Commission Refers 4 States to CJEU Over NIS2

On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to transpose the NIS2 Directive, asking the Court to impose a lump sum and daily penalties on each government until transposition is complete. NIS2 enforcement has now moved from warning letters to the CJEU, more than 20 months after the 17 October 2024 deadline. For companies in the four countries the court case is background. The live question is whether NIS2 binds you yet, and how quickly that answer changes.

The Commission Wants Fines for Four Governments and Has Named No Figures

The referral runs under Article 258 TFEU, with financial penalties requested under Article 260(3) in the form of a lump sum plus daily payments until each state notifies complete transposition. The Commission has not published the amounts it will seek. That is standard at this stage, with figures proposed to the Court later in the written procedure.

The paper trail behind the referral is long. Only Belgium, Croatia, Italy and Lithuania met the October 2024 deadline. The Commission sent letters of formal notice to 23 member states on 28 November 2024, reasoned opinions to 19 on 7 May 2025, and by this July only four had still notified nothing. A directive built around 24 hour incident reporting has now spent 20 months waiting for four governments to report anything at all. As of May 2026, 22 of 27 member states had adopted transposing legislation, with five still in procedure. Luxembourg is among the five stragglers but was not referred on 8 July.

NIS2 Still Binds Nobody in These Four Countries, Until the Day It Binds Everyone

In Ireland, Spain, France and the Netherlands, most NIS2 obligations do not yet formally bind private companies, because a member state cannot enforce a directive it has failed to transpose against businesses. The referral does not change that. National law changes it, and national law is arriving fast.

The Netherlands is the proof. The Eerste Kamer passed the Cyberbeveiligingswet on 7 July 2026, bringing more than 8,000 organisations into scope when it enters into force on 15 August 2026 with no transitional period. The Netherlands passed its NIS2 law on 7 July and was referred to the CJEU on 8 July. The grey zone can close faster than the court can convene.

The other three are behind but moving. Ireland’s National Cyber Security Bill is still in pre-legislative scrutiny and is expected before the Oireachtas by September at the earliest, with the responsible minister aiming to notify transposition by end of 2026. Spain’s cybersecurity governance bill has been stuck in a parliament without a stable majority since January 2025, yet INCIBE-CERT is already running inspections against NIS2-aligned criteria, and once published the law takes effect the following day. France bundled NIS2, CER and DORA into a single resilience bill, then stalled the whole package over an encryption backdoor clause, which is one way to make three deadlines out of one. ANSSI’s MonEspaceNIS2 platform has nonetheless accepted pre-registrations since 24 November 2025.

In our assessment, waiting for your national law is the worst available strategy in all four countries. Supply chain pressure is already contractual, because NIS2-covered customers elsewhere in the EU must manage supplier risk under Article 21 and are demanding evidence now. Registration windows will be short once laws land, as the Dutch timeline shows. And early enforcement in transposed states points the same way, with Germany’s BSI and France’s ANSSI issuing formal notices primarily for missing registrations and contact points. If you have not yet confirmed whether you count as an essential or important entity, check your status with the NIS2 Applicability Checker before your parliament decides the timetable for you.

The Poland Precedent Prices NIS2 Enforcement Delay at €50,000 a Day

Article 260(3) penalties target governments, not companies, and the closest benchmark is Commission v Poland, C-452/22, decided 14 March 2024 over the telecoms code. The Court imposed a €4 million lump sum plus €50,000 per day, with the total exceeding €10 million before Poland complied.

Two things temper the drama. CJEU proceedings of this type typically run 18 to 24 months, and member states usually adopt the missing legislation while the case is pending. Our read is that the referral’s real function is parliamentary acceleration in Dublin, Madrid and Paris, which shortens your preparation runway rather than lengthening it.

Keep the two penalty regimes separate. State fines flow from the treaty. Company fines will flow from each national law implementing Article 34 of the directive, which requires national maximums of at least €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important entities, whichever is higher, with exact ceilings varying by country. Late transposition by your government does not shrink your eventual obligation. It shrinks your preparation time.

The Preparation Window Is Now Set by Brussels, Not by Your Parliament

If you operate in Ireland, Spain, France or the Netherlands, the referral is your cue to treat national law as imminent rather than theoretical.

  1. Confirm scope first. Run your entity size and sector through the NIS2 Applicability Checker to establish whether you fall under essential or important entity rules at all.
  2. Map your security measures against the most advanced national reference already published, meaning ReCyF in France, NCSC guidance in the Netherlands or Ireland’s draft risk management guidelines. The final laws will not diverge much from these.
  3. Prepare your registration package, covering entity details, sector classification and a named contact point. Dutch voluntary registration and French pre-registration are open already, and the windows after entry into force will be measured in weeks.
  4. Brief your board on Article 20. Management liability arrives with the national law, not after a grace period.

If you operate anywhere else in the EU, audit your suppliers in these four countries. Your own Article 21 supply chain duties did not pause while their parliaments did.

The referral is one entry in a much shorter list than most compliance teams assume. We log every confirmed enforcement action across the Big 8, including per-country NIS2 transposition status and national fine ceilings, and as of July 2026 the GDPR is still the only framework with a published corporate fine.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts