EU Refers Ireland, Spain, France, Netherlands to CJEU for NIS2 Non-Transposition — Enforcement Phase Has Arrived
The European Commission on July 8, 2026 referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to notify the Commission of full NIS2 Directive transposition into national law. The referral is a CJEU Article 258 infringement proceeding — available remedies include financial penalties against member states and a binding order to complete transp
BY FRONTIER DESK · JULY 16, 2026 · 1 MIN READ
The European Commission on July 8, 2026 referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to notify the Commission of full NIS2 Directive transposition into national law. The referral is a CJEU Article 258 infringement proceeding — available remedies include financial penalties against member states and a binding order to complete transposition. NIS2 (Directive 2022/2555), which entered into force on January 16, 2023 and required full transposition by October 17, 2024, establishes cybersecurity risk management and incident reporting obligations across 18 critical sectors, including financial market infrastructure, digital infrastructure (cloud, data centres, CDN, trust services), healthcare, energy, and transport. For legal risk teams advising regulated clients in Ireland, Spain, France, and the Netherlands: NIS2 as transposed by each member state carries direct civil and criminal liability for senior management, and non-transposition does not eliminate the obligation where member states have issued partial implementing legislation. Clients in these four jurisdictions should assess their NIS2 compliance posture based on each country's partial or draft implementing measures rather than waiting for confirmed full transposition — and should monitor CJEU proceedings for the timing of any financial penalty order that could trigger accelerated national implementation.