NIS2 in Ireland:not yet transposed — the Commission referred Ireland to the EU Court of Justice on 8 July 2026

Know which EU rules apply
and what to do first

GDPR, NIS2, the EU AI Act and DORA — answered for your organisation in plain English: which apply, which obligations matter most, and the first steps, each linked to the text of the law. A compliance support tool, not legal advice.

Find out in 5 minutes — free. No credit card, no consultant fees, no jargon.

4
Frameworks covered
GDPR · NIS2 · AI Act · DORA
24h
NIS2 early warning
DORA: 4h after classifying a major incident
2 Dec 2027
AI Act high-risk rules
Moved by the Digital Omnibus (2026)

No credit card required • Results in 5 minutes • EU data residency • Assessments free

PRODUCT PREVIEW — dashboard launches with paid plans
app.guardai.work/dashboard
GuardAI Dashboard
OverviewRegulationsActionsReports
GDPR Score
82%
+12%
NIS2 Score
61%
+8%
AI Act
44%
NEW
Overall Risk
63%
↑ Improving
Priority Actions (3 Critical)
CriticalComplete NIS2 risk register documentationNIS2
HighUpdate data processing agreements with suppliersGDPR
MediumSchedule cybersecurity awareness trainingNIS2
🇮🇪 Built for Irish SMEs🏦 CBI-Aligned DORA Templates🔒 EU Data Residency📋 NIS2 Ready⚖️ GDPR Compliant🤝 DPC Guidelines Followed
Every rule
Linked to its source
GuardAI assessment
Free
Time to first gap map
5 minutes

The EU Compliance Crisis

Multiple regulations converging in 2026. Irish businesses face unprecedented compliance burden.

GDPR

Data Protection • Since 2018
  • €20M max fine or 4% global turnover
  • Irish DPC fined Meta €1.2bn in May 2023 — the largest GDPR fine to date
  • Report personal data breaches to the DPC within 72 hours
  • Other infringements: up to €10m or 2%
🎯 Applies to: ANY business handling EU personal data

NIS2

Cybersecurity • Expected 2026
  • Essential entities: €10m or 2%; important: €7m or 1.4%
  • Incident early warning within 24 hours
  • 10 risk-management measures (Art. 21)
  • Management must approve and oversee measures (Art. 20)
🎯 Applies to: medium and large organisations in 18 sectors (generally 50+ staff or over €10m turnover)

AI Act

AI Regulation • Aug 2026
  • €35m or 7% for prohibited practices
  • Prohibitions in force since 2 Feb 2025
  • High-risk rules from 2 Dec 2027 (Annex III)
  • Transparency duties (Art. 50) on original schedule
🎯 Applies to: Any business deploying/using AI systems

DORA

Financial Resilience • ACTIVE Since Jan 2025
  • Sanctions set nationally — CBI holds full enforcement powers
  • 5 pillars: ICT risk, third-party, incidents, testing, oversight
  • CBI reporting: strict incident notification windows
  • Board accountability: mandatory senior mgmt oversight
🎯 Applies to: ALL CBI-regulated banks, credit unions, insurers

Penalties are set per regulation and per breach, and most organisations are nowhere near the maximums. What matters is which obligations apply to you — that is what the assessment answers.

Choose Your Compliance Path

Start free in 5 minutes. Know exactly where you stand.

SME Edition

For Irish businesses & tech companies

GDPRNIS2AI Act
  • 5-Minute Assessments
    Plain-English questions mapped to the regulation texts
  • Instant Score & Gap Analysis
    See exactly which requirements you meet — and which you don't
  • Prioritised Action Plan
    Every gap ranked by severity, with the obligation it comes from
  • Free NIS2 Checklist
    The 10 Article 21 measures explained, by email
Free
Paid plans from €29/month launch Q4 2026 — assessments are free today
🎯 Get Your Free SME Score →
Takes 5 minutes • No credit card

Financial Institution

For banks, credit unions & insurers

DORA Coverage:
  • ICT Risk Management
  • Third-Party Risk Tracking
  • Incident Management & CBI Reporting
  • Resilience Testing Management
  • Board Oversight Dashboards
  • Free Five-Pillar Gap Assessment
    Mapped to the DORA regulation text and ESA guidance
  • Pillar-by-Pillar Scoring
    See which of the five pillars need attention first
  • Prioritised Remediation List
    Every gap tied to the DORA article it comes from
Free
Full platform (from €1,000/month) launches 2027 — assessment is free today
🏦 Start Free DORA Assessment →
Takes 5 minutes • No credit card

GuardAI vs Hiring a Consultant

Why most Irish SMEs can't afford the traditional approach.

Feature
GuardAI
Compliance Consultant
Initial gap assessmentAbout 10 minutesScoped per engagement
CostFree (paid plans from €29/mo at launch)Quoted per engagement
GDPR + NIS2 + AI Act + DORA✅ All coveredTypically one specialism
Available 24/7✅ Always on❌ Business hours only
Instant action plan✅ ImmediateWeeks of consulting
No extra charge for new regulations✅ Included❌ New engagement required
Irish-specific guidance✅ DPC, CBI alignedDepends on firm
Re-run as you close gaps✅ Unlimited, freeNew engagement each time
🎯 Get Your Free Score in 5 Minutes →

No credit card · Results in 5 minutes · EU data residency

Why Irish Businesses Can Trust It

Built on the regulation texts — not marketing claims.

The free assessment maps your answers against the actual regulation texts — NIS2's 10 risk-management measures, DORA's five pillars, GDPR's core articles — and shows every gap with the article it comes from.

