Law / Ireland

European Union (NIS) Regulations 2018, Incident Notification

S.I. No. 360/2018, Regs. 18 and 22

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 September 2018.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds a relevant digital service provider (an online marketplace, online search engine or cloud computing service under Schedule 2) and a designated operator of essential services under Schedule 1; the operator-of-essential-services sector and designation class is not separately flagged here, for the reason given on this jurisdiction's companion security-requirements row.
  • Notify the State's CSIRT without delay and in any event not later than 72 hours after becoming aware of an incident with a significant impact on the continuity of your essential service, or a substantial impact on your digital service, including an incident affecting a third-party digital service provider you rely on.
  • Notify the CSIRT again once the incident has been resolved.
  • Where the incident also compromises personal data, expect the competent authority, the CSIRT or the single point of contact to cooperate with the Data Protection Commission on it, a duty separate from your own breach-notification duty to the Commission under the General Data Protection Regulation.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A failure to notify the CSIRT under Regulation 18 or 22 is itself an offence under Regulation 34, unlike a failure to take the Regulation 17 or 21 security measures, which is enforced only through a compliance notice.

Penalty structure

Regulation 34 makes a person guilty of an offence under Regulation 18 or 22 (among others) liable, on summary conviction, to a class A fine, or, on conviction on indictment, to a fine not exceeding EUR 50,000 for an individual or EUR 500,000 for a person other than an individual.

Rule
Fixed only
As of
12 September 2026
Currency
EUR
Fixed cap
500,000

Who enforces it

Enforcement body

The Minister (or, for the banking and financial-market-infrastructure sectors, the Central Bank of Ireland) as competent authority, with the National Cyber Security Centre's CSIRT unit receiving and handling the notification.

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Regulation 18 requires a designated operator of essential services to notify the State's CSIRT, without delay and in any event not later than 72 hours after becoming aware, of an incident with a significant impact on the continuity of an essential service it provides, including an incident affecting a third-party digital service provider it relies on, and to notify the CSIRT again once the incident is resolved.

Regulation 22 imposes the equivalent duty on a relevant digital service provider for an incident with a substantial impact on a service listed in Schedule 2. The CSIRT is the unit of the State's cybersecurity department that Regulation 10 designates.

Regulation 6 requires the competent authority, the CSIRT and the single point of contact to cooperate with the Data Protection Commission where a notified incident also compromises personal data, a duty distinct from the breach-notification duty General Data Protection Regulation (GDPR) itself imposes on a controller.

When LexLint raises it

  • operates_social_platform

Read the law

Statutory Instrument text, Irish Statute Book, S.I. No. 360 of 2018

Back to the example  ·  Lint your app