European Commission takes Ireland, Spain, France, and the Netherlands to court over delayed NIS2 cybersecurity law rollout

The European Commission has referred Ireland, Spain, France, and the Netherlands to the EU’s top court for failing to put the NIS2 cybersecurity directive into national law. NIS2 sets minimum cybersecurity, risk-management, and incident-reporting rules for 18 critical sectors including hospitals, energy, transport, and public administration; the four countries are more than 20 months past the October 2024 transposition deadline, and the Commission is seeking lump-sum and daily fines until they comply.
Why it matters: Organizations in affected EU countries face continued legal uncertainty around security and incident-reporting duties for critical services. This matters to governments, regulated operators, and suppliers because NIS2 underpins how Europe enforces baseline cyber defenses for critical infrastructure.

Sources

EU takes member states to court over unimplemented cybersecurity law
2026.07.09 100% relevant
This article establishes a distinct enforcement milestone in the NIS2 rollout: the Commission has moved from warnings and delays to formal court action and proposed financial penalties against specific member states.
← Back to all stories