Ireland published its National Cyber Security Strategy 2030 on October 7th, covering threat detection, NIS2, research, AI and post-quantum. Its priorities mirror France's 2026-2030 strategy and open a real window for Franco-Irish cooperation before Dublin picks its priority partners in 2027.
Threat detection, NIS2, research, artificial intelligence, post-quantum cryptography: with its National Cyber Security Strategy 2030, published on 7 October 2026, Ireland is changing scale. Its priorities overlap widely with those of France's 2026-2030 strategy and, for the first time, outline a genuine cyber cooperation agenda between Paris and Dublin.
Ireland holds a unique place in Europe's digital landscape. It hosts the European headquarters of many technology giants, is a major hub for international data flows and concentrates infrastructure whose importance extends far beyond its borders.
This economic asset has a downside. The strategy acknowledges it: Ireland's pivotal position in global data flows and its status as a digital hub expose it to direct and indirect targeting, by cyber criminals, the foremost threa, as well as by state-aligned actors. The Irish still remember the ransomware attack that crippled the IT systems of their public health service (HSE) in May 2021.
That is what is at stake in the National Cyber Security Strategy 2030, presented on 7 October 2026 by the Minister for Justice, Home Affairs and Migration, Jim O'Callaghan. It was unveiled on the margins of the National Cyber Security Conference, the centrepiece of the “Cyber Week” held in Dublin under Ireland's Presidency of the Council of the EU. Its vision: to build a secure, resilient digital infrastructure that protects Irish society while fostering innovation, a strong indigenous cyber ecosystem and cooperation with European and international partners.
The conference programme alone sums up today's issues: digital sovereignty and supply chain security, EU certification, operational cooperation, cyber diplomacy, subsea cable resilience, AI and post-quantum. The final text, adopted after a public consultation that drew 241 submissions this summer, is backed by more than €30 million of investment under the National Development Plan.
The strategy above all marks a shift in substance. Cyber security is no longer just about protecting IT systems: it becomes a lever of economic policy, national security, research and technological sovereignty.
For France, the timing is ideal. Since January 2026, Paris has been implementing its own National Cybersecurity Strategy 2026-2030, which aims to make France a “first-rank cyber nation”. The two countries start from very different positions, but their priorities converge on many issues.
The Irish strategy is built on three pillars and sets out 29 measures, each with a lead body, a deadline and performance indicators. Its logic is simple: see the threat better, respond better, strengthen the resilience of economic actors and, in parallel, develop Irish cyber skills, research and industry.
Ireland — NCSS 2030 | France — SNC 2026-2030 | |
Published | 7 October 2026 | 29 January 2026 |
Structure | 3 pillars, 29 measures | 5 pillars, 14 objectives |
Pillars | Detect and Defend; Enhance National Resilience; Strengthen Our Cyber Ecosystem | Talent; national resilience; disrupting the threat; mastering digital foundations; European and international cooperation |
Lead authority | NCSC (Department of Justice, Home Affairs and Migration) | ANSSI, under the SGDSN |
NIS2 framework | CyFun, a European framework Ireland co-owns; national certification scheme due Q3 2027 | ReCyF, published March 2026 |
Research | Cyber Security Research Centre of Excellence (site selected Q2 2028) | PEPR Cybersécurité (€65m over six years) |
Post-quantum | Transition framework for Departments Q1 2027; high-risk use cases migrated by 2030 (EU target) | Inventory 2026-2027; post-quantum encryption required across the State from 2030 |
Ecosystem | Cyber Ireland; SME Cyber Research Innovation Fund | Campus Cyber and its regional network |
The starting assessment is clear-eyed. The high level of digitalisation of the Irish economy mechanically widens the attack surface. Heavy reliance on remotely hosted services, embedded AI and third-party technologies increases interdependencies between sectors. The text identifies three systemic risks: the geopolitical environment, emerging technologies and supply chains. These are precisely the areas where links with France become interesting.
