 the European Commission referred Ireland to the Court of Justice of the European Union for failing to notify complete transposition of the Directive.

What it requires

  • This duty does not yet bind: as of September 2026 only the General Scheme (Heads of Bill) has been published, and it has not been introduced as a Bill in either House of the Oireachtas.
  • Once enacted, it will reach your service where you are an essential or important entity under the Bill's Schedules I and II, which name an online marketplace, online search engine or cloud computing service among the digital providers it reaches expressly; the wider sector classes it also reaches (energy, transport, banking, health, drinking water and digital infrastructure, and public administration) are not raised here for the reason given on this jurisdiction's companion risk-management row.
  • Notify the CSIRT without undue delay of any incident with a significant impact on the provision of your service: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report within one month.
  • Where appropriate, notify the recipients of your service of the incident and of any measures they can take in response.
  • Expect the National Cyber Security Centre, not your own organisation, to hold the coordinated vulnerability disclosure function for a vulnerability reported about a product or service in the State.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The General Scheme's own penalty provision for a Head 15 infringement is an administrative financial penalty imposed by an adjudicator; no head reviewed here makes the infringement itself a criminal offence.

Penalty structure

Proposed and not yet in force. The same penalty provision that governs a Head 29 infringement governs a Head 15 infringement: the greater of EUR 10,000,000 or at least 2 percent of worldwide turnover for an essential entity, and the greater of EUR 7,000,000 or at least 1.4 percent for an important entity, mirroring NIS2 Article 34(4) and (5).

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The National Competent Authority the General Scheme would designate per sector under Head 17, with the National Cyber Security Centre's CSIRT receiving and handling the notification.

Settledness

As of
12 September 2026
Guidance link
https://www.ncsc.gov.ie/nis2/
Guidance body
National Cyber Security Centre (NCSC), Department of Justice, Home Affairs and Migration
Open questions
Will the enacted Act's coordinated vulnerability disclosure function under Head 16 impose any duty directly on the manufacturer of the affected product, or does it remain a duty on the NCSC alone to coordinate a disclosure it receives?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Head 15 of the General Scheme would require an essential or important entity to notify the CSIRT, without undue delay, of any incident with a significant impact on the provision of its service, submitting an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report within one month, on the same clock NIS2 Article 23 sets.

Where appropriate, the entity must also notify the recipients of its service of the incident and of any mitigating measures they can take. Head 16 would separately give the NCSC a coordinated vulnerability disclosure function for a vulnerability reported about any product or service in the State, a duty the General Scheme places on the NCSC rather than on the product's manufacturer.

This duty does not yet bind: the General Scheme has undergone pre-legislative scrutiny but has not been introduced as a Bill in either House of the Oireachtas.

When LexLint raises it

  • operates_social_platform

Read the law

General Scheme (Heads of Bill), Department of Justice, Home Affairs and Migration, published 30 August 2024
not yet introduced as a Bill

Back to the example  ·  Lint your app