The European Commission has referred Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to implement NIS2, and opened infringement procedures against Spain, France, and Latvia for incomplete DORA enforcement. If you're a CISO at a multinational with EU operations, or you're building a program for an entity under these directives, you're likely fielding questions from your board and executive team about what this enforcement wave means for your timeline and budget.
Here's what you need to know.
Does this affect us if we're not in one of those four countries?
Yes, in two ways.
First, if you operate across multiple EU member states, you're dealing with uneven implementation timelines. NIS2's transposition deadline was mid-October 2024, but most countries missed it. By January 2025, seven member states still hadn't notified implementing measures. Now four are facing court action, while Bulgaria, Sweden, and Luxembourg have their laws in place. This means your compliance obligations vary by jurisdiction, even though NIS2 aims to create harmonized standards.
Second, this signals a shift in enforcement. The Commission isn't just sending letters anymore. Court referrals with requests for fines mean the EU is done waiting. If you've been treating NIS2 as a distant deadline, that calculation just changed. The enforcement model is hardening, affecting how you justify budget and prioritize work.
What sectors does NIS2 actually cover, and how do I know if we're in scope?
NIS2 applies to 18 critical sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, postal and courier services, waste management, chemicals, food production and distribution, manufacturing of critical products, digital providers (including cloud, data centers, content delivery networks, managed service providers, online marketplaces, and search engines), and research organizations.
The directive splits entities into "essential" and "important" categories based on sector and size. Essential entities face stricter obligations and direct supervision by national authorities. Important entities have lighter oversight but must meet baseline requirements.
If you're unsure whether your organization is in scope, check your member state's transposition law. Each country defines thresholds slightly differently, but generally: if you're medium or large (50+ employees, €10M+ annual turnover or balance sheet), operate in a covered sector, and provide services the national authority deems critical, you're likely covered.
Our legal team says DORA applies automatically because it's a regulation, not a directive. So why does enforcement matter?
DORA applies directly across the EU without needing national implementing legislation. But regulations still require member states to designate competent authorities, establish enforcement mechanisms, and define penalties.
The Commission's infringement procedures against Spain, France, and Latvia target this gap: these countries haven't notified the required national measures for penalties and authority powers. DORA requires member states to disclose implementing legislation to the Commission and relevant authorities by January 2025.
For your program, this means two things. First, if you're a financial entity covered by DORA (banks, insurance undertakings, investment firms, payment institutions, crypto-asset service providers, credit rating agencies, and others), your obligations are live now, even if your member state hasn't finalized enforcement rules. Second, enforcement inconsistency creates risk. If your national authority hasn't published penalty frameworks, you're operating with less clarity about non-compliance costs.
France is bundling NIS2, DORA, and the Critical Entities Resilience Directive into one law. Should we wait for that, or start implementing now?
Don't wait.
France's approach makes political sense: one comprehensive bill covering cybersecurity (NIS2), financial sector resilience (DORA), and physical protection of essential services (CER Directive). The draft appeared in late 2024, with a final version published in September 2024. Legal observers expected passage in Q1 2025. It didn't happen. Now France faces court action on NIS2 and infringement procedures on DORA.
If you're a French entity, you're already subject to DORA's requirements. NIS2's obligations were supposed to be in force by October 2024. Waiting for national legislation to clarify details is reasonable for edge cases, but core requirements are clear: incident reporting within 24 hours of awareness (with updates at 72 hours and one month), supply chain risk management, vulnerability handling, business continuity, and crisis management. You can start building those capabilities now.
Spain's situation is similar. The government approved a draft NIS2 law in January 2025 but hasn't submitted it to parliament. Reports suggest Madrid may be waiting to incorporate requirements from the Commission's January 2025 Cybersecurity Act revisions and November 2024 Digital Omnibus proposal. That's a bet on legislative alignment, but it leaves Spanish entities in limbo.
Ireland's draft law lets the National Cyber Security Centre scan public systems without permission. Is that normal under NIS2?
No, and that's why civil liberties groups are pushing back.
NIS2 requires member states to establish Computer Security Incident Response Teams and competent authorities with incident response and supervisory powers. It does not mandate blanket authority to scan all publicly accessible systems without notice, nor does it require mass data retention or domain-blocking capabilities framed as cybersecurity measures.
Ireland's draft goes further than NIS2's baseline. It would allow the National Cyber Security Centre to scan systems for vulnerabilities without permission, gather communications metadata and public-sector network traffic at scale, and enable domain-blocking and surveillance equipment installation by telecom providers and datacenter operators. The European Court of Justice has repeatedly struck down mass data retention schemes, so Ireland's approach carries legal risk.
For practitioners, this matters because it shows how national implementation can expand directive requirements in ways that create compliance friction. If you operate in Ireland, you'll need to track how the final law differs from the current draft as it moves through the Senate.
We're a Dutch entity. The Senate just approved the NIS2 law, and it enters into force in mid-August. Are we off the hook?
You're ahead of the other three countries facing court referrals, but "off the hook" isn't the right frame.
The Netherlands' NIS2 law will enter into force in mid-August, which may prompt the Commission to withdraw its Court of Justice referral. But your compliance work starts now. You'll need to identify which category you fall into (essential or important), register with the national authority, implement the required risk management measures, establish incident reporting procedures, and document your supply chain risk assessments.
The law entering into force doesn't mean you get a grace period. National authorities will begin supervision immediately, and incident reporting obligations are non-negotiable from day one.
Where do we go for implementation guidance while national laws are still in flux?
Start with ENISA, the EU cybersecurity agency. They've published sector-specific guidelines, incident taxonomy frameworks, and coordinated vulnerability disclosure templates. This week they released recommendations on AI-enabled threats, noting that NIS2 providers must now "harden operations against AI-scale threats such as adaptive phishing, model poisoning and supply-chain pivots."
For DORA, the European Supervisory Authorities (EBA, ESMA, EIOPA) have published regulatory technical standards, implementation guidance, and Q&A documents. These clarify ICT risk management requirements, third-party risk frameworks, and incident classification thresholds.
Don't wait for perfect national clarity. The core obligations are consistent across member states. Build your incident response playbook, map your critical third parties, establish your vulnerability management process, and document your risk assessments. When your national law finalizes, you'll adjust details, not scramble to build a program from scratch.





