Hard2bit
← Back to the cybersecurity blog

NIS2 without a national law: what the CJEU referral changes

By Adrián González · CEO · Published: 21 July 2026 · Updated: 21 July 2026
NIS2 without a national law

On 8 July 2026 the European Commission decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify measures transposing the NIS2 Directive. This is not a procedural formality. The Commission is asking the Court to impose a lump sum and daily penalty payments accruing until each country notifies full transposition. The original deadline expired on 17 October 2024.

For boards in the referred countries there is a comfortable reading available: no national law, no obligation. It is the wrong reading, and an expensive one. NIS2 requirements are already reaching organisations in those markets — just through a different channel than expected. They arrive through contracts, through supply chain clauses, and through sector regulators that already have their own legal basis.

At a glance

  • Four member states were referred to the CJEU on 8 July 2026, with an explicit request for financial sanctions.
  • The Netherlands appears on the list despite its Senate approving the Cyberbeveiligingswet on 7 July 2026, because referral turns on what has been formally notified.
  • Spain approved a draft cybersecurity governance bill in January 2025 and still has no published text.
  • Article 21 risk management measures come from Brussels, not from national legislators. They can be built today.
  • The requirement that breaks first in a real incident is not a technical control — it is the 24-hour notification clock.

What actually happened

The sequence is worth having straight before it reaches a board discussion.

  1. 17 October 2024: transposition deadline for Directive (EU) 2022/2555 passes without notification from several member states.
  2. 7 May 2025: the Commission sends reasoned opinions to 19 member states for failing to notify full transposition, as recorded on its transposition tracking page.
  3. 8 July 2026: the Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice and requests financial sanctions. Reported by The Record and Agence Europe, among others.

The Dutch case is instructive. The Senate approved the national implementing act on 7 July 2026, with entry into force scheduled for 15 August, and the referral still went ahead the following day. Referral decisions rest on formal notification to the Commission, not on parliamentary progress. The practical consequence for anyone tracking this is that a country's real status can shift within weeks while the judicial procedure continues independently.

Why the “no law, no duty” argument does not hold

An untransposed directive does not, on its own, create obligations that a national authority can enforce against a private company. That much of the argument survives scrutiny. The difficulty is that enforcement is not arriving through that route.

It arrives through contracts

A German, Italian or Belgian essential entity is already bound by its national law, and its supply chain risk obligation is passed down to suppliers as contractual terms: audit rights, incident notification windows, continuity requirements, documented control evidence. A Spanish or Irish supplier may not be in scope at home, but is very much in scope of a contract that reproduces NIS2 clause by clause. Same work, different legal label — which is why third-party risk management tends to be the first front to activate.

It arrives through regulators that already have a basis

In banking, insurance and markets, DORA is a regulation and has applied since January 2025 with no transposition needed. In public sector supply chains, national security frameworks such as Spain's ENS already impose an audited control regime. Organisations serving both worlds usually discover that most of what NIS2 will ask for is already being asked by somebody else in different vocabulary. Keeping ENS and DORA as live frameworks removes a great deal of later work.

It arrives through the market

Insurers, lenders and large customers ask about security maturity during vendor onboarding. None of those questions is waiting for a national gazette.

The German mirror: what happens once the law exists

Germany transposed, which makes it a useful preview. Registration with the BSI was legally due on 6 March 2026. The market response fell short: by the end of May, roughly 18,500 of approximately 29,000 in-scope entities had registered, per BSI figures reported by heise. The BSI then wrote to industry associations flagging 31 July 2026 as the date by which registration should be completed.

The legal nuance matters. That July date is not a new statutory deadline — it is a signal of supervisory leniency. The enforceable date remained March. Translated into planning terms: when a national law finally lands, the first collision is not with technical controls but with scope determination and administrative registration. A third of the affected German market missed an identification step, with the law published and the authority already active.

The question to settle before the law exists is not “are we compliant?” but “are we an essential entity, an important entity, or neither — and on what documented reasoning?”

What can be built now, independent of the final text

Article 21 of the Directive sets out the minimum risk management measures. National legislators do not draft that content; Brussels already has, and it is published. National discretion sits in competent authorities, thresholds, registration procedures and the penalty regime — not in the substance of the controls. Everything below is stable work rather than speculation.

Scope and governance

  • Determine essential or important status by sector and size, and document the reasoning with a date. When the law arrives you revise it; you do not start over.
  • Formal approval of the risk management framework by the management body. NIS2 makes directors accountable, and that accountability does not delegate down to the IT function.
  • Board-level training with attendance records. It is one of the few requirements evidenced by a single document, and almost nobody has it ready.

Controls that leave evidence

  • Asset and critical service inventory with named owners. Without it, no impact analysis will survive scrutiny.
  • Phishing-resistant multi-factor authentication on administrative and remote access, with encryption in transit and at rest for sensitive information.
  • Tested continuity and recovery: immutable backups and documented restoration exercises, with measured real times rather than declared objectives.
  • Vulnerability management with defensible prioritisation and remediation service levels, measured in exposure time rather than finding counts.
  • Supply chain security: suppliers classified by criticality, notification clauses in contracts, and an inventory of critical technology dependencies.