One of the most structural projects is the creation of a National Detection Network. The diagnosis is candid: detection remains scattered across organisations and sectors, and there is no comprehensive national sensor network covering critical services. The text even admits that Ireland is not yet self-reliant in threat detection: it sometimes learns about threats to its own systems from third parties. Without the ability to correlate these signals, the strategy warns, the State risks missing the early signs of a hybrid operation combining cyber attacks, information campaigns and physical sabotage.
The future network will aggregate telemetry from different sectors, with threat hunting, anomaly detection, malware analysis and information-sharing capabilities. It will be complemented by a National Cyber Hub linked to the EU Cyber Solidarity Act mechanisms, and by stronger cyber threat intelligence (CTI) and vulnerability coordination capabilities. The target date is Q4 2030.
This is natural ground for dialogue with France. ANSSI and CERT-FR have long experience in detection, incident response and running a national ecosystem. The French strategy makes disrupting the cyber threat one of its five pillars and aims to strengthen information-sharing between public and private actors.
An ANSSI–NCSC dialogue on threat knowledge, detection architectures, CTI sharing and crisis management would therefore be a first concrete area of cooperation. It would build on European networks where both agencies already sit, such as CyCLONe for crisis management. And it would be best started now, while the Irish system is being designed, rather than once it is complete. Detection companies from both countries could be involved.
The other major transformation is regulatory. According to the strategy, the NIS2 Directive will bring around 4,500 entities across 18 sectors under Irish cyber supervision.
Ireland's specificity goes further. Under the EU main establishment principle, Dublin will supervise, on behalf of the whole Union, cloud and digital service providers whose main establishment is on its territory. Ireland thus fully embraces its ambition to be a digital regulatory hub.
Both countries share one difficulty: they have fallen behind in transposing NIS2. Ireland was referred to the Court of Justice of the EU in July 2026; the National Cyber Security Bill, which is to transpose the Directive and put the NCSC on a statutory footing, is still being drafted. In France, the Resilience Bill has also been delayed.
In the meantime, each country has adopted an operational framework:
• In France, since 17 March 2026 ANSSI has made available the Référentiel Cyber France (ReCyF), which lists the measures it recommends to meet NIS2 security objectives. Not mandatory by default, it will allow entities that apply it to rely on it during inspections. A tool lets users compare it with other standards and frameworks.
• In Ireland, the NCSC relies on CyberFundamentals (CyFun), a framework originally developed in Belgium, which Ireland adopted and became a co-owner of in 2025. The strategy makes it the basis of the national voluntary certification scheme, due in Q3 2027, and then the common assessment framework for NIS2 entities by 2030.
This is where a very concrete bridge appears: ANSSI has begun mapping ReCyF against CyFun. The Irish strategy itself invites this, presenting CyFun as a scheme co-owned with “like-minded European Member States” and designed to support cross-border harmonisation. This work could become the basis of a Franco-Irish dialogue on maturity assessment, certification, SME support, supply chain security and the interplay between NIS2 and the Cyber Resilience Act.
The stakes are very practical for the many companies active in both countries. A French group operating in Ireland, or an Irish group present in France, would benefit greatly from knowing that compliance in one country largely counts in the other. As EU regulation becomes denser, cooperation could thus move beyond exchanges between agencies to become a dialogue on the regulation of trusted technologies.
One of the most interesting elements of the Irish strategy is the creation of a Cyber Security Research Centre of Excellence, already announced in February 2026 in the Digital Ireland digital and AI strategy. The aim is not merely academic.
The diagnosis is unusually frank. Ireland has pockets of world-class research, but none of its universities produces globally recognised cyber security research at scale. Research remains fragmented, with no ecosystem effect and no academic partner of critical mass.
The future centre will bring together research, industry, government and critical infrastructure operators. Its themes: quantum-safe cryptography, AI-driven cyber security, cloud and edge computing security, secure IoT, 6G applications, nanotechnology and biophysical computing. It may host a national cyber range, a platform simulating complex environments for research, training and exercises. Its stated mission: to turn research results into commercial prototypes and policy recommendations.
The timeline is gradual. A steering group of government, industry and academia is preparing the project; Government approval is expected by end-2027 and the site selection in Q2 2028. The centre will scale up from 2029, with an explicit mission to build international research networks and increase Irish participation in EU programmes.
