#E2025J0019EFTA Court finds Norway failed to implement EU cybersecurity rules
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
Norway failed to put EU cybersecurity rules into national law by the required deadline. The EFTA Court confirmed that Norway did not adopt the measures needed to implement Directive 2016/1148 on network and information system security. The ruling mainly affects Norwegian authorities and regulated digital, communications, and information service sectors. It increases pressure on Norway to complete implementation and align its cybersecurity framework with EEA obligations.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Confirms that Norway missed the deadline to implement Directive 2016/1148 on cybersecurity
- Requires Norway to bear the costs of the EFTA Court proceedings
- Adds formal pressure for Norway to complete its national cybersecurity implementation
Obligations
What this law requires
Norway was required under Article 7 of the EEA Agreement to adopt the measures necessary to implement Directive (EU) 2016/1148 on security of network and information systems within the prescribed time limit.
Norway failed to fulfil its EEA obligations by not adopting the national measures necessary to implement Directive (EU) 2016/1148 within the prescribed time limit.
The EFTA Court ordered Norway to bear the costs of the infringement proceedings.