A fixed-scope, 90-day assessment for Irish organisations in scope of NIS2. You leave with a clear position, an executive report your board can act on, and a prioritised roadmap. No open-ended consultancy.
Ireland has not yet enacted the National Cyber Security Bill that transposes NIS2, but the pressure to do so is now coming from Brussels and the obligations are arriving by other routes.
The date by which every member state was to have NIS2 in national law. Ireland's National Cyber Security Bill remains unenacted.
The National Cyber Security Centre sets out what it expects of management boards in NIS2-scope organisations: cyber risk owned and overseen at the highest level of executive management.
The European Commission refers Ireland to the Court of Justice of the EU for failing to transpose NIS2.
The Bill can be enacted at any point, and the obligations it carries will not come with a grace period.
Organisations that assess now choose their own timetable. Those that wait will be working to someone else's.NIS2 reaches well beyond the utilities and infrastructure operators covered by the first directive. Most medium and large organisations in these sectors are in scope, and smaller organisations can be brought in where they provide a critical service.
The directive treats cybersecurity as a governance matter. Three articles carry most of the weight for senior management, and the penalties sit alongside them.
The management body must approve the organisation's cyber risk-management measures, oversee their implementation, and can be held liable for failures. Board members must undertake cybersecurity training.
Supervisors will expect to see this recorded: decisions, minutes, evidence of oversight.
Ten mandatory measures: risk analysis and policies, incident handling, continuity and crisis management, supply-chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication.
Each must be proportionate to your exposure and demonstrable on request.
A significant incident must be reported with an early warning within 24 hours, a notification within 72 hours, and a final report within one month.
That clock only works if you already know what counts as significant, who decides, and how the report is made.
Up to €10 million or 2% of global turnover for essential entities; up to €7 million or 1.4% for important entities, whichever is higher.
Authorities can also suspend certifications and, for essential entities, temporarily bar individuals from management roles.
The reason is rarely a lack of technology. It is that nobody has measured the organisation against the directive, evidence is scattered across teams and suppliers, and the board has never been given a view it can understand and sign off. That is a governance gap, and it can be closed in 90 days.
Fixed scope. Fixed duration. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.
A documented view of whether you are in scope, as an essential or important entity, and which obligations follow.
What the organisation relies on, where it is exposed, and what an incident would mean for it.
Your position against Articles 20, 21 and 23, evidenced and mapped to NIST CSF 2.0 and CyFun.
Your assessment, gaps and evidence on CyberPrism for the duration of the programme.
Written for a board, not an IT department. Where you stand, what matters most, and what closing the gaps will take.
Actions ordered by exposure and effort, with owners and timeframes your team can commit to.
A session with your board or executive team, meeting the expectation that management understands and oversees cyber risk.
ThreatLens matches current threat activity and vulnerabilities to where you are weakest, so the roadmap reflects what is happening now.
CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.
The assessment is anchored on NIST CSF 2.0 and includes the CyFun framework recommended by the National Cyber Security Centre, so your position is expressed in terms Irish regulators already use. The same platform carries overlays for DORA, the EU AI Act and other regimes — which matters if NIS2 is not the only obligation you face.
The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.
Keep your CyberPrism environment live. Track remediation, re-assess quarterly, receive ongoing threat intelligence and advisory, and give your board a standing view rather than an annual snapshot. This is the position supervisors will expect once the Bill is enacted.
Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.
Because the obligations are already arriving by other routes. The NCSC has published what it expects of boards. Customers and insurers are writing NIS2 clauses into contracts. And the European Commission is pursuing Ireland through the Court of Justice, which makes enactment a matter of when. Organisations that assess now choose their own timetable.
Typically a few hours a week from a coordinator, plus short sessions with the people who own each area — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports.
Those are good foundations and the assessment credits them. NIS2 adds obligations they do not cover — board accountability, incident reporting timelines, supply-chain measures — and asks for those to be evidenced in the regulator's terms. The assessment shows exactly where your existing certification carries you and where it does not.
No. It is a readiness assessment. Its purpose is to give you an accurate position and a plan before any supervisor asks. The evidence base it produces is, however, what you would draw on if one did.
That is settled in the first two weeks. If it turns out you are not in scope, we will tell you — and you will still hold a clear view of your exposure and a short list of sensible actions.
Yes, and usually should be. They hold much of the evidence and will deliver part of the roadmap. We work alongside them; the assessment sits above the technology, not in competition with it.
The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.
A 30-minute scoping call is enough to confirm whether you are in scope, what the assessment would cover for you, and when it could start.