|8 min read|Yvann Lièvre

NIS2: France Before the CJEU, What the Deadline Changes for Companies

The Commission referred France to the CJEU on July 8, 2026 for failing to transpose NIS2. Penalties loom and the resilience law is delayed: what to anticipate.

ComplianceNIS2RegulationSigma
NIS2: France Before the CJEU, What the Deadline Changes for Companies

On July 8, 2026, the European Commission officially referred France to the Court of Justice of the European Union for failing to transpose the NIS2 cybersecurity directive. France is not the only one targeted: Ireland, the Netherlands, and Spain face the same procedure. For French companies that have followed this file for months, this step marks a change in nature: it moves from an administrative delay to litigation accompanied by a demand for financial penalties.

What the referral concretely means

The Commission asks the Court to impose financial penalties on France, in the form of a lump sum coupled with daily penalties, until the directive's rules are fully transposed. France is already more than twenty months behind on various rules meant to strengthen the security of computer networks, and faces a flat-rate fine that could run into the millions of euros, not counting daily penalties of several tens of thousands of euros until the law is published.

These penalties target the state, not companies. But they have a direct consequence for the latter: they accelerate the deadline. A government under daily penalty no longer has any interest in letting transposition drag. European financial pressure becomes a schedule driver.

The resilience law, vehicle of transposition

In France, the bill on the resilience of critical infrastructure and the strengthening of cybersecurity is the one meant to transpose NIS2 into domestic law. Its examination was postponed again, at the earliest to the September 2026 parliamentary session, a delay announced in early July by the minister delegate for artificial intelligence and digital affairs, Anne Le Hénanff. The combination of this delay and the CJEU referral creates a paradoxical situation: the text is late, but the pressure to adopt it has never been stronger.

Why companies must prepare now

It would be tempting for a company to consider that until the law is published, nothing obliges it. That reasoning is risky for three reasons. First, the scope of NIS2 is vast: the directive concerns a far greater number of entities than its predecessor, estimated at several thousand organizations in France, across a large number of sectors deemed essential or important. Many companies not covered by NIS1 will be covered by NIS2.

Next, the penalties the directive provides for non-compliant entities are significant, on the order of several million euros or a percentage of worldwide annual turnover for the most critical entities. These amounts alone justify early preparation, because compliance is not achieved in a few weeks.

Finally, the substantive requirements of NIS2, risk management, technical measures, incident notification within short deadlines, are independent of the legislative calendar. An organization that puts in place now a capacity to detect and notify incidents will be ready the day the law enters into force, without haste.

Detection at the heart of compliance

An often underestimated aspect of NIS2 is its requirement regarding incident detection and notification. The directive imposes short reporting deadlines, which presupposes having a capacity to spot an incident quickly. You only notify what you detect. A company that approaches NIS2 solely through the documentary lens, drafting policies without acquiring operational detection means, will find itself unable to meet the notification deadlines when the time comes.

This is where compliance meets the daily practice of security. Having up-to-date detection rules, able to spot common attack techniques on your estate, is not just good practice: it is a prerequisite for meeting NIS2's notification obligations. Regulatory compliance and operational detection are two sides of the same preparation.

Building a detection capacity ready for NIS2's notification requirements requires maintained rules covering current threats. That is what the ThreatClaw Sigma feed provides: up-to-date detection rules, ready to integrate into a SIEM, to turn a regulatory obligation into a concrete ability to spot and notify incidents on time.

Related articles