Criminal charges for not fixing known vulnerabilities? That's a risky road to travel down. Especially given the general state of infosec among various governments around the world and the offensive first mindset of their security agencies.
This sounds like the result of being pressured to appear to be doing something about a very public problem rather than using the justice system to set a meaningful precedent. Especially if enforcement is going to be arbitrarily based on only exceptionally bad cases.
People love to use the courts as a knee jerk reaction to every problem without considering more effective or efficient alternatives first.