Vulnerabilities

EU Takes Member States to Court Over Unimplemented NIS2 Directive

July 10, 2026 00:13 · 12 min read
EU Takes Member States to Court Over Unimplemented NIS2 Directive

The European Commission has taken a significant step towards enforcing the implementation of the NIS2 Directive, a cybersecurity law that sets minimum security standards for critical infrastructure such as hospitals, energy networks, and public administrations. On Wednesday, the Commission filed legal referrals at the EU's top court against four member states - Ireland, Spain, France, and the Netherlands - for failing to implement the directive, which is now over 20 months overdue.

Background on the NIS2 Directive

The NIS2 Directive is an update of the original Network and Information Security Directive of 2016, which covered fewer sectors and was applied unevenly across the EU. The newer directive widens its scope to 18 critical sectors and adds risk management and incident reporting requirements that were not included in the original directive. The EU's Cyber Resilience Act, which imposes security requirements on connected products, relies on the national response-team network that NIS2 establishes.

Consequences of Non-Implementation

The Commission has asked the Court of Justice of the European Union to impose a lump sum and ongoing daily financial penalties on all four countries until each formally notifies full transposition of the directive. However, in practice, these fines are rarely paid, as member states have generally adopted the required legislation while proceedings are underway, prompting the Commission to withdraw before the court makes a ruling.

The filing comes as ENISA, the EU's cybersecurity agency, has warned of thousands of cybersecurity incidents affecting the bloc in the year ending June 2025. Public administration was identified as the most-targeted critical sector, accounting for 38% of incidents, followed by transport at 7.5%. European officials have cast the risk in increasingly stark terms, with the Commission's technology lead, Henna Virkkunen, warning that the European Union could no longer afford to be "naive" about adversaries' ability to switch off critical infrastructure.

Current Status of Implementation

Ireland has stated that its National Cyber Security Bill, which will transpose NIS2 and place the country's National Cyber Security Centre on a statutory footing, is close to finalization, with the minister responsible expecting to notify transposition by the end of 2026. However, Spain, France, and the Netherlands have not published comparable statements at the time of writing.

The Commission has also proposed revising the EU's Cybersecurity Act to strengthen ENISA and reduce risks in critical technology supply chains, including a provision that would see member states phase out designated high-risk suppliers such as Huawei and ZTE from critical infrastructure. Additionally, the Commission has proposed targeted amendments to NIS2 to provide greater legal clarity and ease compliance for companies, which officials have said contributed to delays in transposing the updated directive.

The European Commission's actions demonstrate the importance of implementing the NIS2 Directive to ensure the security and resilience of critical infrastructure across the EU. As the EU continues to face increasing cybersecurity threats, the implementation of this directive is crucial to protecting the bloc's critical sectors and maintaining the trust of its citizens.

The EU's efforts to enhance cybersecurity and protect critical infrastructure are ongoing, and the implementation of the NIS2 Directive is a key step towards achieving this goal. As the EU continues to face evolving cybersecurity threats, the importance of implementing and enforcing this directive cannot be overstated.


Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free