The match with France is strong. Led by CEA, CNRS and Inria and operated by the French National Research Agency (ANR), the PEPR Cybersécurité programme invests €65 million over six years to structure upstream research and foster breakthrough technologies. It brings together around 200 permanent researchers and some twenty universities and schools, and is set to train around 140 PhD students by 2028. Its work covers the security of the three layers of cyberspace: hardware, software and data.
Rather than waiting for the Irish centre to be fully launched, cooperation could begin during its design phase. Links between the NCSC, Research Ireland and the centre's future teams on one side, and CEA, CNRS, Inria and French universities on the other, would help prepare Horizon Europe and Digital Europe projects or Marie Skłodowska-Curie doctoral networks. Existing bilateral instruments, such as the Ulysses Hubert Curien partnership, can serve as a starting point.
This is where bilateral cooperation is most useful: building consortia before European calls are published, rather than trying to assemble them a few weeks before the deadline.
One topic deserves particular attention: post-quantum cryptography. The Irish strategy explicitly describes the store now, decrypt later risk: a hostile actor can store encrypted communications today in order to decrypt them once a sufficiently powerful quantum computer becomes available.
The NCSC is therefore tasked with drawing up a national roadmap for the transition to post-quantum cryptography, with deadlines for public bodies and critical infrastructure. The first milestone is a transition framework for Government Departments in Q1 2027. This national roadmap fits within the one jointly adopted by EU Member States in 2025, which aims to address the highest-risk use cases by 2030. A working group bringing together government, industry and academia is to be set up in Q2 2027.
The French timeline is remarkably close. ANSSI estimates that the migration will take more than a decade and has long recommended anticipating it. Published in April 2026, the French State's digital security roadmap sets precise milestones: an inventory of long-term sensitive data by end-2026, identification of technical building blocks by end-2027 and, from 2030, the exclusive deployment of encryption products that integrate post-quantum cryptography. For businesses, Campus Cyber published a migration guide in 2026, drafted by its dedicated working group.
It is hard to imagine better ground for Franco-Irish cooperation. A joint initiative could bring together agencies, laboratories and companies around demonstrators in telecommunications, financial services, energy, health or public services.
It would have another merit: bringing together two communities that still too often work separately, quantum technologies and cyber security. Both countries have a national quantum strategy on which such an initiative could build. On the Irish side, the strategy cites the new Rinn Quantum centre, which puts cryptography at the heart of its work, the CONNECT centre, and the European quantum key distribution project TransEuroOGS, linked to the Eagle-1 satellite.
The Irish strategy gives significant weight to artificial intelligence. It notes that AI lowers the expertise needed to carry out certain attacks, allows them to be automated at scale and creates new vulnerabilities when integrated into critical systems. But it also sees AI as a defensive tool: the NCSC plans to use it to improve detection, triage and incident response.
The text observes that the most advanced AI models already outperform humans in some benchmarked cyber security tests and can chain vulnerabilities together to build complex exploits. In response, an interdepartmental AI–cyber forum will be created alongside the future AI Office of Ireland, following the EU Action Plan on Cybersecurity and Artificial Intelligence released in July 2026.
This twin movement — AI for cyber security, cyber security for AI — should become one of the most fertile fields of European scientific and industrial cooperation. It ties in directly with the French objective of mastering essential digital foundations and critical technologies. France also has a dedicated institute for AI evaluation and security, INESIA: a natural counterpart for Irish teams.
The document's other message is economic. Ireland does not only want to secure the large infrastructure located on its territory: it wants to develop an indigenous cyber ecosystem, with more Irish skills, research and companies. The strategy provides for dedicated SME support, openly licensed security tools and an SME Cyber Research Innovation Fund, with the target of 5,000 SMEs using the tools it funds by 2030.
The country starts from a real base. According to the national cluster Cyber Ireland, the sector employed more than 7,300 professionals in nearly 500 companies in 2022, and could reach 17,000 jobs by 2030.
