National Cyber Security Bill, Cybersecurity Risk-Management Measures
Head 29, General Scheme, National Cyber Security Bill 2024
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Proposed: draft date not recorded.
In committee, dated 15 July 2025, as of 12 September 2026.
A sector security regimes rule binding public and private bodies.
As of 12 September 2026.
Where it has got to
The text described here is General Scheme (Heads of Bill) of the National Cyber Security Bill 2024, published 30 August 2024.
Locally, this stage is pre-legislative scrutiny of the General Scheme, before formal introduction as a Bill.
The stage above is recorded at www.oireachtas.ie.
An earlier round of pre-legislative scrutiny by the Joint Committee on Transport and Communications on 17 October 2024 produced no published report before the 33rd Dail was dissolved; the Joint Committee on Justice, Home Affairs and Migration received a fresh briefing on 15 July 2025 to resume that scrutiny of the same General Scheme.
The Government's Summer 2026 Legislation Programme still lists the Bill as priority drafting with work ongoing, and on 8 July 2026 the European Commission referred Ireland to the Court of Justice of the European Union for failing to notify complete transposition of the Directive.
What it requires
- This duty does not yet bind: as of September 2026 only the General Scheme (Heads of Bill) has been published, and it has not been introduced as a Bill in either House of the Oireachtas.
- Once enacted, it will reach your service where you are an essential or important entity under the Bill's Schedules I and II, which name an online marketplace, online search engine or cloud computing service among the digital providers it reaches expressly; the wider sector classes it also reaches (energy, transport, banking, health, drinking water and digital infrastructure, and public administration) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your operations or services, with your management board approving and overseeing those measures.
- Expect your management board to be held liable for an infringement, with personal liability reaching a director or executive on a finding of gross negligence following a cybersecurity incident, according to the General Scheme's own explanatory material.
- Expect an exemption to the extent an equivalent sector-specific EU regime, such as the Digital Operational Resilience Act for a bank or financial-market-infrastructure entity, already imposes at least equivalent risk-management duties on you.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The General Scheme's own penalty provision for a Head 29 infringement is an administrative financial penalty imposed by an adjudicator; no head reviewed here makes the infringement itself a criminal offence.
Penalty structure
Proposed and not yet in force. The General Scheme's penalty provision sets the maximum financial penalty for an essential entity's infringement of Head 15 or Head 29 at the greater of EUR 10,000,000 or at least 2 percent of worldwide turnover in the preceding financial year, and a lower tier for an important entity at the greater of EUR 7,000,000 or at least 1.4 percent, mirroring NIS2 Article 34(4) and (5); the same Head exempts a public body designated under Head 23 from these penalties.
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The National Competent Authority the General Scheme would designate per sector under Head 17, with the National Cyber Security Centre serving as the State's CSIRT and single point of contact.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.ncsc.gov.ie/nis2/
- Guidance body
- National Cyber Security Centre (NCSC), Department of Justice, Home Affairs and Migration
- Open questions
- Will the enacted Act retain the General Scheme's personal liability for a director or executive on a finding of gross negligence, given NIS2 Article 34 and Recital 128 do not require a Member State to impose personal civil or criminal liability on a natural person for an entity's infringement?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Head 29 of the General Scheme would require every essential and important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its operations or services, and to prevent or minimise the impact of an incident, transposing NIS2 Article 21.
Head 28 would require the entity's management board to approve and oversee those measures and would hold the board liable for an infringement; the same Head's own explanatory note states that an organisation's management and executives can be found personally liable where gross negligence is found following a cybersecurity incident, a duty NIS2 itself does not require a Member State to impose on a natural person.
Head 25 would exempt an entity from these measures to the extent an equivalent sector-specific EU regime, such as the Digital Operational Resilience Act for a banking or financial-market-infrastructure entity, already imposes at least equivalent risk-management duties. This duty does not yet bind: the General Scheme has undergone pre-legislative scrutiny but has not been introduced as a Bill in either House of the Oireachtas.
When LexLint raises it
operates_social_platform
Read the law
General Scheme (Heads of Bill), Department of Justice, Home Affairs and Migration, published 30 August 2024
not yet introduced as a Bill