Skip to main content

folkfox

Skip to main content
Skip to content
EU CYBERSECURITY LAW

NIS2 Compliance Meets the Court of Justice, and Ireland Picks Up the Bill

Brussels does not send a fine first. It sends a summons, and then it sends a bill that grows by the day.

Quick answerIreland missed its NIS2 compliance deadline by 677 days, and the European Commission has referred it, Spain, France and the Netherlands to the Court of Justice, with Aon pricing Ireland's exposure at €2.8 million plus daily fines.
Section 01

What the CJEU referral actually changes#

677 days

Ireland's nis2 compliance now sits this far past its legal deadline of 17 October 2024

European Commission

The fox does not wait for the badger to notice the trap; it reads the ground and moves first. Ireland did not move first. On 8 July 2026 the European Commission decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union, for failing to notify measures transposing the NIS2 Directive, formally Directive (EU) 2022/2555, into national law. The transposition deadline was 17 October 2024. None of the four had notified full transposition by the date the Commission acted, and the referral asks the Court for a lump sum plus daily penalties for as long as the delay continues.

The Irish Times reported the practical price tag on 24 August 2026: professional services firm Aon, working from the Commission's own published penalty methodology, puts Ireland's lump-sum exposure at €2.8 million, with daily fines stacking on top for every day the National Cyber Security Bill stays unsigned. Leann Moroney, Aon Ireland's associate director for cyber risk management, called nis2 compliance “one of the most significant changes to cybersecurity regulation in recent years,” and added a line that reads like a warning dressed as advice: “Cyber threats are not waiting for legislation, and businesses shouldn't either.”

Recorded Future News reported that the Commission's own technology chief, Henna Virkkunen, framed the referral bluntly: Europe could no longer afford to be “naive” about adversaries' ability to disrupt critical infrastructure such as power grids and hospitals. The same report puts the delay at more than twenty months past the original deadline, wide enough that the old pattern, a quiet fix once a case is filed, is no longer a safe bet to plan a client's own calendar around.

Ireland is not alone in the dock, but it is not equally exposed either. According to TechCentral's report on the referral, the Netherlands has since closed its own gap, its Cyberbeveiligingswet entering force on 15 August 2026, five weeks after Brussels filed. Spain and France remain where Ireland stands. Three foxes still circling the same thicket, one already clear of it.

Three of four, still exposed
Waffle chart showing 75 percent, three of four EU member states referred to the Court of Justice over NIS2 compliance still have not transposed the directive75% of the states referred to the CJEU overnis2 compliance have still not transposed the directive
Ireland, Spain and France remain unresolved a month after the Netherlands closed its own gap. Illustrative share of the four referred states, not a Commission-published figure. Source: European Commission, TechCentral.

Read that grid the way a fox reads a hedgerow gap: three-quarters of it is still closed, and the one state that found its way through did it in five weeks once the political will turned up. That is the whole shape of this story before a single euro changes hands.

Section 02

Why nis2 compliance requirements caught four capitals flat-footed#

nis2 compliance requirements run wider than most directors expect, which is precisely the design. The directive, in force since January 2023, covers eighteen critical sectors under the Commission's own Digital Strategy guidance: energy, transport, health, water, digital infrastructure, public administration, space and more, split between “essential” entities that face direct supervision and “important” ones that face lighter but still real duties. ENISA, the EU's own cybersecurity agency, frames the shift plainly: risk-management measures, incident reporting and, for the first time, personal accountability for the management bodies that skip the paperwork.

A watercolour fox watches an hourglass run out, illustrating nis2 compliance running past its legal deadline
The clock was already the story before the summons arrived.

The deadline itself is not a trade-press estimate. Article 41 of the directive's own text, hosted on EUR-Lex, states plainly that “by 17 October 2024, Member States shall adopt and publish the measures necessary to comply with this Directive.” Ireland's own parliament was already tracking the gap on that exact date: the Houses of the Oireachtas convened a pre-legislative scrutiny session for the National Cyber Security Bill 2024 on 17 October 2024, the very day the transposition clock ran out, with committee chair Alan Farrell TD telling the room the committee wanted sector-specific views on “the challenges Ireland faces into the future.” Two years on, that scrutiny still has not produced an Act.

