XelonXelon

NIS2

Readiness, gap analysis and certification for Ireland's incoming cybersecurity law: NIS2 applicability, the CyFun framework, the NCSC Risk Management Measures and the ISO 27001 route to certification, delivered by one team.

How the frameworks connect: the NCSC Risk Management Measures, CyFun and ISO 27001 all demonstrate compliance with the NIS2 Directive, and we map your evidence so it is gathered once and counts towards each.

NIS2 readiness

The law is late. The obligations are not.

NIS2 status in Ireland, updated September 2026

The EU deadline for transposing NIS2 passed in October 2024 and Ireland has still not enacted the National Cyber Security Bill. In July 2026 the European Commission referred Ireland to the Court of Justice of the EU over the delay.

None of that means the directive can be ignored. The National Cyber Security Centre has already published governance guidance for management boards of NIS2 entities. Customers and supply chain partners in other member states are writing NIS2 obligations into contracts with Irish suppliers right now. And when the Bill is enacted, the compliance clock will start with very little warning. An estimated 4,000 Irish organisations will fall within scope, facing sanctions of up to €10 million or 2% of global turnover for essential entities, with personal accountability resting on senior management.

Organisations that treat the legislative delay as breathing space to prepare will be fine. Organisations that treat it as a reason to do nothing will be scrambling.

Applicability and scoping

Many organisations do not yet know whether they are an essential entity, an important entity or out of scope entirely. We establish your classification, identify your likely competent authority and set out your registration and reporting obligations in a short written assessment your board can rely on.

Remediation workplan

Findings become a sequenced, costed workplan with named owners and realistic timelines. We have built NIS2 workplans running to seventeen workstreams for a large public body, and we scale the same method down for organisations a fraction of that size.

Board governance and training

Article 20 of the directive places accountability on management bodies personally. Board members must approve risk management measures, oversee their implementation and undergo training. We brief boards in plain language, aligned with the NCSC's 2026 governance guidance, and document each session in the form the regulator expects to see.

Incident reporting readiness

NIS2 requires an early warning to the CSIRT within 24 hours of a significant incident and a full notification within 72. We test whether your detection, escalation and communication arrangements can actually meet those clocks, and fix the gaps before a real incident finds them for you.

CyFun: the Cyber Fundamentals Framework

The reference standard Ireland's draft legislation points to.

CyFun is the Cyber Fundamentals Framework developed by the Centre for Cybersecurity Belgium, built on NIST CSF 2.0 and mapped to ISO 27001 and CIS controls, with graduated assurance levels matched to an organisation's risk profile. It matters in Ireland for a simple reason: the draft National Cyber Security Bill recognises it as a reference standard for demonstrating NIS2 compliance, which makes it the most defensible yardstick available while the law is finalised.

We assess your current controls against CyFun at the assurance level appropriate to your classification, and we have applied the framework in practice inside a Government department, not just read the documentation. You get an honest picture of where you stand, written in plain language, rather than a scored spreadsheet nobody can act on, and because CyFun maps onto ISO 27001, the evidence you gather here counts again if certification is your next step.

NCSC Risk Management Measures

The Irish baseline your compliance will be measured against.

The National Cyber Security Centre has translated the directive's Article 21 obligations into a set of Risk Management Measures for Irish organisations, and this is the practical baseline a competent authority will hold you to. We work with these measures daily: building compliance matrices that map your existing controls to each measure, separating genuine gaps from documentation gaps, and turning the result into a phased workplan with owners, costs and timelines that a management board can approve and a regulator can follow.

Because we work across the RMMs, CyFun and ISO 27001 together, evidence is gathered once and reused across all three, rather than your team assembling the same proof three times for three different audiences.

ISO 27001 certification

Built by consultants who have carried Irish public bodies through to Stage 2 audit.

ISO 27001 certification is increasingly a condition of doing business, whether imposed by enterprise customers, public procurement or insurers. Achieving it is a project with a defined end point, not a permanent consulting relationship, and that is how we treat it.

Xelon has built information security management systems from a standing start and carried them through to Stage 2 certification audit, including for a national public body with a large and complex ICT estate. That means the documentation we produce has been tested against real assessors, not just templates.

Gap analysis and scoping

Getting the ISMS scope right at the outset largely decides whether certification is achievable on your timeline and budget. We assess where you stand against the standard, recommend a defensible scope and give you an honest estimate of the effort involved before you commit.

Building the ISMS

We produce the policies, standards and procedures the standard requires, written for your organisation rather than copied from a library. That includes the risk assessment methodology, Clause 6.2 security objectives, the Statement of Applicability and the governance structures that make an ISMS real: a security committee and management review process with terms of reference that function in practice instead of sitting in a binder.

Risk management

We build risk registers with countermeasures mapped to Annex A controls, and we have delivered large-scale migrations of legacy risk data into GRC platforms including Base27. If your risks currently live in a spreadsheet or an ageing internal app, we can move them somewhere they will survive an audit. Read about our Base27 implementation partnership.

Certification audit support

We prepare you for Stage 1 and Stage 2, assemble the evidence packs, brief the staff who will be interviewed and coordinate with the certification body across the audit days themselves. Assessors have a rhythm and a set of expectations, and having someone alongside you who knows both takes most of the fear out of the week.

After certification

Certification is the start of a three-year cycle, not the finish line. We support surveillance audits, internal audit programmes and the continual improvement record that keeps the certificate valid.

Book a NIS2 scoping call