Back to all guides

Ireland Incorporation Guide for Foreign Cybersecurity Companies

How a foreign cybersecurity company can establish in Ireland: subsidiary or branch, CRO filing, directors, NIS2, GDPR, export controls, tax and banking.

August 11, 2026 13 min read Editorial update

By the StartCompany.ie editorial team. Last updated August 11, 2026. Check current regulatory guidance at the CRO and Revenue.

Foreign cybersecurity founders planning Irish company incorporation with an adviser in Dublin
Cybersecurity founders should decide the Irish legal structure and regulatory perimeter before filing the incorporation documents.

Ireland can be used as an EU base by a foreign cybersecurity consultancy, software vendor, managed security provider or international security group. The incorporation mechanics are similar to other Irish businesses, but the operating plan deserves additional work: cyber services may involve sensitive customer systems, personal data, regulated-sector clients, controlled technology and demanding insurance or procurement terms.

This Ireland incorporation guide for a foreign cybersecurity company separates the company-law filing from those operational obligations. Incorporation creates the entity. It does not certify the product, prove NIS2 compliance, authorise controlled exports or guarantee a bank account.

Start with the legal route

A foreign founder can normally form a new Irish LTD with foreign shareholders. An existing foreign company may instead register an Irish branch where it establishes one in the State. A subsidiary is a separate Irish company; a branch remains part of the overseas company. Decide between them before preparing CRO documents or customer contracts.

Irish subsidiary or foreign-company branch?

An Irish LTD can contract, employ staff, own intellectual property and incur liabilities in its own name. The foreign parent may own all its shares. The LTD has its own CRO, RBO, tax, accounting and annual-return obligations.

A branch is not a new company. CRO guidance states that a company incorporated outside Ireland that establishes a branch in the State must register it. EEA companies generally use Form F12 and non-EEA companies Form F13, with constitutional, incorporation and accounting documents and certified translations where required. Review our subsidiary versus branch guide before choosing.

Core requirements for a new Irish LTD

  • A suitable company name and LTD constitution.
  • A physical registered office address in Ireland.
  • At least one director and a company secretary; a sole director cannot also be secretary.
  • An EEA-resident director or an available statutory alternative, commonly a Section 137 bond for a new company.
  • Accurate shareholder, share-capital and beneficial-owner information.
  • PPSN or the applicable IPN identity route for relevant directors and beneficial owners.
  • A truthful description of the cybersecurity activity and its Irish operations.

The incorporation filing uses CRO Form A1 and the constitution. Foreign ownership does not remove the requirement for an activity in Ireland, and a registered office alone should not be described as operational substance.

Define the cybersecurity service precisely

“Cybersecurity” can mean penetration testing, incident response, managed detection, security monitoring, identity tools, secure software, training, governance consulting or resale of third-party products. The exact description affects contracts, data protection, insurance, export screening, NIS2 analysis and the evidence a bank may request.

Write a one-page service map covering what systems the company accesses, whether it stores customer logs or credentials, where staff and infrastructure are located, which countries receive services, and whether the company can make changes inside customer environments. This is more useful than a broad technology label.

NIS2 and managed security services

The National Cyber Security Centre's NIS2 guidance names managed service providers and managed security service providers among the categories that can fall within the regime. Scope depends on the service, establishment, sector, size rules and current Irish implementation. Some entities can fall within specific rules regardless of ordinary size thresholds.

Do not assume every cyber consultancy is in scope, and do not assume a small business is always outside scope. Check the NCSC's current legislation, registration and risk-management guidance when the company launches and as it grows. Regulated customers may also impose equivalent controls contractually even where the supplier itself is not directly in scope.

GDPR, customer data and security evidence

A cybersecurity provider may process employee identifiers, IP addresses, authentication logs, incident records or customer communications. The Data Protection Commission explains that organisations must use appropriate technical and organisational security measures, considering confidentiality, integrity, availability and resilience.

