
Ireland can be used as an EU base by a foreign cybersecurity consultancy, software vendor, managed security provider or international security group. The incorporation mechanics are similar to other Irish businesses, but the operating plan deserves additional work: cyber services may involve sensitive customer systems, personal data, regulated-sector clients, controlled technology and demanding insurance or procurement terms.
This Ireland incorporation guide for a foreign cybersecurity company separates the company-law filing from those operational obligations. Incorporation creates the entity. It does not certify the product, prove NIS2 compliance, authorise controlled exports or guarantee a bank account.
Start with the legal route
A foreign founder can normally form a new Irish LTD with foreign shareholders. An existing foreign company may instead register an Irish branch where it establishes one in the State. A subsidiary is a separate Irish company; a branch remains part of the overseas company. Decide between them before preparing CRO documents or customer contracts.
Irish subsidiary or foreign-company branch?
An Irish LTD can contract, employ staff, own intellectual property and incur liabilities in its own name. The foreign parent may own all its shares. The LTD has its own CRO, RBO, tax, accounting and annual-return obligations.
A branch is not a new company. CRO guidance states that a company incorporated outside Ireland that establishes a branch in the State must register it. EEA companies generally use Form F12 and non-EEA companies Form F13, with constitutional, incorporation and accounting documents and certified translations where required. Review our subsidiary versus branch guide before choosing.
Core requirements for a new Irish LTD
- A suitable company name and LTD constitution.
- A physical registered office address in Ireland.
- At least one director and a company secretary; a sole director cannot also be secretary.
- An EEA-resident director or an available statutory alternative, commonly a Section 137 bond for a new company.
- Accurate shareholder, share-capital and beneficial-owner information.
- PPSN or the applicable IPN identity route for relevant directors and beneficial owners.
- A truthful description of the cybersecurity activity and its Irish operations.
The incorporation filing uses CRO Form A1 and the constitution. Foreign ownership does not remove the requirement for an activity in Ireland, and a registered office alone should not be described as operational substance.
Define the cybersecurity service precisely
“Cybersecurity” can mean penetration testing, incident response, managed detection, security monitoring, identity tools, secure software, training, governance consulting or resale of third-party products. The exact description affects contracts, data protection, insurance, export screening, NIS2 analysis and the evidence a bank may request.
Write a one-page service map covering what systems the company accesses, whether it stores customer logs or credentials, where staff and infrastructure are located, which countries receive services, and whether the company can make changes inside customer environments. This is more useful than a broad technology label.
NIS2 and managed security services
The National Cyber Security Centre's NIS2 guidance names managed service providers and managed security service providers among the categories that can fall within the regime. Scope depends on the service, establishment, sector, size rules and current Irish implementation. Some entities can fall within specific rules regardless of ordinary size thresholds.
Do not assume every cyber consultancy is in scope, and do not assume a small business is always outside scope. Check the NCSC's current legislation, registration and risk-management guidance when the company launches and as it grows. Regulated customers may also impose equivalent controls contractually even where the supplier itself is not directly in scope.
GDPR, customer data and security evidence
A cybersecurity provider may process employee identifiers, IP addresses, authentication logs, incident records or customer communications. The Data Protection Commission explains that organisations must use appropriate technical and organisational security measures, considering confidentiality, integrity, availability and resilience.
Determine whether the Irish company is a controller, processor or both for each service. Where it processes personal data for a customer, the GDPR requires an appropriate controller-processor contract. Prepare access controls, retention rules, incident handling, subprocessors, transfer mechanisms and deletion procedures before promising them in a sales agreement.
Export controls and cybersecurity technology
Ireland's Department of Enterprise explains that export controls can apply to dual-use software and technology, including certain cyber-surveillance items, technical assistance and transfers of controlled information. Most ordinary cyber services are not automatically controlled, but product capability, end user, destination and intended use matter.
Screen products and destinations before exporting security software, exploit tooling, interception capability, cryptographic technology or technical assistance. Use the Department's current export-control guidance and obtain specialist classification advice where the technology may be dual use.
Tax, VAT and payroll setup
Incorporation is separate from Revenue registration. The company should assess Corporation Tax, VAT and PAYE based on its actual activity, staff and transactions. Cross-border B2B cyber services often require careful place-of-supply, reverse-charge and invoice analysis. Intellectual-property ownership and transactions with a foreign parent also need arm's-length documentation and appropriate tax advice.
Use the Irish company tax-registration checklist and do not advertise Ireland's trading tax rate without confirming that the income and management facts support the treatment.
Banking, insurance and customer contracts
- Prepare ownership, source-of-funds, customer and expected-transaction evidence for banking.
- Explain high-risk jurisdictions, digital assets or security-testing payments before onboarding.
- Review professional indemnity, cyber liability and employer insurance with a suitable broker.
- Define authorised testing, scope, customer permission, liability limits and incident escalation in contracts.
- Keep intellectual-property assignments and foreign-parent licences consistent with the operating model.
- Maintain an evidence pack for security policies, staff screening, access control and subcontractors.
Foreign cybersecurity company launch checklist
- Choose an Irish subsidiary or registered branch with legal and tax advice.
- Define the services, customer sectors, infrastructure, data flows and export countries.
- Prepare the Irish address, officers, ownership, identity route and CRO filing.
- Assess NIS2, GDPR, customer-sector regulation and export controls.
- Register applicable taxes and prepare compliant invoices and bookkeeping.
- Arrange banking, insurance, employment documents and customer contracts.
- Complete RBO and first-year CRO obligations for an Irish subsidiary.
StartCompany.ie can help with the incorporation layer while specialist advisers address regulation, tax and contracts. Review non-resident formation or send us the proposed ownership and director countries for a practical starting route.