This ambition echoes the evolution of France's Campus Cyber. Its 2026-2028 roadmap, adopted in January, seeks to make it a “pivot operator” for the national strategy and the European digital sovereignty agenda. It brings together government services, large groups, SMEs, start-ups, research bodies and training institutions, and is developing a network of European hubs.
A partnership between Campus Cyber and Cyber Ireland could support cross-acceleration programmes, access to major buyers, pilot projects with critical infrastructure operators and joint applications to European calls.
The stakes go beyond the two national markets. The French strategy makes structuring a European market for cyber security products and services one of its objectives. The aim is to keep technologies, skills and intellectual property in Europe.
Finally, Paris and Dublin share a similar view of the international framework. Ireland reaffirms its commitment to an open, free, peaceful and secure cyber space, to international law and to EU, UN and OSCE mechanisms. It notes that multilateral deadlock is leading like-minded states to develop more cyber dialogues and bilateral capacity-building partnerships.
The French strategy follows a similar logic: European and international cooperation is a pillar in its own right, in support of European strategic autonomy. The timing is right, as the EU27 negotiate the revision of the Cybersecurity Act and Ireland holds the Council Presidency.
Above all, the strategy announces for Q3 2027 an international engagement framework that will prioritise exchanges with “key like-minded partner countries”. Only one country is named: the United Kingdom, with which Dublin will hold regular meetings on skills, awareness and research. For France, the window is open: the goal is to be among these priority partners before the framework is finalised.
The political ground is there. It now needs to be turned into projects.
France and Ireland differ in size, institutional architecture and cyber capabilities. It would be artificial to try to transpose the French model to Dublin. The complementarity lies elsewhere.
France brings long-built institutional, scientific and industrial depth around ANSSI, public research, cyber defence and a substantial industrial base. Ireland offers an exceptional position at the heart of Europe's digital economy, a highly international environment and a strategy that now seeks to turn this position into national capabilities.
Five projects could quickly give shape to this convergence:
1. A regular ANSSI–NCSC dialogue on threats, detection architectures, CTI sharing and crisis management, to place France among the priority partners of Ireland's international engagement framework due in 2027.
2. A ReCyF–CyFun mapping, to simplify NIS2 compliance for companies active in both countries.
3. Cooperation between the future Irish Centre of Excellence and the PEPR Cybersécurité, starting at the design stage, with a view to European consortia.
4. Joint post-quantum demonstrators in telecommunications, finance, energy, health or public services.
5. Industrial bridges between Campus Cyber and Cyber Ireland: cross-acceleration, pilots with critical operators, joint applications.
But it would be worth going one step further. Cyber security, artificial intelligence and quantum technologies are still too often handled in separate forums, while the boundaries between them are becoming increasingly porous. The Irish strategy shows this clearly, and Campus Cyber has understood it by preparing platforms dedicated to AI and quantum.
Ultimately, the goal may be less to create a new bilateral initiative devoted strictly to cyber security than to build a Franco-Irish axis for trusted digital technologies, combining cyber security, AI security and quantum-safetechnologies.
Ireland now seeks to move from being a major platform of Europe's digital economy to being an actor able to understand, regulate and secure that environment. For France, this is precisely the moment when cooperation becomes worthwhile.
• Department of Justice, Home Affairs and Migration — National Cyber Security Strategy 2030 (October 2026)
• Irish Presidency of the Council of the EU — National Cyber Security Conference (7 October 2026)
• gov.ie — Digital Ireland, cyber security chapter (February 2026)
• gov.ie — New guidance and Cyber Fundamentals framework
• SGDSN — National Cybersecurity Strategy 2026-2030 (English version)
• cyber.gouv.fr — Stratégie nationale de cybersécurité 2026-2030
• cyber.gouv.fr — NIS 2 Directive and ReCyF
• ANSSI / Numeum — NIS 2: lançons collectivement la dynamique de sécurisation (April 2026)
• cyber.gouv.fr — French State digital security roadmap 2026-2027
• CNRS — The Cybersecurity PEPR
• Campus Cyber — 2026-2028 roadmap (press release, January 2026)
• Campus Cyber — Post-quantum cryptography migration guide (2026)
• Enterprise Ireland — Cyber Ireland cluster strategy to 2030