Infosecurity

EU sues four member states over NIS2 cybersecurity law delays

Published

on

Brussels turns up the heat on laggards

The European Commission has filed legal referrals at the EU’s top court against four member states for failing to implement the bloc’s flagship cybersecurity law covering critical infrastructure. Ireland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 cybersecurity law, which sets minimum security standards for hospitals, energy networks, transport operators and public administrations.

The Commission has asked the Court of Justice of the European Union to impose a lump sum and ongoing daily financial penalties on all four countries until each formally notifies full transposition. The move, announced Wednesday, marks a rare escalation in the EU’s enforcement of digital rules.

Why NIS2 matters now

NIS2 is an update of the original Network and Information Security Directive of 2016, a law that covered fewer sectors and was applied unevenly across the bloc. The newer directive widened its scope to 18 critical sectors and added risk management and incident reporting requirements that were not included in the original directive.

Few member states met the original October 2024 deadline for transposing NIS2 into domestic legislation. As of January 2025, only six of the EU’s 27 member states had transposed the directive. The delays have left glaring gaps in the bloc’s cyber defenses.

European officials have cast the risk in increasingly stark terms. Speaking in Munich in February, the Commission’s technology lead, Henna Virkkunen, warned the European Union could no longer afford to be “naive” about adversaries’ ability to switch off critical infrastructure, saying that power grids, hospitals and financial systems were all increasingly exposed.

Fines: real teeth or paper tiger?

In practice, the fines being sought by the Commission are rarely paid. Member states in previous cases have generally adopted the required legislation while proceedings are under way, prompting the Commission to withdraw before the court makes a ruling.

That pattern could repeat here. Ireland said its National Cyber Security Bill, which will transpose NIS2 and place the country’s National Cyber Security Centre on a statutory footing, is close to finalization, with the minister responsible expecting to notify transposition by end of 2026. Spain, France and the Netherlands had not published comparable statements at the time of writing.

The threat landscape: incidents are climbing

The filing comes as ENISA, the EU’s cybersecurity agency, has warned of thousands of cybersecurity incidents affecting the bloc in the year ending June 2025. ENISA identified public administration as the most-targeted critical sector at 38% of incidents, followed by transport at 7.5%.

Those numbers explain the urgency. A single breach in a hospital network can disrupt patient care; a compromised energy grid can shut down entire regions. The NIS2 rules are designed to force member states to take basic precautions seriously.

What NIS2 actually requires

  • Risk management measures across 18 critical sectors
  • Mandatory incident reporting to national authorities
  • Supply chain security for ICT products and services
  • Board-level accountability for cyber risks

NIS2 also underpins a broader legislative program on cybersecurity. The EU’s Cyber Resilience Act, which imposes security requirements on connected products and whose vulnerability-reporting obligations begin to apply in 2027, relies on the national response-team network that NIS2 establishes.

What’s next for the directive

In January, the Commission proposed revising the EU’s Cybersecurity Act to strengthen ENISA and reduce risks in critical technology supply chains, including a provision that would see member states phase out designated high-risk suppliers such as Huawei and ZTE from critical infrastructure.

Separately, the Commission proposed targeted amendments to NIS2 to provide greater legal clarity and ease compliance for companies — issues which officials have said contributed to delays in transposing the updated directive. Those amendments could soften some of the more burdensome requirements, but they don’t change the core obligations.

For businesses operating across the EU, the message is clear: NIS2 isn’t going away. Even if the court cases drag on, the directive’s requirements will eventually apply everywhere. Companies that haven’t started mapping their compliance obligations should treat this as a wake-up call.

The Commission’s legal action is a signal that Brussels is losing patience. Whether the fines ever get paid is almost beside the point. The real pressure is political and reputational — and for the four countries named, the clock is ticking.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version