On 8 July the European Commission referred Ireland, Spain, France, and the Netherlands to the EU Court of Justice for missing the NIS2 cybersecurity transposition deadline, with daily fines to follow.
Why It Matters
NIS2 is not just a big-enterprise rule. It covers mid-sized manufacturers, digital infrastructure providers, and many suppliers to public bodies as important or essential entities, and enforcement is now real rather than theoretical: Germany's BSI began proactive audits in March, and the Netherlands passed its transposition law on 7 July with enforcement from 15 August, requiring over 8,000 organisations to register with the NCSC and show board-level cybersecurity training.
What To Do About It
If you operate in the Netherlands, register with the NCSC before 15 August; if you supply critical infrastructure, healthcare, digital services, or manufacturing anywhere in the EU, check whether you fall under NIS2 Annex I or II before a regulator asks you first. Ask 3DH for a 30-minute scope check if you are unsure which bucket you are in.