· Kai Roer

The EU is suing France over NIS2. What that means for your board.

The European Commission is taking France and three other states to court over NIS2. The real signal for boards is not the delay, but what enforcement now expects.

The EU is suing France over NIS2. What that means for your board.

The European Commission has filed infringement proceedings against Ireland, Spain, France, and the Netherlands for failing to transpose NIS2 into national law by the October 2024 deadline. More than twenty months after the deadline passed, these four member states still had not completed the legal work required to make NIS2 enforceable within their borders. The Commission is now asking the Court of Justice of the European Union to impose lump-sum payments and daily penalties until transposition is completed.

Most coverage has treated this as a story about government incompetence. Four countries missed a deadline, the Commission is annoyed, and eventually everyone will comply. That reading misses the point.

The signal is not the delay. The signal is the response.

The Commission had options. It could have issued warnings and waited. It could have treated transposition delay as a political inconvenience and let bilateral pressure do the work. Instead, it filed legal proceedings against four sovereign governments, including two of the largest economies in the EU. That is not a procedural step. It is a statement of intent.

If Brussels is willing to take France to court over NIS2 transposition, the idea that enforcement of the directive itself will be soft or slow becomes difficult to sustain. The Commission is demonstrating, with legal action, that it considers NIS2 non-optional at every level — from the member states that must adopt it to the organisations that must comply with it.

The provision boards need to read

NIS2 Article 20 introduces something that most prior cybersecurity regulation carefully avoided: personal liability for management bodies. Not organisational fines. Not reputational risk. Personal liability for named members of management bodies who fail to approve, oversee, or ensure compliance with the cybersecurity risk-management measures required under Article 21.

The significance of this provision is structural. Under most prior frameworks, a board’s exposure to cybersecurity failure was indirect. Something went wrong, the organisation paid a fine, and the responsible executive — usually the CISO — was replaced. The board’s role was to delegate, not to demonstrate personal oversight.

Article 20 closes that option. It requires management bodies to approve the measures, to undergo training, and to oversee their implementation. “We delegated it to the security team” is not a defence when the directive specifically names management body members as personally accountable.

This is not speculation about how NIS2 might be interpreted. It is what the text says.

The wrong question and the right one

Many boards are still asking “when does NIS2 apply to us?” That question made sense in 2023. In the second half of 2026, with the Commission suing member states over transposition delays and the directive’s obligations already live in those states that have transposed, the question has become a way to defer action.

The more useful question is: what would we show an auditor if they asked tomorrow?

Waiting for national transposition before preparing is a strategy. It has the advantage of delaying cost and effort. It has the disadvantage of assuming that when transposition happens, organisations will have enough lead time to build their evidence record. The historical pattern in EU regulation does not support that assumption. GDPR enforcement arrived faster than most organisations expected after a two-year grace period they had been fully aware of.

NIS2 Article 21(2)(f) requires organisations to have “policies and procedures to assess the effectiveness of cybersecurity risk-management measures.” That is not a requirement you can satisfy quickly. It requires a process — a live, documented, ongoing process — that produces evidence over time. An organisation that begins building that process after national transposition is confirmed will have no historical evidence to show. The process will exist. The evidence trail will be empty.

What the infringement action actually tells you

The Commission’s decision to sue four member states is a data point, not an anecdote. It tells you three things about how NIS2 enforcement is likely to unfold.

First, the Commission treats NIS2 compliance as non-negotiable. If it will take sovereign governments to court for transposition delay, the idea that organisational non-compliance will be tolerated is implausible.

Second, the enforcement appetite exists now, not in some future period. These proceedings were filed while the majority of EU member states had still not completed transposition. The Commission did not wait for full adoption before acting. It acted while the framework was still being implemented. That sequencing matters.

Third, the personal liability provision in Article 20 has teeth precisely because the broader enforcement posture is aggressive. A personal liability provision in a softly enforced directive is a paper risk. A personal liability provision in a directive the Commission is willing to litigate over is a different thing entirely.

The question boards should be answering

The story here is not that four governments were slow to transpose a directive. Governments are routinely slow to transpose directives. The story is that the Commission chose to respond with legal action, at speed, against major member states. That response is a preview of how NIS2 will be enforced at every level.

The direction is clear. The question is whether your organisation will have an evidence record — a documented, ongoing, time-stamped process for assessing the effectiveness of your security measures — when enforcement reaches you.

Building that record takes time.

For the full regulatory argument and enforcement precedents, read the white paper: Measuring Security Control Effectiveness: From Attestation to Evidence

Ready to see your employees' security behaviors?

Connect your Microsoft 365 and see months of behavioral data in 15 minutes. Free 30-day trial — no credit card, no sales call.

Start Free Trial