EU directive
Also known as: directive
A type of EU law that sets goals every member state must reach, but lets each country write its own national law to do it.
Draft - this entry has not been reviewed yet.
Formal
A legal act of the European Union that is binding on each member state as to the result, but leaves the form and method to national authorities; it must be written into national law by a deadline, as with NIS2 and the Danish NIS2 Act.
In plain English
Like a parent telling several teenagers "your rooms must be clean by Sunday" - the goal is fixed, but each decides how to get there.
In practice
The IT department of a Danish region does not read NIS2 itself to find its hospitals' duties; it follows the Danish NIS2 Act, which puts the directive into force and names the Danish authorities.
Why it matters
Because each country writes its own version, details and deadlines can differ between countries, so organisations working across borders must check each national law.
Technical deep dive
Article 288 TFEU defines a directive as binding, as to the result to be achieved, upon each member state to which it is addressed, while leaving to the national authorities the choice of form and methods. Most security-relevant directives, including NIS2 (Directive (EU) 2022/2555) and the CER Directive (2022/2557), are adopted under the ordinary legislative procedure (Art. 294 TFEU), published in the Official Journal and enter into force on the date they specify or, failing that, on the twentieth day after publication (Art. 297). Entry into force starts the transposition period; the obligations reach organisations only through the national implementing measures, which must be notified to the Commission, often with a correlation table.
The harmonisation level determines how much national variation is possible. Minimum-harmonisation directives allow stricter national rules; NIS2 Art. 5 expressly permits member states to adopt or maintain provisions ensuring a higher level of cybersecurity, which is why sector scope, supervisory models and penalty procedures differ between countries. Adding requirements beyond the directive is called gold-plating. Maximum-harmonisation directives, common in consumer and financial law, forbid such deviations within their scope. Where uniformity is essential, the EU chooses a regulation instead, as it did for GDPR and DORA.
The Court of Justice has developed doctrines for when transposition fails or is incomplete. After the deadline, provisions that are unconditional and sufficiently precise have vertical direct effect and can be invoked against the state and emanations of the state (Van Duyn, 41/74; Ratti, 148/78), but not against private parties, because directives have no horizontal direct effect (Marshall, 152/84; Faccini Dori, C-91/92). National courts must nevertheless interpret national law as far as possible in conformity with the directive (von Colson, 14/83; Marleasing, C-106/89), and individuals can claim damages from a state for serious failures to transpose (Francovich, C-6/90 and C-9/90). For a private company, the practical rule is therefore: your duties come from the national law, read in the light of the directive.
Non-transposition is enforced under Art. 258 TFEU, and Art. 260(3) allows the Commission to ask the Court for financial penalties already in the first referral when a member state fails to notify transposition measures. NIS2 illustrates the sequence: the transposition deadline was 17 October 2024; the Commission sent letters of formal notice to 23 member states, including Denmark, on 28 November 2024 and reasoned opinions to 19 on 7 May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court with a request for penalties. Denmark transposed through the NIS2-loven, in force from 1 July 2025, supplemented by executive orders (bekendtgørelser) and sector rules. Cross-border groups must therefore map each national transposition separately, including registration deadlines, authority contacts and incident-reporting channels.
What to learn first
Everything this builds on, foundations first.
- Compliance
- →EU directive
Relationships
- Requires
- Compliance
- Don't confuse with
- EU regulation
Sources & further reading
Standards & official texts
- Treaty on the Functioning of the European Union, Article 288
Official documentation
Course material
- Cyber Security Fast Track - Kursuskompendium, Ordliste (NIS2-direktivet)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…