Four member states now face a bill that grows with every passing day, and the reason is a cybersecurity law they should have finished writing almost two years ago. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July over incomplete NIS2 transposition, and it asked the judges to impose financial sanctions immediately rather than after a second judgment.
That request is the part worth reading twice. Article 260(3) of the Treaty lets the Commission seek a lump sum and a daily penalty at the first referral, but only when a country has failed to notify its transposition measures. The provision punishes silence, not bad law. It is a blunt instrument, and the Commission has grown noticeably more willing to reach for it.
The timeline explains the impatience. The NIS2 Directive set 17 October 2024 as the transposition deadline. Formal notices went out the following month to a majority of capitals. Reasoned opinions followed on 7 May 2025, with the customary two months to respond. Fourteen months after that, four governments still had nothing complete to notify. By May 2026, twenty-two of the twenty-seven had adopted transposing legislation, which makes the remaining group look less like a systemic failure and more like a handful of stubborn legislative queues.
The Dutch case shows how thin the margin can be. Parliament in The Hague adopted its transposing law on 7 July, one day before the referral landed, with entry into force set for 15 August. Once formal notification reaches the Commission, the referral loses its object and will almost certainly be withdrawn. That near-miss says something uncomfortable about the process. The referral list reflects a snapshot of paperwork on a particular Wednesday, not the actual state of cyber defences in any of the four countries.
Substance is where the frustration bites. NIS2 covers eighteen sectors, from hospitals and energy grids to drinking water, waste management and public administration itself. It replaced a 2016 regime that applied to a much narrower slice of the economy, and it pushed obligations down to medium-sized firms that had never dealt with a cybersecurity regulator before. Governments had to designate competent authorities, build incident-reporting channels, define which entities count as essential and which merely important, and reconcile all of it with existing sectoral rules for banking and aviation. None of that is fast work, and several capitals underestimated it badly.
Companies bear the cost of the delay in a way the treaty does not measure. A logistics operator running warehouses in Ireland, Spain and Germany currently faces one settled rulebook and two moving targets. Compliance teams cannot register with authorities that do not yet exist, and boards cannot sign off on liability arrangements that national law has not defined. Firms that prepared early are now waiting, which is the worst possible signal to send to the ones that did not.
There is a fair defence of the laggards. Rushing a cybersecurity framework through parliament produces a law that regulators cannot administer and companies cannot follow. France in particular has argued that its draft needed to slot into a national security architecture that predates the directive. A late but coherent transposition may serve the directive’s purpose better than a quick copy-paste that collapses at first contact with a real incident.
The Court will not weigh that argument, because notification is a binary fact. Judges will fix a lump sum and a daily rate, both calculated from national economic weight and the duration of the breach, and the meter will run until the paperwork arrives. Expect the remaining three to file within months, and expect the Commission to point at the outcome the next time a directive deadline slips.