Wide scope is exactly why four capitals missed the mark. Ireland's own route runs through that same National Cyber Security Bill, published in general scheme form on 30 August 2024 and still moving through pre-legislative scrutiny and departmental drafting two years on, per TechCentral's reporting on the referral. This is not Ireland's first brush with this exact problem: the state previously paid €4.5 million for a three-year delay transposing the European Electronic Communications Code, a precedent the Irish Times notes explicitly. A fox that has stepped in the same snare twice stops calling it bad luck.

None of this waits for the Bill to pass either. Moroney's own advice, that businesses should not wait for legislation before tightening controls, matches what folkfox sees across every regulated client: procurement teams, insurers and larger customers are already writing nis2 compliance requirements into contracts and security questionnaires, months ahead of any enactment date.

Section 03

What nis2 compliance actually costs a state that waits#

Aon's own modelling of Ireland's exposure
Aon's own modelling of Ireland's exposureBullet chart showing Aon's estimated 2.8 million euro lump-sum exposure for Ireland against a zero-euro compliant targetLump-sum exposure: 2.8 of 0Lump-sum exposure2.8€m
Aon's modelling under the Commission's own penalty methodology puts Ireland's lump-sum exposure at €2.8 million, before a single day of daily fines is added. Source: Irish Times, Aon.

A lump sum is a one-off sting. A daily penalty is a leak in the den floor, small on any single day, and never patched by simply intending to fix it later. Ireland has form here: the €4.5 million European Electronic Communications Code fine was for a delay of three years, and this referral has already run past that clock on the calendar, if not yet in cash terms.

TechBuzz Ireland's follow-up the next morning repeated Aon's own advice almost as a dare: do not wait for the Bill's enactment date before acting as if the obligations are already real, because for any firm sitting inside a larger customer's supply chain, they already are.

Academic attention is only now catching up to a directive Brussels finalised in 2022. A systematic literature review by Jukka Ruohonen, first posted in 2024 and revised in 2026 on arXiv, found scholarship on NIS2 still concentrated in a handful of sectors, industrial control systems, telecoms, energy and information-sharing infrastructure, and flagged real, unfilled gaps in how the wider compliance burden is studied. Ireland's own delay is a live case study nobody has written up yet.

Three of the four referred states remain unresolved a month after the Netherlands closed its gap.
StateNIS2 status as of 25 August 2026Referred to CJEU
IrelandNot yet transposed; National Cyber Security Bill still draftingYes, 8 July 2026
SpainNot yet transposedYes, 8 July 2026
FranceNot yet transposedYes, 8 July 2026
NetherlandsTransposed; Cyberbeveiligingswet in force since 15 August 2026Yes, since resolved

What does nis2 compliance mean in cash terms once the Court actually rules, rather than once a state is merely referred to it. Historically, member states tend to pass the outstanding law once proceedings are underway, and the Commission withdraws before judgment. That is the likely path here too. It does not make the daily fine notional in the meantime, and it does not un-write the questionnaire a nervous customer already sent.

Section 04

What nis2 enforcement actually looks like before the ruling lands#

Waiting for the Bill is not a strategy, it is a bet on Brussels' patience, and Brussels has already shown its patience has a date on it. nis2 enforcement does not politely wait for a state's own Act to pass, it starts the moment a customer, insurer or auditor asks the question, regardless of what the Oireachtas, the Cortes or the Assemblée nationale do next.

Getting ready before nis2 enforcement arrives
Confirm scope

Check whether you sit inside the 18 sectors NIS2 covers, and whether you land as an essential or important entity. Supply-chain reach counts: plenty of firms discover their nis2 compliance obligations arrive through a customer's contract, not their own sector code.

Name an accountable owner

NIS2 puts personal accountability on management bodies, not a delegated compliance officer alone. Put a named executive's name against the file, not a department's.

Map the incident clock

Build the staged reporting runbook before an incident forces you to improvise one: an early signal fast, fuller detail soon after, a complete report within the month.

Audit the supply chain

Third-party and supplier risk sits inside scope now, not beside it. List every vendor whose own posture could drag your compliance status down with them.

Document, don't just decide

A board that approved a policy and a business that can prove it operates that policy are two different postures. Keep the evidence trail running, not just the meeting minutes.

Revisit quarterly, not annually

nis2 enforcement calendars are moving faster than annual review cycles now. A readiness checklist reviewed once a year is already a season behind the scent.

u/Pitiful_Signature264
hardware-compliance-handbook: an open-source, fact-checked EU CRA/RED/NIS2/CSA compliance reference (also works as a Claude Skill)
r/cybersecurity, 24 August 2026View on Reddit

That thread is small, and it is exactly the right size. Practitioners are not waiting for a courtroom verdict to start building their own reference material, and neither should you. The tools are getting more specific by the week; the checklist above is the durable part underneath them.