The notification clock breaks first

Of all NIS2 obligations, the one most organisations miss during their first genuine incident is not a preventive control. It is the reporting timetable. The Directive sets an early warning within 24 hours of becoming aware of a significant incident, a notification with an initial assessment within 72 hours, and a final report within one month. That first 24-hour window is what destroys improvised procedures.

The reason is operational rather than legal. In the opening hours of an incident the team does not yet know what happened, and still has to decide whether the event is significant and report it. That requires several things to be settled in advance:

  • A written definition of “significant incident” translated into your own thresholds: users affected, services interrupted, duration, geographic spread, potential impact on third parties.
  • The ability to reconstruct a timeline within hours, which means sufficient log retention and centralised correlation. If endpoint logs age out after seven days, there is no timeline to build.
  • A named person with authority to declare, reachable out of hours, plus a deputy. The 24-hour clock runs in August and at weekends too.
  • Communication templates prepared and reviewed by legal counsel, so nothing is drafted under pressure. Much of the reputational outcome is set in the first 24 hours of a cyber crisis.

A managed SOC with adequate retention and a rehearsed incident response procedure solve the mechanical half of this. The judgement half — who declares, against which threshold — is a governance decision that cannot be outsourced.

Two approaches we would avoid

The first is waiting for the definitive text before starting. When the law publishes, the registration window will be short and will hit the whole market simultaneously: the same auditors, the same consultants, the same few weeks. Germany shows that even with a published law and an active authority, registration does not complete on time.

The second is buying a certificate as a substitute for the work. A well-implemented ISO 27001 covers a good share of Article 21 and is an excellent starting point, but NIS2 adds elements a generic management system does not resolve by itself: personal accountability of the management body, statutory reporting deadlines to a competent authority, and specific supply chain risk treatment. It is a foundation, not an alibi.

How we are approaching it

The approach working for organisations in this position has three layers and one rule: nothing that depends on the final legal text belongs in the first layer.

  • Documented scope determination and a gap analysis against Article 21, reusing whatever already exists from ENS, ISO 27001 or DORA rather than duplicating it. Framework consolidation is where the time is won, and it is what NormexAI is built for.
  • Closing the gaps that also reduce real risk today: stronger authentication, tested restoration, controlled external exposure, logs retained long enough to be useful.
  • Building the file: dated evidence, board approval minutes, a notification procedure with named owners. When registration opens, the file already exists.

None of this is wasted if the final wording shifts. It lowers incident probability and recovery time regardless of what the national gazette eventually prints. And if your organisation serves essential entities in transposed markets, that work is already being demanded of you — even where the contract never mentions NIS2.

More detail on scope and obligations sits on our NIS2 page and in our analysis of NIS2 compliance automation.

Frequently asked questions

Are organisations obliged to comply with NIS2 where the directive is not yet transposed?

Formally, an untransposed directive does not create obligations directly enforceable against a private company by a national authority. In practice, many organisations are already bound by equivalent requirements through contracts with customers in transposed markets, through DORA if they operate in financial services, or through public sector security frameworks. The obligation tends to arrive contractually well before it arrives legally.

What exactly did the European Commission decide on 8 July 2026?

The Commission decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify measures transposing the NIS2 Directive, whose deadline expired on 17 October 2024. The referral includes a request for financial sanctions: a lump sum plus daily penalty payments accruing until each member state notifies full transposition.

Why were the Netherlands referred if their national law had just been approved?

The Dutch Senate approved the Cyberbeveiligingswet on 7 July 2026, with entry into force scheduled for 15 August 2026, and the referral was decided the next day. Referral decisions rest on what has been formally notified to the Commission as complete transposition, not on parliamentary progress. A country's status can therefore change within weeks while the judicial procedure runs on its own timetable.

What are the NIS2 incident reporting deadlines?

Three milestones: an early warning within 24 hours of becoming aware of a significant incident, a notification including an initial assessment within 72 hours, and a final report within one month. The 24-hour window causes the most failures, because it forces a decision on significance before the scope of the incident is understood. It requires written thresholds and a named decision-maker reachable outside working hours.

Does ISO 27001 certification satisfy NIS2?

It is a solid foundation rather than a substitute. A well-implemented management system covers a good share of the Article 21 risk management measures and saves considerable effort. NIS2 nonetheless adds elements the standard does not resolve on its own: personal accountability of the management body, statutory notification deadlines to a competent authority, and specific treatment of supply chain risk.

What does the German experience suggest for other member states?

Germany transposed and set 6 March 2026 as the registration deadline with the BSI. By the end of May, roughly 18,500 of approximately 29,000 in-scope entities had registered, and the BSI flagged 31 July as a date to regularise. The lesson is that the first obstacle is not technical controls but scope determination and completing the administrative step on time — even with a published law and an active supervisor.

What can be built before the national law is published?

Everything that flows from Article 21 of the Directive, which is already published and is not drafted by national legislators: documented scope determination, board approval of the risk framework, management body training, asset inventory, phishing-resistant multi-factor authentication, immutable backups with tested restoration, vulnerability management with remediation service levels, and supplier classification by criticality.

What happens if a member state keeps failing to transpose after referral?

The Commission has asked the Court to impose a lump sum together with daily penalty payments that continue accruing until full transposition is notified. Those financial consequences fall on the member state rather than on individual organisations. The practical effect for businesses is indirect: sustained pressure tends to compress the eventual national implementation timetable, leaving a shorter window to prepare.