Four member states, one court, one daily fine
· Cryptaguard · 7 min read
In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice over NIS2, asking for financial sanctions. The penalties fall on the states. The obligations, awkwardly, do not wait for them.
On 8 July 2026 the European Commission referred four member states to the Court of Justice of the European Union for failing to notify complete transposition of NIS2: Ireland, Spain, France and the Netherlands. It asked the Court to impose financial sanctions — a lump sum, plus a daily penalty accruing until each state notifies.
This is not a surprise ending. It is the third act of a procedure that has been running in public since 2024, and the interesting question is not why the Commission acted but what it means for an entity that operates in one of the four.
How a directive deadline becomes a court case
Article 41 of NIS2 gave member states until 17 October 2024 to adopt and publish the measures necessary to comply, and to apply them from the following day. The infringement procedure that follows a missed deadline has a fixed shape.
- Letter of formal notice. Sent to 23 member states in November 2024 — an early sign of how unusual this transposition was: most directives do not miss in bulk.
- Reasoned opinion. Sent to 19 member states in May 2025, naming among others Bulgaria, Czechia, Germany, Ireland, Spain, France, Cyprus, the Netherlands, Austria, Poland, Portugal, Slovenia, Finland and Sweden. Most of that list has since transposed.
- Referral to the Court of Justice. July 2026, for the four that had still not notified.
The attrition between stages is the part worth reading. Nineteen states received a reasoned opinion; four ended up in front of the Court. The procedure worked as designed, slowly.
Article 260(3), and why it makes this faster than usual
Normally the Court rules that a member state has breached its obligations, the state does nothing, the Commission brings a second action, and only then can penalties be imposed. That is two full cases and several years.
When the Commission brings a case before the Court pursuant to Article 258 on the grounds that the Member State concerned has failed to fulfil its obligation to notify measures transposing a directive adopted under a legislative procedure, it may, when it deems appropriate, specify the amount of the lump sum or penalty payment to be paid by the Member State concerned which it considers appropriate in the circumstances.Treaty on the Functioning of the European Union
Article 260(3) exists precisely for failure to notify transposition of a legislative directive, and it lets the Court impose a financial penalty in the FIRST judgment. That is what the Commission has asked for here. A lump sum punishes the period of the breach; the daily penalty payment runs from judgment until notification, which gives it a shape governments understand — every day of further delay has a price on it.
Who pays
These sums are owed by the member state to the Union budget. No part of an article 260(3) penalty is passed to companies, and no entity is a party to the case. If you are reading this because someone told you your organisation might be fined, they have confused two entirely different regimes.
The trap: "there is no national law, so there is no obligation"
This is the reasoning that costs money, and it is wrong in three separate ways.
The directive does not vanish because it is late
A directive that has not been transposed by its deadline can still be relied on against the state and its emanations, where its provisions are unconditional and sufficiently precise. That does not conjure obligations between private parties, but it does mean that entities dealing with public bodies, and public bodies themselves, are not operating in a vacuum.
The law arrives with its own calendar, and it is short
Look at what the states that transposed late actually did. Bulgaria gave entities no transitional compliance period at all: the amended Cybersecurity Act applied on entry into force in February 2026, with only reduced sanctions for breaches committed up to 1 June 2026. Luxembourg allowed two months between entry into force on 10 May 2026 and the registration deadline of 10 July. A government that is already twenty months late is not in a generous mood about your own runway.
The obligations are not national inventions
The ten measures of article 21(2) are the same in all 27 member states. Where transposition differs is in registration channels, supervisory bodies, reporting portals, national frameworks and the occasional additional obligation — Belgium adds an eleventh measure. The core of the work does not depend on your national law existing, which means the interval before it arrives is buildable time, not waiting time.
What each of the four looks like now
The Netherlands has effectively resolved its side: the Cyberbeveiligingswet entered into force on 15 August 2026, five weeks after the referral was filed and one day after the Senate vote that preceded it. The case nonetheless remains open, because a referral ends on notification of complete transposition, and outstanding ministerial regulations are part of what has to be notified. Entry into force and notification are not the same event.
France has a bill that has been in parliament since 2024 — the loi résilience, which transposes NIS2, the critical entities resilience directive and DORA in a single text. The Sénat adopted it at first reading in March 2025 and the Assemblée nationale special committee reported in September 2025. A public session was announced for July 2026 and promulgation was widely expected over the summer; at the time of writing nothing has been promulgated and the legislative file still shows that committee report as its most recent step. ANSSI has meanwhile opened a pre-registration portal, which is the pragmatic move: register now, classify now, argue later.
Spain is further back. The Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers in January 2025 and had still not entered parliamentary procedure. Entities in Spain are working directly from the directive and from sector guidance, which is the least comfortable position in the Union.
Ireland carries a particular irony: it co-owns the CyberFundamentals scheme and offers it as a national assessment framework while its own transposing law is still pending. You can get assessed in Ireland today against a framework Ireland helped build. You cannot yet read the Irish obligations it is meant to evidence.
- Do not read a missing national law as a missing obligation. The article 21(2) measures are identical in all 27.
- Build against the directive now. Late transposing states have granted short or no transitional periods.
- In France, register on the ANSSI portal ahead of the law — it costs nothing and fixes your classification.
- Remember that article 260(3) penalties fall on the member state. No entity is a party to these cases.
- Track notification, not entry into force. That is the event that closes an infringement referral.