The European Commission has referred Ireland, Spain, France, and the Netherlands to the Court of Justice for missing the October 2024 NIS2 implementation deadline. Spain, France, and Latvia also face infringement procedures for failing to implement the Digital Operational Resilience Act (DORA). These aren't warnings anymore; they're lawsuits with requested fines.
If entire national governments can't get this right, your organization probably isn't immune to the same mistakes. Here's what went wrong and how to avoid repeating these errors at the enterprise level.
Why These Mistakes Keep Happening
NIS2 and DORA represent a fundamental shift in how the EU regulates cybersecurity. Unlike previous directives that focused narrowly on specific sectors, NIS2 covers 18 critical sectors and introduces mandatory incident reporting, supply chain security requirements, and board-level accountability. DORA standardizes operational resilience across the entire financial sector.
The complexity isn't just technical; it's organizational. These frameworks require coordination between legal, IT, operations, and executive leadership. They demand changes to procurement processes, vendor management, and incident response procedures. When implementation fails, it's rarely because someone didn't read the directive. It fails because organizations treat compliance as a project instead of a transformation.
Mistake 1: Waiting for Perfect National Guidance
Why it happens: Teams assume they should wait until their national regulator publishes detailed implementation guidance before starting work. Spain's government approved a draft NIS2 law in January 2025 but hasn't submitted it to parliament, possibly waiting to incorporate upcoming EU legislative changes. Organizations in Spain are now caught in limbo.
Real consequence: You lose your preparation window. NIS2's incident reporting requirements, for example, demand that you notify authorities within 24 hours of becoming aware of a significant incident. If you wait for final national rules to build your notification procedures, you won't have time to test them, train staff, or integrate them with your existing Computer Security Incident Response Team workflows.
The fix: Map your current controls to the directive's requirements now. NIS2 Article 21 specifies cybersecurity risk management measures including supply chain security, vulnerability handling, and multi-factor authentication. You don't need national legislation to audit whether you're meeting these baseline requirements. Build a gap analysis against the directive itself, then adjust when national rules add specifics. France is implementing NIS2, DORA, and the Critical Entities Resilience Directive in one bill, but French organizations that started mapping controls early aren't scrambling now.
Mistake 2: Treating DORA Like Optional Guidance
Why it happens: DORA is a regulation, not a directive, which means it applies directly across all EU member states without requiring national implementing legislation. Teams see that Spain, France, and Latvia haven't passed their implementing laws and assume compliance can wait.
Real consequence: DORA entered into force in January 2025. Financial entities operating in the EU are already subject to its requirements for ICT risk management, incident reporting, third-party risk management, and digital operational resilience testing. The fact that some countries haven't published administrative penalty frameworks doesn't suspend your obligations. If you experience a major ICT-related incident and fail to report it according to DORA's timelines, you're non-compliant regardless of national law status.
The fix: Implement DORA's core requirements immediately if you're a financial entity. Focus on Article 6's ICT risk management framework, Article 17's incident classification and reporting, and Article 28's third-party ICT service provider oversight. You need policies, procedures, and technical controls in place now. National implementing legislation will clarify enforcement mechanisms and penalty structures, but it won't change your substantive obligations.
Mistake 3: Bundling Too Many Initiatives
Why it happens: France decided to implement NIS2, DORA, and the Critical Entities Resilience Directive in a single comprehensive bill. The logic seems sound: reduce redundancy, create unified national cybersecurity legislation, avoid overlapping requirements.
Real consequence: The draft law first appeared in late 2024, was last published in September, and still hasn't passed. Meanwhile, entities covered by these directives remain in regulatory uncertainty. At the organizational level, bundling your ISO/IEC 27001 certification, NIS2 readiness, and SOC 2 Type II preparation into one massive "cybersecurity transformation" project creates the same problem. You miss deadlines because no single team can manage the entire scope.
The fix: Separate regulatory compliance from certification projects. NIS2 compliance is mandatory and time-bound. Your ISO/IEC 27001 certification is valuable but discretionary. Run them as parallel workstreams with separate owners and milestones. For NIS2, prioritize the requirements that differ from your existing controls: supply chain security measures under Article 21(2)(e), vulnerability disclosure coordination, and 24-hour incident notification procedures. You can integrate everything into a unified control framework later, but meet the legal deadline first.
Mistake 4: Assuming Elections and Politics Don't Affect Your Timeline
Why it happens: Ireland's NIS2 implementation delays stemmed partly from a national election. Organizations don't factor political disruption into their compliance planning because they focus on technical requirements, not legislative calendars.
Real consequence: If your compliance strategy depends on national guidance that's tied to a legislative process, you're exposed to political risk. Ireland published its NIS2 bill in 2024, but parliamentary committee scrutiny is ongoing. Civil liberties groups are challenging provisions that would allow the National Cyber Security Centre to scan publicly accessible systems without permission and require telecommunications providers to install surveillance equipment. These debates delay passage and create uncertainty about final requirements.
The fix: Build a two-track compliance approach. Track one: implement the directive's explicit requirements regardless of national law status. Track two: monitor your national legislative process and prepare for jurisdiction-specific additions. For Ireland-based entities, this means planning for potential vulnerability scanning by authorities and understanding how domain-blocking provisions might affect your incident response procedures. Don't wait for political clarity to start technical work.
Mistake 5: Ignoring Cross-Directive Implications
Why it happens: Teams treat NIS2, DORA, and other EU cybersecurity laws as separate compliance exercises. They assign NIS2 to the infrastructure team, DORA to the financial controls group, and General Data Protection Regulation (GDPR) requirements to the privacy office.
Real consequence: These frameworks overlap substantially. NIS2's incident reporting requirements intersect with GDPR's 72-Hour Notification Requirement for personal data breaches. DORA's third-party risk management obligations overlap with NIS2's supply chain security measures. When different teams own different frameworks, you create redundant controls, conflicting procedures, and gaps where everyone assumes someone else is responsible.
The fix: Map control objectives across frameworks before implementing solutions. NIS2 Article 21's supply chain security requirements and DORA Article 28's third-party oversight both demand due diligence, contractual security requirements, and ongoing monitoring. Build one vendor risk management program that satisfies both. Your incident response playbook should address NIS2's 24-hour notification, DORA's incident classification criteria, and GDPR's breach notification simultaneously. The European Commission's Digital Omnibus proposal aims to streamline reporting requirements across EU cybersecurity laws; anticipate this by designing flexible reporting workflows now. Digital Omnibus proposal
Prevention Checklist
Use this checklist to avoid the mistakes that led to Commission enforcement action:
- Gap analysis complete against directive text, not just national guidance
- Incident notification procedures tested for 24-hour NIS2 timeline
- Supply chain security requirements from NIS2 Article 21 mapped to vendor contracts
- DORA ICT risk management framework implemented if you're a financial entity
- Cross-framework control mapping completed for NIS2, DORA, GDPR, and relevant sector laws
- Separate project owners assigned for mandatory compliance vs. voluntary certifications
- Legislative monitoring process established for jurisdiction-specific requirements
- Board briefing scheduled on NIS2's management accountability provisions
- Third-party risk management program covers both NIS2 and DORA requirements
- Vulnerability handling and disclosure procedures documented per NIS2 Article 21(2)(d)
The Netherlands approved its NIS2 implementation law in April, and the Senate followed this week. The law enters into force in mid-August, which may prompt the Commission to withdraw its referral. That's the timeline you're working with: fix it fast, or explain to the court why you didn't.




