The European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify measures transposing the NIS2 Directive โ Directive (EU) 2022/2555 on securing network and information systems โ into national law. The decision, taken on 8 July 2026, is the Commission's first referral of member states to the Court over NIS2 and escalates an infringement procedure that had been running since late 2024.
Member states had until 17 October 2024 to transpose the Directive. Most complied; these four did not notify full transposition. The Commission's escalation path is documented: letters of formal notice on 28 November 2024, then reasoned opinions on 7 May 2025, then referral. The referrals ask the Court to impose financial sanctions โ a lump sum plus daily penalties until complete transposition is notified, which is the mechanism that gives the action teeth beyond a declaratory judgment.
| Attribute | Detail |
|---|---|
| Action | Referral to the Court of Justice of the EU |
| Decision date | 2026-07-08 |
| Member states | Ireland, Spain, France, the Netherlands |
| Instrument | NIS2 Directive (EU) 2022/2555 |
| Transposition deadline missed | 2024-10-17 |
| Prior steps | Formal notice 2024-11-28; reasoned opinion 2025-05-07 |
| Sanctions sought | Lump sum plus daily penalties |
| Infringement case refs | INFR(2024)0279 (IE), 0270 (ES), 0274 (FR), 0288 (NL) |
Why it matters
NIS2 sets cybersecurity standards for entities across 18 critical sectors, including health, energy, transport and the public sector, so transposition is the step that converts an EU directive into enforceable national obligations on operators. A member state that has not notified transposition has no national regime for those entities to comply with, which is why the Commission treated the delay as a compliance failure rather than an administrative one.
The four states are not a random set: they include three of the EU's larger economies and one โ the Netherlands โ whose national cyber security centre is an active participant in the same vulnerability-warning cycle this wiki tracks elsewhere (see the NCSC-NL warning on the two Check Point VPN flaws, check-point-patches-two-cvss-9-8-vpn-certificate-flaws-allowing-unauthenticated-rce.md). The enforcement action is a regulatory signal rather than a technical incident: no system was compromised, and the exposure it describes is the absence of a legal regime rather than a control failure. It is recorded here because it is the EU's clearest escalation to date on NIS2 compliance and because the daily-penalty mechanism creates a recurring driver for transposition timelines across the bloc.
Sources
- European Commission press release IP/26/1499 โ official referral decision
- Commission digital-strategy announcement โ 8 July 2026
- Digest reference:
raw/digests/Cyber-Digest-2026-07-18.md
Related concept: nis2-directive.md. Note the digest entry that carried this story on 18 July 2026 cited the Hunton privacy blog's index page rather than the article โ the official Commission release above supersedes that citation.