BLOG

Date
06-10-2026

Regulatory Compliance

The NIS2 Patchwork: What Four CJEU Referrals Mean for Vendors Selling Into Europe

On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to transpose the NIS2 Directive into national law. The Commission asked the Court to impose lump sum payments and daily penalties until transposition is notified. The original deadline was 17 October 2024, which makes those four states roughly twenty months late.

For a North American industrial operator or equipment vendor, this is not European political theater. It is the reason your European customers cannot give you a straight answer about what they need from you. A directive is not directly binding on companies. It binds member states to write national law, and until that law exists, the obligations your customer will push down to you are undefined. Understanding that gap is the difference between a useful OT cybersecurity program and one built on guesswork.

Why a directive creates a patchwork and a regulation does not

This is the single most useful thing to understand about NIS2. The directive sets the floor. Each member state writes its own law on top, and they diverge on the details that actually cost money: which entities get registered, what counts as a significant incident locally, how quickly supervisory authorities act, and how far obligations are pushed down the supply chain.

Contrast that with the Cyber Resilience Act, which is a regulation and therefore applies directly and uniformly across all 27 states with no national transposition. If you build equipment, that distinction matters enormously, and our guide to CRA applicability for industrial equipment covers the product side.

The practical consequence for your contracts

A customer in a transposed state has a legal basis to demand specific evidence from you. A customer in a non-transposed state is often demanding things based on the directive text or on their parent company policy, which may be stricter or looser than the law they will eventually face. Both situations are real, and they call for different responses. Do not sign to the stricter reading by default.

 

Where the four referrals leave operators in those states

A company operating in Ireland, Spain, France or the Netherlands is in an awkward position. There is no national law to comply with yet, so there is no supervisory authority issuing penalties under it. But the law is coming, it will arrive under political pressure, and transitional periods are likely to be short because the state is already years late.

What we see working: build to the directive text and to IEC 62443, not to a guess at the national law. The ten risk management measures in Article 21 are in the directive itself and will appear in every national implementation. Building against those is safe. Guessing at national registration thresholds is not.

What varies, and what never does

Consistent across all states

Varies by national law

The ten Article 21 risk management measures, including supply chain security

Registration mechanics, deadlines and which authority you register with

The 24 hour, 72 hour and one month reporting structure

Local thresholds for what counts as a significant incident

Management body accountability and the training duty

Whether personal sanctions on managers are available, and how severe

Essential and important entity categories

Sector scoping at the margins, and which entities get designated regardless of size

Fine floors of 10 million euro or 2 percent for essential entities

National ceilings, which may be higher than the floor

 

The left column is where you should spend your budget. It is stable, it is where most of the engineering work sits, and it transfers directly to IEC 62443 work you may already have underway.

What North American vendors should do now

  • Map your European exposure by country, not by region. Which customers are in transposed states, which are not. That single table will answer most inbound questionnaires.
  • Build one evidence pack, not twenty-seven. Answer to the directive and to 62443, then map that evidence to whichever national law a customer cites.
  • Push back on contract language that references a law that does not exist yet. Commit to the directive obligations, not to an unwritten national implementation.
  • Watch the four referred states closely. When those laws land they will land fast, and your customers there will come to you with short deadlines.

Our supply chain cyber risk assessment playbook sets out the method we use to build and defend an evidence pack.

Why Choose Arista Cyber

We work on live industrial assets across North America and the Gulf, and we read regulation the way an engineer has to: what does this require me to change on a running plant. Our consultants carry functional safety and OT security credentials, which means compliance advice from us accounts for what a change does to a safety case. Our case studies show how that works in practice.

Next Steps

Start with an exposure map and a gap assessment against the Article 21 measures. That is stable ground regardless of how the four referrals resolve, and it is the evidence base your European customers will ask for. Pair it with an OT risk assessment if your baseline has not been reviewed against the directive.

Common Questions

Which countries have transposed NIS2?

The picture changes month to month. As of the July 2026 referrals, Ireland, Spain, France and the Netherlands had not transposed and were sent to the CJEU. Several other states transposed late, and a number have partial implementations. Check a current tracker rather than relying on any article, including this one, for the live status.

Does NIS2 apply to my company if we are based in the US or Canada?

Not directly. NIS2 binds entities operating in the EU. It reaches you through your customers, who must manage supply chain security under Article 21(2)(d) and will pass requirements down contractually.

What penalties are the referred states facing?

The Commission asked the Court to impose lump sum amounts and daily penalties until full transposition is notified. These are penalties on the member states, not on companies.

Should we comply with the directive or wait for national law?

Build to the directive and to IEC 62443. The Article 21 measures appear in every national implementation, so that work is never wasted. Hold off only on country-specific mechanics such as registration.

Is the Cyber Resilience Act affected by the same delays?

No. The CRA is a regulation, so it applies directly in all member states with no national transposition. Its reporting duties have been live since September 2026.

Which of your European customers can actually enforce what they are asking for?

Arista Cyber maps NIS2 exposure by jurisdiction for North American operators and vendors, separating the stable directive obligations from national variation so you build once and answer many.

Request a NIS2 exposure review

BOOK YOUR CONSULTATION