The European Commission has referred France, Ireland, Spain and the Netherlands to the Court of Justice of the European Union for failing to transpose the NIS2 Directive into national law more than 20 months after the deadline. Brussels is seeking both lump-sum and daily financial penalties until each country formally notifies full implementation of the cybersecurity law, which expands security and incident-reporting obligations across 18 critical sectors and sits at the center of the EU’s wider cyber regulatory framework.
In France, the enforcement action follows another delay in parliamentary review of the national transposition bill, with examination now expected in September rather than July despite the measure being treated as a government priority. The French debate has also been complicated by a disputed provision, article 16 bis, which would protect end-to-end encryption and has drawn criticism from the parliamentary intelligence delegation over concerns it could restrict access to protected data, while ANSSI continues operational preparations through preregistration work and a new agreement with the Banque de France and the ACPR.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to transpose NIS2 into national law. It is seeking lump-sum and daily financial penalties until full implementation is formally notified.
The references state that Ireland, Spain, France, and the Netherlands had still not transposed the NIS2 Directive more than 20 months after the deadline, establishing that the implementation deadline had already passed without full national transposition.
While legislation remained delayed, ANSSI continued implementation preparations, including a pre-registration process and a new agreement with the Banque de France and the ACPR.
France again postponed parliamentary examination of the bill transposing the EU NIS2 directive. Review, initially expected in July, was now hoped for in September, despite the bill being described as a government priority.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.