NIS2
NIS2 Readiness as Code for Irish .NET Enterprises
NIS2 Legal Framework 2026
EU NIS2 Directive 2022/2555 - pending full transposition in Ireland via the National Cyber Security Bill 2026.
Applies to 'essential' (energy, banking, public sector) & 'important' entities (IT, cloud, MSPs) - >50 employees or >€10 M turnover.
Expected fines post‑enactment: €10 M or 2 % of global turnover. Enforcement: NCSC Ireland & DPC .
Current status: Irish law expected later 2026, with initial compliance phase extending into 2027.
5 Core Readiness Areas
Risk management (Article 21 principles)
Incident‑response readiness (24h/72h model, NCSC reporting under development)
Supply‑chain and vendor risk (Article 21.2)
Cyber awareness and training programs
Encryption and resilience testing framework
.NET 10 Incident Reporting Prototype
Microsoft.Extensions.AI + ILogger telemetry integration
Azure Monitor + Application Insights structured logging
Planned 24h/72h incident workflow → NCSC Ireland API (available after Bill enactment): https://www.dataprotection.ie/en
Automatic severity classification
HttpClient POST to NCSC test endpoint
72h detailed report template generation
Supply Chain Security
SBOM generation via dotnet list package --vulnerable
Azure Purview for vendor risk evaluation
Smart contract verification for AI providers
Zero‑trust vendor access via Entra ID and Conditional Access