Brussels: The cybersecurity directive that was meant to harmonise resilience requirements across the Union is heading into its second year of application as a fragmented instrument rather than the level playing field its drafters promised. Twenty of the twenty-seven member states have now notified full transposition of NIS2, a number that conceals more than it reveals. The remaining seven include several of the bloc’s larger digital economies, and the reasoned opinions the Commission issued in May 2025 to nineteen capitals are now ripening into potential referrals to the Court of Justice of the European Union.
The transposition deadline of seventeen October 2024 came and went with only a handful of capitals at the legislative finish line. The intervening eighteen months have seen a slow march, with Germany, France and the Netherlands among the more recent arrivals on the transposed list, but the divergence in national approaches has been more telling than the headline count. National laws now diverge on the size thresholds that pull entities into scope, on the breadth of incident reporting obligations, and on the level of management accountability the directive envisaged as a non-negotiable floor.
The patchwork creates a compliance problem that European industry associations have started to quantify. Multinational operators in the energy, transport and digital infrastructure sectors face up to twenty-seven national supervisory authorities with different methodologies for assessing essential and important entities, different formats for the incident notifications that the directive requires within twenty-four hours of significant impact, and different penalty calibrations that range from administrative fines to criminal sanctions in a minority of capitals. The compliance cost was not what the directive was designed to produce.
The Commission’s enforcement toolkit is now being tested against this fragmentation. The reasoned opinion stage typically gives capitals two months to respond before the Commission decides whether to refer cases to Luxembourg. With most opinions issued in May 2025, the referral window has been open for nearly a year. The Berlaymont has taken a deliberately patient approach, partly because several of the laggard capitals are now in the last stages of parliamentary procedure and partly because the political cost of dragging governments before the Court during a single-market simplification cycle is non-trivial.
The substance of the cases the Commission is likely to take to Luxembourg is also part of the calculation. The directive contains hard deadlines but few procedural prescriptions on how member states must structure their cybersecurity authorities. A Court judgment that condemns a capital for failing to notify transposition is a useful precedent but a limited one. The Commission has indicated, in correspondence with the European Parliament’s industry committee, that it is more interested in eventual second-stage cases that test the quality of transposition rather than its existence.
The next inflection point is the directive’s first implementation review, which the Commission has signalled it will start later this year. The review will be the first formal opportunity to ask whether the patchwork is a transitional phenomenon that will close as the remaining capitals catch up, or whether the directive’s design itself permitted too much national divergence. Industry submissions to the consultation are likely to focus on the latter argument. A coordinating committee of national authorities under the Network and Information Systems Cooperation Group has so far been a venue for information sharing rather than convergence, and the European Union Agency for Cybersecurity has limited convening power outside its advisory mandate.
The political backdrop has shifted in ways the directive’s drafters did not anticipate. Three years after the regulation was adopted, the Commission’s Digital Omnibus proposal has put horizontal simplification at the centre of digital policy, and the question of whether NIS2 should be reopened in that exercise has been actively debated. Officials close to the file describe a strong institutional preference for treating implementation gaps through Court referrals and guidance rather than through legislative reopening, on the grounds that a renegotiation in the current political climate would yield a weaker text rather than a stronger one.
What the Commission cannot avoid is the credibility cost of a directive that operates unevenly across the union for which it was designed. The Court of Justice route is slow, but it is the only instrument that ties capitals to the timetable they accepted. The next twelve months will determine whether NIS2 becomes the model for assertive enforcement of digital legislation, or a cautionary tale about what happens when a complex directive meets twenty-seven legal cultures with their own definitions of essential and important entities.




