17 July 2026

COMMISSION REFERS MEMBER STATES TO COURT OF JUSTICE OVER NIS2 TRANSPOSITION

Last week, the European Commission has decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify the full transposition of the NIS2 Directive into national law.

The Directive, which had to be transposed by 17 October 2024, establishes a common EU framework to strengthen cybersecurity across 18 critical sectors, including transport and energy. It introduces enhanced cybersecurity risk management requirements and incident reporting obligations for both public and private entities operating in essential and important sectors.

The referrals follow the launch of infringement proceedings in November 2024 and the issuance of reasoned opinions in May 2025. The Commission is requesting that the Court impose financial penalties, including lump-sum payments and daily fines, until the four Member States notify the complete transposition of the Directive.

The Commission underlines that the timely implementation of the NIS2 Directive is essential to strengthen the resilience of critical infrastructure and improve the EU's capacity to prevent and respond to growing cybersecurity threats.

Source: European Commission