NIS2 Transposition — Expected By End 2026
00
d
00
h
00
m
00
s

Don't Risk a
€10 Million Fine

The NCSC estimates 3,500–6,000 Irish entities will fall under NIS2 alone — and GDPR and the AI Act reach almost every business. Is yours one of them? Once transposed, non-compliance can mean fines up to €10M and personal liability for management.

Find out in 5 minutes — free. No credit card, no consultant fees, no jargon.

€10M
Max NIS2 Fine
Or 2% global revenue
€20M
Max GDPR Fine
Or 4% global revenue
24hrs
Incident Deadline
NIS2 & DORA mandatory

No credit card required • Results in 5 minutes • EU data residency • Assessments free

PRODUCT PREVIEW — dashboard launches with paid plans
app.guardai.work/dashboard
GuardAI Dashboard
OverviewRegulationsActionsReports
GDPR Score
82%
+12%
NIS2 Score
61%
+8%
AI Act
44%
NEW
Overall Risk
63%
↑ Improving
Priority Actions (3 Critical)
CriticalComplete NIS2 risk register documentationNIS2
HighUpdate data processing agreements with suppliersGDPR
MediumSchedule cybersecurity awareness trainingNIS2
🇮🇪 Built for Irish SMEs🏦 CBI-Aligned DORA Templates🔒 EU Data Residency📋 NIS2 Ready⚖️ GDPR Compliant🤝 DPC Guidelines Followed
Compliance consultant gap analysis
€5,000–€50,000
GuardAI assessment
Free
Time to first gap map
5 minutes

The EU Compliance Crisis

Multiple regulations converging in 2026. Irish businesses face unprecedented compliance burden.

GDPR

Data Protection • Since 2018
  • €20M max fine or 4% global turnover
  • Irish DPC fined Meta €1.2B in 2023 — the largest GDPR fine ever
  • Data breach notification: 72 hours
  • DPC enforcement: Active audits in 2026
🎯 Applies to: ANY business handling EU personal data

NIS2

Cybersecurity • Expected 2026
  • €10M max fine or 2% global turnover
  • Incident reporting: 24 hours early warning
  • 18 mandatory measures required
  • Management personally liable — up to temporary bans
🎯 Applies to: an estimated 3,500–6,000 Irish entities in essential/important sectors (NCSC)

AI Act

AI Regulation • Aug 2026
  • €35M max fine or 7% global turnover
  • Risk categorization: 4 levels
  • High-risk AI: conformity assessment required
  • User disclosure obligations mandatory
🎯 Applies to: Any business deploying/using AI systems

DORA

Financial Resilience • ACTIVE Since Jan 2025
  • Sanctions set nationally — CBI holds full enforcement powers
  • 5 pillars: ICT risk, third-party, incidents, testing, oversight
  • CBI reporting: strict incident notification windows
  • Board accountability: mandatory senior mgmt oversight
🎯 Applies to: ALL CBI-regulated banks, credit unions, insurers
Maximum Combined Penalties — GDPR + NIS2 + AI Act
€65M+

Non-compliance across the three capped regimes alone — before DORA sanctions and personal liability for management

Choose Your Compliance Path

Start free in 5 minutes. Know exactly where you stand.

SME Edition

For Irish businesses & tech companies

GDPRNIS2AI Act
  • 5-Minute Assessments
    Plain-English questions mapped to the regulation texts
  • Instant Score & Gap Analysis
    See exactly which requirements you meet — and which you don't
  • Prioritised Action Plan
    Every gap ranked by severity, with the obligation it comes from
  • Free NIS2 Checklist
    18 mandatory measures explained, delivered by email
Free
Paid plans from €29/month launch Q4 2026 — assessments are free today
🎯 Get Your Free SME Score →
Takes 5 minutes • No credit card

Financial Institution

For banks, credit unions & insurers

DORA Coverage:
  • ICT Risk Management
  • Third-Party Risk Tracking
  • Incident Management & CBI Reporting
  • Resilience Testing Management
  • Board Oversight Dashboards
  • Free Five-Pillar Gap Assessment
    Mapped to the DORA regulation text and ESA guidance
  • Pillar-by-Pillar Scoring
    See which of the five pillars need attention first
  • Prioritised Remediation List
    Every gap tied to the DORA article it comes from
Free
Full platform (from €1,000/month) launches 2027 — assessment is free today
🏦 Start Free DORA Assessment →
Takes 5 minutes • No credit card

GuardAI vs Hiring a Consultant

Why most Irish SMEs can't afford the traditional approach.