B
Built on the regulations themselves
Checkable against the source
GDPR · NIS2 · DORA

The assessment is free and takes about 10 minutes. It tells you which frameworks apply, the obligations that matter most for you, and the first steps — each linked to the regulation text.

C
Consultant-grade starting point
Free assessment
10 minutes

No fake reviews here — we don't publish testimonials we can't verify. Run the free assessment on your own business and judge the output yourself.

H
Honesty policy
Judge it on the report
Free

Compliance in 3 Simple Steps

No legal expertise required. Plain-English questions mapped directly to the regulation texts.

1
🎯

5-Minute Assessment

Answer plain-English questions mapped to GDPR, NIS2, AI Act or DORA requirements.

2
📊

Instant Scoring

Get your compliance score (0–100%) with gap analysis. See exactly where you are vulnerable.

3
✅

Prioritised Action Plan

Every gap ranked by severity with the requirement it comes from — re-run free as you close them.

4
EU Regulations Covered
€0
Cost of Every Assessment
5 min
Assessment Time
24/7
Available Whenever You Are

Where these facts come from

Last reviewed 25 September 2026. GuardAI is a compliance support tool, not legal advice — check the source, and take advice for decisions that carry legal risk.

GDPR

In force

Applies: 25 May 2018 · Maximum: Up to €20m or 4% of worldwide annual turnover, whichever is higher

NIS2

EU directive in force; not yet transposed in Ireland

Applies: Transposition deadline 17 October 2024 · Maximum: Essential entities: at least €10m or 2% of turnover; important entities: at least €7m or 1.4% (maximums set by national law)

  • Member States had to transpose NIS2 by 17 October 2024. Directive (EU) 2022/2555 — EUR-Lex
  • Ireland has not yet enacted its transposing law (the National Cyber Security Bill). On 8 July 2026 the Commission referred Ireland to the Court of Justice for incomplete transposition. NCSC — NIS2
  • Covers medium and large entities (generally 50+ staff or over €10m turnover and balance sheet) in 18 sectors, split into essential and important entities. NIS2 Art. 2–3 & Annexes I–II
  • Management bodies must approve and oversee cybersecurity risk measures and can be held liable (Art. 20). NIS2 Art. 20

EU AI Act

In force; obligations phasing in

Applies: Prohibitions 2 February 2025; GPAI 2 August 2025; high-risk 2 December 2027 / 2 August 2028 · Maximum: Prohibited practices: up to €35m or 7% of worldwide turnover

  • Prohibited AI practices and AI-literacy duties have applied since 2 February 2025; general-purpose AI model rules since 2 August 2025. Regulation (EU) 2024/1689 Art. 113
  • The Digital Omnibus on AI (adopted July 2026) moved high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products (Annex I). Council press release, 7 May 2026
  • Transparency duties for certain AI systems (Art. 50) remain on their original schedule. Regulation (EU) 2024/1689 Art. 50
  • Fines up to €35m or 7% for prohibited practices; €15m or 3% for most other obligations (Art. 99). AI Act Art. 99

DORA

Applies since 17 January 2025

Applies: 17 January 2025 · Maximum: Set nationally. In Ireland the Central Bank can impose up to €10m or 10% of annual turnover

  • DORA applies to EU financial entities from 17 January 2025. Regulation (EU) 2022/2554 — EUR-Lex
  • Major ICT incidents: initial notification within 4 hours of classification (and no later than 24 hours after becoming aware), intermediate report within 72 hours, final report within one month. DORA RTS/ITS on incident reporting
  • Penalty levels are set by Member States. Ireland’s implementing S.I. uses the Central Bank’s administrative sanctions regime: up to €10m or 10% of turnover for firms. A&L Goodbody — Irish DORA S.I.

Frequently Asked Questions

Does NIS2 apply to my Irish business?↓

NIS2 applies to Irish businesses in 18 essential and important sectors with 50+ employees or €10M+ turnover — including IT services, healthcare, energy, transport, and digital infrastructure. The NCSC estimates around 3,500 Irish entities will be in scope, up from roughly 120 under the original NIS Directive.

What is the NIS2 deadline in Ireland?↓

The EU transposition deadline was 17 October 2024. Ireland has not yet enacted its law (the National Cyber Security Bill), and on 8 July 2026 the European Commission referred Ireland to the EU Court of Justice for incomplete transposition. Once in force, fines for essential entities reach at least €10 million or 2% of worldwide turnover (€7 million or 1.4% for important entities), and management bodies must approve and oversee cybersecurity measures. In-scope organisations are already being asked for NIS2-level controls by customers and insurers.

How long does the assessment take?↓

Approximately 5 minutes. You answer plain-English questions about your business and instantly get your compliance score with a prioritised action plan.

Is my data stored in the EU?↓

Yes. All GuardAI data is processed and stored within the EU, fully compliant with GDPR data transfer restrictions.

What is the difference between GDPR and NIS2?↓

GDPR focuses on personal data protection and applies to almost all businesses. NIS2 is a cybersecurity directive requiring risk management, incident reporting, and resilience measures in critical sectors. Most Irish businesses will need to comply with both.

Start with what applies to you

DORA has applied since 17 January 2025. NIS2 is EU law already; Ireland's transposing Act is overdue.

Free to start • No credit card required • EU data residency

Free Resource

Get the NIS2 Compliance Checklist — Free

The 10 NIS2 risk-management measures explained in plain English. Plus GDPR quick-wins for Irish SMEs. No spam.

Unsubscribe anytime. EU data residency. GDPR compliant.

What to do next

Picked for what you just worked out — not a list of everything we make.