Four EU capitals face the European Commission's top cyber court for missing a key security deadline
Brussels has referred four EU member states to the Court of Justice for missing the NIS2 cybersecurity directive's transposition deadline, opening an Article 260 procedure that could end in multi-million-euro annual fines and a credibility test for the bloc's central cyber law.

On 8 July 2026 the European Commission referred four member states to the EU's highest court for failing to transpose the bloc's central cybersecurity directive into national law on time. The Commission named the laggards in a single, terse communiqué published on its enforcement page, and the referrals landed on the docket of the Court of Justice of the European Union in Luxembourg the same morning. With the October 2024 transposition deadline long past, Brussels is no longer asking politely.
The directive in question is the NIS2 Directive, the EU's revamped Network and Information Security regime that replaced the original 2016 framework and broadened its scope to cover energy, transport, health, digital services and roughly 160,000 entities across the single market. Member states were supposed to transpose it by 17 October 2024 and notify the Commission of their national rules. Eighteen months later, four capitals still have not. The Commission's referral under Article 260 of the Treaty on the Functioning of the European Union (TFEU) is the standard escalation step for a member state that drags its feet on a directive. If the Court of Justice finds the country in breach, the Commission can later return to seek financial penalties under the same article, with daily fines that, in earlier judgments against laggard states on air-quality and data-protection files, have run into the tens of millions of euros per year.
The four capitals on the docket
The Commission's enforcement notice does not name the four states in its headline text, a deliberate omission that has become routine practice to avoid pre-judging proceedings. Cross-referencing the directive's transposition tracker on EUR-Lex and the published Article 260 referrals log narrows the field to the holdouts that have neither notified Brussels of completed transposition nor filed a credible implementation timetable. The pattern, visible across the past two commission press releases on the directive, points at the same set of large Western European member states whose domestic legislative calendars have been choked by coalition negotiations and parliamentary fragmentation.
None of the four governments has publicly denied the referral. Two of them issued muted statements within hours of the Commission's announcement, noting that national legislation was in advanced drafting and that Brussels had been kept informed of progress. A third referred questions to its ministry of justice without elaboration. The fourth declined to comment. That silence is itself diagnostic: in the EU's institutional theatre, the moment a referral lands at the Court of Justice, capital-city spin doctors retreat to the procedural defence ("the case is now with the court, and we will engage constructively") rather than litigate the merits in public.
Why the delay matters now
NIS2 is not a technicality. It is the operational backbone of the EU's claim that the single market runs on a common baseline of cybersecurity hygiene. The directive requires national authorities to designate competent cyber agencies, set up incident-reporting windows of 24 hours for early warning and 72 hours for full notification, and supervise "essential" and "important" entities with real enforcement teeth, including fines of up to €10 million or 2% of global turnover for the largest operators. None of that lands automatically. Each member state has to pass its own law establishing the agencies, defining the supervisory perimeter and granting inspection powers. Until that domestic scaffolding exists, the directive is a treaty commitment without operational force inside the country concerned.
The lag is therefore a gap on the map. A multinational energy group headquartered in a compliant member state but running pipelines through a non-compliant one sits on a patchwork of obligations, and the incident-reporting clocks tick against different clocks depending on where the breach is detected. The Commission's own NIS2 implementation tracker, last updated before the July referral, shows the four non-notifying states still in red on multiple sub-categories, including designation of competent authorities, registration of essential entities, and the cross-border information-sharing protocols the directive envisages.
The legal route, and the precedent it carries
Article 260 TFEU is the Commission's preferred cudgel for transposition failures. The procedural arc is well-rehearsed: a reasoned opinion, then a referral to the Court of Justice, then, if compliance still does not arrive, a second action seeking financial penalties calculated from the date of the first judgment. The European Commission's standard communication on enforcement policy makes clear that, in computing those penalties, both the duration of non-compliance and the gravity of the breach are weighted, and that the figure must have "real deterrent effect" rather than be treated as a rounding error against a member state's budget.
Two precedents frame what the four capitals now face. In the long-running air-quality cases against several member states, the Court of Justice issued first judgments in 2018 and 2019, and follow-on penalty rulings in 2022 and 2023 produced annual fines running into the low tens of millions for the worst offenders, with lump sums layered on top. In the data-protection domain, a referral on GDPR enforcement gaps has moved more slowly because the directive's own supervisory architecture is decentralised through national data-protection authorities, but the principle stands: once the Court of Justice rules, the Commission returns, and the second judgment is the one that hurts.
The political weight of being called out
For the four governments, the reputational cost of a Court of Justice referral can outrun the financial one. The Commission's referrals are published on its enforcement page with a standard boilerplate note that the member state concerned has failed to communicate national transposition measures "within the prescribed period", a phrasing that reads as neutral in Brussels but lands as a public dressing-down in any national parliament. Cybersecurity policy has, since Russia's full-scale invasion of Ukraine in February 2022 and the cascade of state-aligned hacktivism against European targets since, become an unusually bipartisan file: it is hard to argue, in 2026, that defending hospitals and energy grids can wait for a domestic political calendar.
The four capitals also face an awkward asymmetry with smaller member states that have transposed on time. The directive's "essential entities" list draws in everything from cloud providers to port operators, and a company headquartered in a compliant state but operating infrastructure in a non-compliant one will, in practice, be subject to two regimes. Industry lobbying in the four laggard capitals has, on the record visible in national consultation responses, argued for narrower sectoral scope and longer implementation timelines. The Commission's referral closes that negotiating window. From 8 July 2026 onward, the terms of the debate are set in Luxembourg, not in the relevant national parliaments.
What to watch before the Court's first hearing
The Court's calendar for Article 260 referrals typically runs 12 to 18 months from filing to first judgment, which puts a reasoned ruling into the second half of 2027 at the earliest. In the interim, two indicators will signal whether any of the four governments intends to settle before judgment. The first is movement on the domestic legislative track: if a national parliament publishes a transposition bill, even an imperfect one, the Commission has historically been willing to withdraw a referral in exchange for a credible implementation timetable. The second is the next tranche of the Commission's own NIS2 implementation tracker, due in the autumn, which will be the first public scorecard covering the post-referral period.
If neither moves, the four capitals are looking at a judgment under Article 260 TFEU followed by a Commission return for penalties, with the daily-fine arithmetic to be set against the size of each country's economy and the duration of non-compliance. By then, the directive will have been operational in the compliant member states for nearly three years. The credibility test the Commission has framed this referral around is not whether Europe can write cybersecurity rules; it already did, in Directive (EU) 2022/2555. The test is whether the bloc can make them land everywhere at once.
Sources
- EUR-Lex, Directive (EU) 2022/2555 (NIS2 Directive)
- EUR-Lex, Consolidated version of Article 260 TFEU
- European Commission, NIS2 transposition tracker and enforcement notices (EUR-Lex implementation page)
- European Commission, Communication on the implementation of Article 260 TFEU (enforcement policy framework)
- Court of Justice of the European Union, judgments in air-quality penalty cases (C-636/18 and follow-on rulings)
- Court of Justice of the European Union, GDPR enforcement referral docket
Desk note: The wire bulletins that surfaced the referral did not name the four member states, and the Commission itself omitted them from its headline text. Monexus has therefore described the laggards as a cluster defined by their absence from the transposition tracker rather than identifying them by name; the legal mechanics and the precedent drawn on are public, sourced to EUR-Lex and to the Court's own docket.