NIS2 Patchwork: Four States Face EU Court
At the beginning of July 2026 the EU Commission brought Ireland, Spain, France and the Netherlands before the EU Court – due to incomplete NIS2 implementation. For German CISOs this is no spectator issue: Those who have subsidiaries or critical suppliers in these countries continue to plan against a moving target.
THE ESSENTIALS IN BRIEF
- Infringement is now tangible. Following warning letters and a reasoned response, EU Court proceedings including a sanctions request are now underway.
- DE is not the defendant state. Operationally relevant remains the German implementation and registration situation – plus subsidiaries and suppliers in the four states.
- Board-Framing changes. “We are still waiting for the law” is no longer a credible risk argument in multi-state setups.
Related:What is KRITIS? Operators, duties and thresholds / NIS2 hits CLOUD Act: Third‑state gap
What the Commission has actually done
What is the NIS2 lawsuit before the CJEU? The European Commission has taken Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union (CJEU) because they failed to notify the full implementation of the NIS2 Directive by the deadline of 17 October 2024. A lump sum and a penalty fee have been requested against the states. The lawsuit does not immediately alter the national obligations for companies.
In the July 2026 Infringement Package, the Commission refers Ireland (INFR(2024)0279), Spain (INFR(2024)0270), France (INFR(2024)0274) and the Netherlands (INFR(2024)0288) to the Court of Justice of the European Union. Allegation: failure to fully notify national measures transposing the NIS2 Directive (EU) 2022/2555.
The procedural path was predictable: a warning letter in November 2024, reasoned opinions in May 2025, and now the final step with a request for financial sanctions (lump sum and penalty fee). The addressees are the member states. The NIS2 fines for operators remain unaffected. The directive imposes high requirements on operators in 18 critical sectors – from energy and transport to health and public administration.
For security leadership, the signalling effect is paramount: Brussels is no longer taking a lenient approach. Companies operating in multiple member states will once again receive a patchwork-like compliance map rather than an EU-wide “once and done” solution.
Member states before the CJEU over NIS2 implementation
Source: European Commission, IP/26/1499, July 2026
What this means for German companies
Germany is not one of the four countries in question. This only partially eases the governance narrative. Many DACH groups have important subsidiaries, shared services, or critical suppliers in FR, ES, NL, or IE. The legal situation remains unclear for now. The Netherlands has adopted its Cybersecurity Act on July 7, 2026, which will enter into force on August 15, 2026. Ireland aims to complete the notification by year‑end.
Secondly, the German registration and reporting logic remains the operational lever: impact assessment, registration, reporting chains, management liability. Those who still plan for “NIS2 comes eventually” internally will collide with procurement, insurance, and customer due diligence, which already reflect EU pressure in questionnaires and contractual provisions.
Thirdly: Multi‑country entities need a location matrix rather than a pure DE playbook. Scope, deadlines, competent authorities, and reporting channels differ – even though the directive sets the same framework.
Board Communication Without the Theater
For the management board, a single slide saying “Cyber is important” isn’t enough. What’s needed are three clear points: (1) Which entities fall under which national implementations? (2) Which evidence – governance, incident response, supplier oversight – is audit‑ready? (3) Which gaps have a deadline and an owner?
The EU Court referral changes the tone: a delay at the state level is no free pass for the corporate side. Regulators, insurers and large customers read the signal as “implementation will be enforced”. The sensible response is prioritized gap remediation rather than maximal tool purchasing.
Next 30 Days
- ✓Scope Matrix DE plus FR/ES/NL/IE subsidiaries and critical suppliers
- ✓Registration and reporting status per entity with owner and date
- ✓Incident Playbook: test 24h/72h logic against real escalation paths
- ✓Board One‑Pager: top‑3 risks with budget and timeline
What Security Is Prioritizing Now
Technically, the list stays sober: clear asset and dependency visibility, privileged access controls, backup/restore testing, logging until reportable, vendors with remote access. Organizationally, it includes roles, coverage, and documented decisions by management-exactly what auditors and accounting firms will later ask for.
Those who already run an Information Security Management System (ISMS) or an ISO‑27001 (International Organization for Standardization 27001) framework can map NIS2 (the EU’s Network and Information Security Directive) requirements onto it rather than building a parallel universe. Those starting from scratch should begin with scope and reporting chain, not with tool comparisons.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Is Germany affected by the ECJ lawsuit?
No as a defendant member state. The German implementation and registration situation, as well as group companies and suppliers in the four defendant states, remain relevant.
What were the four states accused of?
Incomplete notification of national measures transposing the NIS2 Directive. The Commission is seeking financial penalties before the EU Court of Justice.
Does the lawsuit change my German obligations overnight?
Not automatically. It increases political and regulatory pressure and sharpens the due-diligence expectation in multi-state setups and supply chains.
What should the board see next?
An entity matrix with scope, deadlines, pending evidence and named owners – plus three prioritized risks with time and budget.
Is a pure tool upgrade sufficient as an answer?
No. NIS2 requires controllable governance, reporting obligations, and supply chain oversight. Tools alone prove nothing. Governance provides the proof.
Lesetipps der Redaktion
LesetippCursor startet git.exe aus dem Repo-RootLesetippLegacyHive-PoC trifft frische Windows-PatchesLesetippZwei Joomla-Uploads landen im CISA-KEV
Mehr aus dem MBF Media Netzwerk
cloudmagazinWenn KI-Agenten reisen: Data-Residency als Operating-ProblemMyBusinessFutureMehr Insolvenzen, kleinere Fälle: Was zähltDigital ChiefsToken-OPEX: Inference steuert, nicht das Seat-Budget





