EU Takes Four Countries to Court Over NIS2 Directive Delays

The European Commission has referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union (CJEU) for failing to fully transpose the NIS2 Directive into national law. Member states were required to implement the cybersecurity rules by October 17, 2024, but these four nations have not yet notified the Commission of complete transposition, prompting the EU to seek financial penalties including lump sums and daily fines.

Enforcement of EU Cybersecurity Standards

The NIS2 Directive represents a significant upgrade to the EU’s digital defense framework. According to the European Commission, the legislation is vital for boosting the union’s overall resilience by mandating stricter risk management, incident reporting, and security obligations across 18 critical sectors. These sectors include energy, public administration, healthcare, and transport.

The Commission’s decision to move to the CJEU follows a series of formal warnings. Officials issued letters of formal notice on November 28, 2024, followed by reasoned opinions on May 7, 2025.

Risks of Fragmented Implementation

When member states fail to align their national laws with the directive, organizations operating across borders face inconsistent obligations. This inconsistency can weaken the EU’s collective incident response capacity.

Uniformity is the goal of the directive. By establishing a common baseline for cybersecurity, the EU aims to prevent "weak links" in critical supply chains. When one country lags in implementation, it potentially leaves the entire union exposed to coordinated cyber threats that target critical infrastructure.

Did you know? The NIS2 Directive aims to improve national and EU-wide cyber resilience by strengthening risk management, incident response and security obligations for public and private entities.

Future Trends in EU Cyber Governance

Frequently Asked Questions

What is the NIS2 Directive?
The NIS2 Directive is an EU law that sets common cybersecurity requirements for organizations in 18 critical sectors, such as energy, health, and public administration, to improve resilience against cyberattacks.

Understanding the New NIS2 Directive: Compliance for EU Businesses

Why was Ireland, Spain, France, and the Netherlands referred to the court?
The European Commission referred these countries to the Court of Justice of the European Union because they failed to fully transpose the directive into their national laws by the October 17, 2024, deadline.

What are the consequences for non-compliance?
The Commission has requested that the Court impose financial sanctions, including both lump-sum payments and recurring daily penalties, until the member states achieve full compliance.

How does NIS2 affect private companies?
NIS2 imposes stricter risk management and incident reporting obligations on private entities operating within the defined critical sectors, requiring them to meet the same security standards as public institutions.


Are you interested in how evolving digital policies impact your industry? Explore more insights on tech and digital diplomacy by consulting the Diplo chatbot for in-depth analysis.

Leave a Comment