Determine whether the Irish company is a controller, processor or both for each service. Where it processes personal data for a customer, the GDPR requires an appropriate controller-processor contract. Prepare access controls, retention rules, incident handling, subprocessors, transfer mechanisms and deletion procedures before promising them in a sales agreement.

Export controls and cybersecurity technology

Ireland's Department of Enterprise explains that export controls can apply to dual-use software and technology, including certain cyber-surveillance items, technical assistance and transfers of controlled information. Most ordinary cyber services are not automatically controlled, but product capability, end user, destination and intended use matter.

Screen products and destinations before exporting security software, exploit tooling, interception capability, cryptographic technology or technical assistance. Use the Department's current export-control guidance and obtain specialist classification advice where the technology may be dual use.

Tax, VAT and payroll setup

Incorporation is separate from Revenue registration. The company should assess Corporation Tax, VAT and PAYE based on its actual activity, staff and transactions. Cross-border B2B cyber services often require careful place-of-supply, reverse-charge and invoice analysis. Intellectual-property ownership and transactions with a foreign parent also need arm's-length documentation and appropriate tax advice.

Use the Irish company tax-registration checklist and do not advertise Ireland's trading tax rate without confirming that the income and management facts support the treatment.

Banking, insurance and customer contracts

  • Prepare ownership, source-of-funds, customer and expected-transaction evidence for banking.
  • Explain high-risk jurisdictions, digital assets or security-testing payments before onboarding.
  • Review professional indemnity, cyber liability and employer insurance with a suitable broker.
  • Define authorised testing, scope, customer permission, liability limits and incident escalation in contracts.
  • Keep intellectual-property assignments and foreign-parent licences consistent with the operating model.
  • Maintain an evidence pack for security policies, staff screening, access control and subcontractors.

Foreign cybersecurity company launch checklist

  1. Choose an Irish subsidiary or registered branch with legal and tax advice.
  2. Define the services, customer sectors, infrastructure, data flows and export countries.
  3. Prepare the Irish address, officers, ownership, identity route and CRO filing.
  4. Assess NIS2, GDPR, customer-sector regulation and export controls.
  5. Register applicable taxes and prepare compliant invoices and bookkeeping.
  6. Arrange banking, insurance, employment documents and customer contracts.
  7. Complete RBO and first-year CRO obligations for an Irish subsidiary.

StartCompany.ie can help with the incorporation layer while specialist advisers address regulation, tax and contracts. Review non-resident formation or send us the proposed ownership and director countries for a practical starting route.

Frequently asked questions

Can a foreign cybersecurity company incorporate in Ireland?

Yes. Foreign owners can establish an Irish subsidiary, and an existing overseas company that establishes an Irish branch may need to register that branch with the CRO. The right route depends on liability, contracts, tax, staffing, regulation and group structure.

Does an Irish cybersecurity company need a special licence?

There is no single incorporation licence covering every cybersecurity business. However, the services, customers and technology may bring NIS2, GDPR, sector regulation, export controls, professional requirements or contractual security standards into scope. Obtain specialist advice for the actual offering.

Does NIS2 apply to cybersecurity service providers in Ireland?

The NCSC identifies managed service providers and managed security service providers among the NIS2 categories. Scope depends on the service, establishment, size rules and current Irish implementation. Check the NCSC's live guidance rather than deciding from the company name alone.

Can a foreign founder own all the shares in an Irish cybersecurity company?

Irish company law does not generally require Irish shareholders. A foreign person or company can own the shares, but the company must separately satisfy director-residence, registered-office, identity, RBO, tax and banking requirements.

Should a foreign cybersecurity business use an Irish subsidiary or branch?

A subsidiary is a separate Irish legal entity, while a branch is part of the foreign company. Compare liability, customer contracting, accounts, tax, governance, funding and group reporting before choosing.

Ready to form your Irish company?

Compare the four formation routes or ask us which package fits your directors and address requirements.