preloader

· nis2 digital-security compliance gdpr europe regulation incident-response

Four EU States Are Now Being Sued Over NIS2. Your Compliance Deadline Has Not Moved

Source: European Commission

Cybersecurity regulation in the EU has just produced an unusual spectacle: a directive designed to protect member states from attackers is now the reason four of those member states are being taken to court by their own Commission. On 8 July, Brussels referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to notify complete transposition of the NIS2 Directive, whose deadline passed on 17 October 2024. The Commission opened infringement proceedings that November, issued a reasoned opinion in May 2025 giving each country two more months, and is now asking the Court to impose daily financial penalties until each government finishes the job.

A government’s delay is not your compliance excuse

Here is the part that matters if you run IT, security, or operations at a company in one of these four countries, or anywhere that has not yet finalised its national law: NIS2 already applies to you. The directive sets minimum cybersecurity risk-management measures and incident reporting obligations across 18 critical sectors, energy, transport, health, public administration, and digital infrastructure among them, and national transposition delay does not pause your legal exposure. Companies operating in jurisdictions with incomplete transposition are frequently left interpreting the directive’s text directly, without the clarity a finished national law would normally provide, while regulators in neighbouring countries with completed transpositions are already auditing.

The Netherlands offers a useful contrast. Its Senate approved the Cyberbeveiligingswet, the Dutch NIS2 implementation, on 7 July, one day before the Commission’s referral, with the law entering into force on 15 August. That timing shows regulators are not waiting for every country to finish before enforcement activity ramps up elsewhere: national CSIRTs across the bloc are already running systematic audits of essential entities, and the first NIS2 fines, roughly €885,000 across five member states so far, have already landed.

What “build to the directive” actually means in practice

Waiting for your national law to arrive before starting NIS2 work is a losing strategy on two fronts. First, the substantive requirements, risk analysis, incident handling, business continuity, supply chain security, multi-factor authentication, are set at EU level and unlikely to shift materially in national implementation. Second, once a transposition law does land, and courts are now actively forcing that timeline, the gap between “not yet required” and “already overdue” can close in weeks, not months, especially for entities in health, energy, transport, or public administration, sectors regulators have flagged for particular scrutiny in the second half of 2026.

If you are unsure whether your organisation falls under NIS2’s essential or important entity categories, or you know you are in scope and have not yet mapped your obligations against the directive’s actual text, contact Excello Digital. We help European businesses translate NIS2 requirements into a working security and incident response programme, regardless of where your national transposition law currently stands.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!