#E2025J0020EFTA Court finds Norway failed to implement EU cybersecurity rules
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
Norway failed to bring EU rules on cybersecurity risk management and incident impact reporting for digital service providers into its national law. The ruling mainly affects Norway’s government and digital service providers operating under EEA rules, including online marketplaces, search engines and cloud services. Norway must now cover the court costs and is expected to fix the gap in its national framework.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- The EFTA Court confirmed that Norway failed to implement EU cybersecurity rules for digital service providers.
- Norway must make Commission Implementing Regulation (EU) 2018/151 part of its national legal order.
- Norway was ordered to pay the costs of the proceedings.
Obligations
What this law requires
The EFTA Court declared that Norway failed to fulfil its Article 7 EEA Agreement obligation by not making Commission Implementing Regulation (EU) 2018/151, as adapted for the EEA, part of its internal legal order.
Commission Implementing Regulation (EU) 2018/151 specifies the elements digital service providers must take into account when managing risks to the security of network and information systems under Directive (EU) 2016/1148.
Commission Implementing Regulation (EU) 2018/151 specifies parameters for determining whether a network and information systems security incident has a substantial impact for purposes of incident assessment under Directive (EU) 2016/1148.
The EFTA Court ordered Norway to bear the costs of the infringement proceedings.