Why the EU is suing four countries over NIS2—and what that means for backup security
The European Commission has taken Ireland, France, Spain, and the Netherlands to the Court of Justice of the European Union for failing to implement the NIS2 Directive. The case is one of the EU's largest actions to date to enforce cybersecurity. In this blog, we’ll explain what the lawsuit is about, what happens next, and why NIS2 matters for backup and recovery security.
Why the EU escalated the case
The core issue is that the transposition deadline was missed. NIS2 is an EU directive, which means each country within the EU needs to pass its own national laws to implement it. Ireland, France, the Netherlands, and Spain did not notify the Commission that they had fully transposed the directive.
Under EU law, failure to transpose a directive by the deadline is a violation in and of itself. The Commission followed the standard infringement sequence: formal notice, reasoned opinion, and finally, referral to the Court. The Commission escalated the case in July 2026, roughly 20 months after the formal deadline.
Article 41(1) is the specific legal basis for the lawsuit. It requires member states of the EU to adopt and publish national measures implementing NIS2 and missing that obligation triggered the referral to the Court.
Status of the lawsuit and what happens next
The case is now before the Court of Justice. The Commission has requested both lump‑sum fines and daily penalties until each country completes transposition. The Court will review the infringement and determine financial consequences.
Member states typically accelerate legislative work once a case reaches this stage. The Netherlands has already passed its law; Ireland, France, and Spain are expected to finalise theirs to limit ongoing penalties.
Why NIS2 compliance matters for backup data security
NIS2 highlights the need for dependable recovery and continuity. Backup storage plays a direct role in meeting several of the directive’s risk‑management requirements:
-
Data availability: Backups ensure data remains accessible when primary systems fail to ransomware, insider threats, or natural disasters.
-
Business continuity: Recovery plans depend on clean, usable backup data to restore operations within required timeframes.
-
Ransomware resistance: Immutable backups prevent attackers from altering or deleting backup data.
-
Incident evidence: Backups preserve historical information needed for investigation and mandatory reporting.
-
Recovery speed: Reliable restore processes reduce downtime after an operational disruption.
If backup data can’t be restored—untampered and reliably—and within required timeframes per Article 23 (24-hour early warning, 72-hour incident notification, and 30-day final report), an organisation cannot fulfill NIS2 obligations for incident response, reporting, or continuity.
With the lawsuit, the EU is demonstrating how serious it is about NIS2 being put into action in member states. Consequently, organisations throughout the EU can expect closer scrutiny on their own compliance with the regulation.
Resources to help you meet NIS2 requirements
Object First has a few resources that explain what NIS2 requires and how organisations can evaluate their readiness.
The NIS2 Directive white paper explains the directive’s scope, the difference between essential and important entities, the specific risk‑management measures required under Article 21, and how secure, immutable backups fit into business continuity and incident‑response expectations. It also outlines how NIS2 changes supervisory oversight and what organisations should expect once national enforcement begins.
The NIS2 compliance checklist provides a practical way to assess current posture. It walks through required security controls, incident‑reporting readiness, backup and recovery resilience, supply‑chain considerations, and documentation requirements. Teams can use it to identify gaps, prioritise remediation, and prepare for audits once their country’s transposition is complete.