Section 05

Why nis2 compliance uncertainty is a client's opening, not just a headache#

Here is the useful reframe. A prospect who reads that Ireland just picked up a €2.8 million exposure for waiting does not think that is Brussels' problem. They think is my own house in order, and that thought is the entire opening a folkfox client needs. Uncertainty is not a marketing headwind here, it is the marketing message. A vendor, MSSP or compliance consultancy selling into the EU has rarely had a cleaner, more honestly urgent hook than a live court referral with a running daily meter.

A deadline that already passed is a better sales trigger than one still approaching. Nobody has to be persuaded the clock started.
folkfox, on selling nis2 compliance urgency without inventing it

This only works if the content stays honest, which is where most cybersecurity marketing trips over its own feet. Fear without a fact underneath it reads as noise, and buyers in this category can smell noise from the far side of a thicket. Pair every deadline you cite with its source, every number with where it came from, and let the regulator's own timeline do the persuading. That discipline is what folkfox's cybersecurity marketing work is built around, and it is the same approach behind our pieces on DORA's operational resilience gaps and the Cyber Resilience Act's own counting clock.

The Netherlands is the case worth studying if you sell compliance software or advisory hours: it went from referred to resolved in five weeks flat once the political will turned up, which we covered in full when its own nis2 compliance arrived one day after Brussels sued for the wait. Ireland, Spain and France have not yet found that same gear, and every week they do not is a week your prospects are watching a neighbouring jurisdiction move first.

Content built on this story earns its keep twice: once as search demand from a compliance lead typing nis2 enforcement into a browser late on a Friday, and once as a citation an AI answer engine can lift cleanly, because every claim in it traces back to the Commission, ENISA or a named source rather than a vibe. That is the same groundwork behind our identity security posture management coverage this week, and it is what folkfox's SEO and GEO team builds into every regulated client's content calendar.

The fox that outfoxes the field is not the loudest one in the brush. It is the one who read the regulator's own calendar before the client's competitor did, and said so first, in writing, with the source attached.

Questions

Frequently asked questions#

Who needs to be NIS2 compliant?

Any organisation classed as an essential or important entity under one of NIS2's 18 covered sectors, from energy and health to digital infrastructure and public administration, per the European Commission's own scope guidance. Many mid-sized suppliers discover they are in scope through a customer's procurement contract rather than their own sector code, so checking supply-chain exposure matters as much as checking the sector list.

What does NIS2 compliance mean?

It means meeting the risk-management, incident-reporting and governance duties set out in Directive (EU) 2022/2555, with named accountability sitting at management-body level rather than delegated entirely to a compliance officer. In practice that covers supply-chain vetting, board sign-off and a documented incident-reporting runbook, not just a signed policy.

What is the NIS2 compliance deadline?

The legal deadline for EU member states to transpose NIS2 into national law was 17 October 2024. Ireland, Spain and France had still not fully transposed it as of August 2026, which is why the European Commission referred all three, plus the Netherlands, to the Court of Justice.

What happens if a country misses the NIS2 compliance deadline?

The European Commission can open an infringement procedure, issue a reasoned opinion, and ultimately refer the state to the Court of Justice with a request for a lump sum plus daily financial penalties until it notifies full transposition. Aon estimates Ireland's own lump-sum exposure at €2.8 million.

What does NIS2 enforcement look like in practice?

So far it means an infringement procedure, a reasoned opinion, and then a referral to the Court of Justice with a request for a lump sum plus daily fines, exactly the path Ireland, Spain, France and the Netherlands have been through. nis2 enforcement against individual companies, rather than states, follows separately once each country's own regulator is operational.

Does the NIS2 compliance requirement apply before national law passes?

Practically, yes. Larger customers, insurers and supply-chain partners are already writing NIS2-shaped clauses into contracts and questionnaires ahead of formal enactment, so waiting for a bill to become law is not the same as waiting to be asked about it.

Keep reading

Read more on this topic#

Ready to make your nis2 compliance story the one prospects actually trust?

folkfox builds the sourced, sharp, search-ready content that turns regulatory uncertainty into a reason to talk to you first, not a reason to freeze.