Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Penalties Won't Fix NIS2 Transposition DelaysRegulations & Laws
4 min readFor Regulatory Affairs Professionals

Penalties Won't Fix NIS2 Transposition Delays

The Conventional Wisdom

The European Commission's decision to refer Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union is a clear signal: financial penalties are intended to compel member states to transpose the NIS2 Directive. This move, more than 20 months after the October 2024 deadline, follows a familiar pattern. When member states delay, the Commission escalates to court proceedings, requests penalties, and waits for compliance.

Many see this as a necessary measure. To achieve harmonized cybersecurity standards across 18 critical sectors, enforcement is essential. Without financial consequences, member states might deprioritize transposition, leaving hospitals, energy networks, and transport operators vulnerable.

The Real Issue

Financial penalties aren't the main problem. They're a symptom of a deeper issue: the Commission designed NIS2 with complexities that member states couldn't manage in the given timeframe.

Transposition isn't a simple task. Member states must designate competent authorities, establish Computer Security Incident Response Teams, define sector-specific thresholds, create enforcement mechanisms, and build a national response-team network supporting the EU's broader Cyber Resilience Act.

Ireland's statement that its National Cyber Security Bill is "close to finalization" with notification expected by the end of 2026 highlights the timeline mismatch. That's over two years past the original deadline for legislation effective since January 2023. Spain, France, and the Netherlands haven't made similar statements, indicating they're facing comparable challenges.

The Commission's January proposal to amend NIS2 for "greater legal clarity and ease compliance" shows the directive's requirements were ambiguous, making it hard for member states to create workable domestic frameworks. When clarifications are proposed after the deadline, it's not a compliance failure but a drafting failure.

The Evidence

As of January 2025, only six of the EU's 27 member states had transposed the directive. That's just 22% compliance, 15 months after the deadline. When 78% miss a deadline, the deadline itself is flawed.

The Commission notes that "in practice, the fines being sought by the Commission are rarely paid." Member states typically adopt required legislation during proceedings, leading to withdrawal before the court rules. This pattern shows financial penalties are more political theater than genuine enforcement. The threat is more significant than the execution.

Meanwhile, ENISA identified thousands of cybersecurity incidents in the year ending June 2025, with public administration accounting for 38% and transport 7.5%. These sectors are already under attack. The issue isn't whether member states fear penalties but whether delays worsen the threat landscape and if penalties address the root cause.

They don't. The original Network and Information Security Directive of 2016 covered fewer sectors and was "applied unevenly across the bloc," according to the Commission. NIS2 expanded to 18 sectors and added requirements that weren't in the original directive, creating challenges penalties can't solve.

Ireland's approach shows the real work involved. Transposing NIS2 requires establishing the National Cyber Security Centre on statutory footing, defining authority roles, and building enforcement capabilities that didn't exist under the 2016 directive. You can't fine your way to institutional capacity.

What to Do Instead

If you're a CISO or GRC leader in a critical sector within the EU, don't wait for your member state to formalize transposition. The directive's requirements are clear enough to start implementation.

Begin with risk management obligations. NIS2 requires measures covering supply chain security, network and information systems acquisition, risk analysis, incident handling, business continuity, crisis management, and human resources security. Map these to your existing ISO/IEC 27001 controls or NIST Cybersecurity Framework (CSF) 2.0 implementation. The overlap is substantial.

For incident reporting, prepare your team to meet notification timelines even if your national authority isn't designated. The General Data Protection Regulation's 72-Hour Notification Requirement established reporting practices you can adapt for NIS2. Document your incident classification criteria now to avoid making judgment calls under pressure.

Focus on supply chain risk. NIS2 addresses supplier security, and the Commission's proposal to phase out high-risk suppliers like Huawei and ZTE from critical infrastructure signals where enforcement will focus. Conduct supplier security assessments and ensure contracts include incident notification obligations that align with your NIS2 responsibilities.

For cross-border operations, don't assume your member state's approach will match neighboring countries. The 2016 directive was "applied unevenly," and current patterns suggest NIS2 will be similar. Build your compliance program to the directive's requirements, not the lowest national implementations.

When the Conventional Wisdom Is Right

Financial penalties do push member states to prioritize legislative action over indefinite delay. Without the Court of Justice referral, Ireland might not have committed to finalization by 2026. Spain, France, and the Netherlands might continue deferring transposition while other priorities compete for attention.

The need for harmonized cybersecurity standards is also correct. When ENISA warns of thousands of incidents affecting the bloc, with public administration representing 38% of attacks, inconsistent security baselines create exploitable gaps. An attacker targeting transport infrastructure doesn't care whether your member state has transposed NIS2. They care whether your incident response plan works.

The Commission's broader legislative program depends on NIS2's national response-team network. The Cyber Resilience Act's vulnerability-reporting obligations, starting in 2027, assume that network exists. If member states haven't established the infrastructure NIS2 requires, the entire cybersecurity regulatory stack becomes harder to enforce.

So yes, the Commission needs enforcement mechanisms, and financial penalties are the tool available. But if you're responsible for critical infrastructure security, don't confuse regulatory process with operational readiness. The threat landscape ENISA describes doesn't pause while member states finalize transposition. Your security program can't either.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like