Data Privacy & Tech

#E2025J0019EFTA Court finds Norway failed to implement EU cybersecurity rules

🇪🇺European Union··Other·Medium Impact·View source ↗

AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.

🇬🇧 English

Norway failed to put EU cybersecurity rules into national law by the required deadline. The EFTA Court confirmed that Norway did not adopt the measures needed to implement Directive 2016/1148 on network and information system security. The ruling mainly affects Norwegian authorities and regulated digital, communications, and information service sectors. It increases pressure on Norway to complete implementation and align its cybersecurity framework with EEA obligations.

AI-generated summary. May contain errors. Refer to official sources for legal decisions.

Key Changes

  • Confirms that Norway missed the deadline to implement Directive 2016/1148 on cybersecurity
  • Requires Norway to bear the costs of the EFTA Court proceedings
  • Adds formal pressure for Norway to complete its national cybersecurity implementation

Obligations

What this law requires

high

Norway was required under Article 7 of the EEA Agreement to adopt the measures necessary to implement Directive (EU) 2016/1148 on security of network and information systems within the prescribed time limit.

Kingdom of Norway
within the time prescribed by the EEA implementation obligation
operational
high

Norway failed to fulfil its EEA obligations by not adopting the national measures necessary to implement Directive (EU) 2016/1148 within the prescribed time limit.

Kingdom of Norway
operational
medium

The EFTA Court ordered Norway to bear the costs of the infringement proceedings.

Kingdom of Norway
operational

Affected Parties

Norwegian government authoritiesDigital service and electronic communications providers+1 more…

Tags

cybersecurity,NIS Directive,Norway