On 8 July the European Commission referred Ireland, Spain, France, and the Netherlands to the EU Court of Justice for missing the NIS2 cybersecurity transposition deadline, with daily fines to follow.
Why It Matters
NIS2 is not just a big-enterprise rule. It covers mid-sized manufacturers, digital infrastructure providers, and many suppliers to public bodies as important or essential entities, and enforcement is now real rather than theoretical: Germany's BSI began proactive audits in March, and the Netherlands passed its transposition law on 7 July with enforcement from 15 August, requiring over 8,000 organisations to register with the NCSC and show board-level cybersecurity training.
What To Do About It
If you operate in the Netherlands, register with the NCSC before 15 August; if you supply critical infrastructure, healthcare, digital services, or manufacturing anywhere in the EU, check whether you fall under NIS2 Annex I or II before a regulator asks you first. Ask 3DH for a 30-minute scope check if you are unsure which bucket you are in.
Related Signals
Microsoft's AZ-500 Azure Security Engineer certification retires 31 August 2026, replaced by the new SC-500 Cloud and AI Security Engineer Associate credential.
29 Jul 2026Microsoft made Business Standard with Copilot (23.50 USD/user/month) and Business Premium with Copilot (32 USD/user/month) permanent SKUs on 1 July 2026, for 1 to 300 seats.
28 Jul 2026Pax8 confirmed Microsoft's global Copilot and M365 price rise took effect 1 July 2026, alongside new Purview deployment services and an SMB-focused Copilot sales course for partners.
27 Jul 2026