Feature
GuardAI
Compliance Consultant
Initial gap assessment5 minutes4–8 weeks
CostFree (paid plans from €29/mo at launch)€5,000–€50,000+
GDPR + NIS2 + AI Act + DORA✅ All coveredTypically one specialism
Available 24/7✅ Always on❌ Business hours only
Instant action plan✅ ImmediateWeeks of consulting
No extra charge for new regulations✅ Included❌ New engagement required
Irish-specific guidance✅ DPC, CBI alignedDepends on firm
Re-run as you close gaps✅ Unlimited, freeNew engagement each time
🎯 Get Your Free Score in 5 Minutes →

No credit card · Results in 5 minutes · EU data residency

Why Irish Businesses Can Trust It

Built on the regulation texts — not marketing claims.

"The free assessment maps your answers against the actual regulation texts — NIS2's 18 mandatory measures, DORA's five pillars, GDPR's core articles — and shows every gap with the article it comes from."

B
Built on the regulations themselves
Checkable against the source
GDPR · NIS2 · DORA

"A compliance consultant typically charges €1,200+ per day for a gap analysis. GuardAI's assessment is free, takes about 10 minutes, and gives you the same starting map."

C
Consultant-grade starting point
Free assessment
10 minutes

"No fake reviews here — we don't publish testimonials we can't verify. Run the free assessment on your own business and judge the output yourself."

H
Honesty policy
Judge it on the report
Free

Compliance in 3 Simple Steps

No legal expertise required. Plain-English questions mapped directly to the regulation texts.

1
🎯

5-Minute Assessment

Answer plain-English questions mapped to GDPR, NIS2, AI Act or DORA requirements.

2
📊

Instant Scoring

Get your compliance score (0–100%) with gap analysis. See exactly where you are vulnerable.

3

Prioritised Action Plan

Every gap ranked by severity with the requirement it comes from — re-run free as you close them.

4
EU Regulations Covered
€0
Cost of Every Assessment
5 min
Assessment Time
24/7
Available Whenever You Are

Frequently Asked Questions

Does NIS2 apply to my Irish business?

NIS2 applies to Irish businesses in 18 essential and important sectors with 50+ employees or €10M+ turnover — including IT services, healthcare, energy, transport, and digital infrastructure. The NCSC estimates roughly 3,500–6,000 Irish entities will be in scope, up from ~120 under NIS1.

What is the NIS2 deadline in Ireland?

The EU deadline was October 2024, but Ireland has not yet transposed NIS2. The National Cyber Security Bill is before the Oireachtas, and the Minister for Justice expects transposition to be notified by end of 2026. Once in force, fines reach €10M or 2% of global turnover, with personal liability for management.

How long does the assessment take?

Approximately 5 minutes. You answer plain-English questions about your business and instantly get your compliance score with a prioritised action plan.

Is my data stored in the EU?

Yes. All GuardAI data is processed and stored within the EU, fully compliant with GDPR data transfer restrictions.

What is the difference between GDPR and NIS2?

GDPR focuses on personal data protection and applies to almost all businesses. NIS2 is a cybersecurity directive requiring risk management, incident reporting, and resilience measures in critical sectors. Most Irish businesses will need to comply with both.

Don't Wait for a Fine

DORA enforcement is active now. NIS2 transposition is expected in 2026.

Free to start • No credit card required • EU data residency

Free Resource

Get the NIS2 Compliance Checklist — Free

18 mandatory NIS2 measures explained in plain English. Plus GDPR quick-wins for Irish SMEs. No spam.

Unsubscribe anytime. EU data residency. GDPR compliant.