Recital 133

Recital 133

Directive on the security of network and information systems · UE 2022/2555

(133)

In order to further strengthen the effectiveness and dissuasiveness of the enforcement measures applicable to infringements of this Directive, the competent authorities should be empowered to suspend temporarily or to request the temporary suspension of a certification or authorisation concerning part or all of the relevant services provided or activities carried out by an essential entity and request the imposition of a temporary prohibition of the exercise of managerial functions by any natural person discharging managerial responsibilities at chief executive officer or legal representative level. Given their severity and impact on the entities’ activities and ultimately on users, such temporary suspensions or prohibitions should only be applied proportionally to the severity of the infringement and taking account of the circumstances of each individual case, including whether the infringement was intentional or negligent, and any actions taken to prevent or mitigate the material or non-material damage. Such temporary suspensions or prohibitions should only be applied as a last resort, namely only after the other relevant enforcement measures laid down in this Directive have been exhausted, and only until the entity concerned takes the necessary action to remedy the deficiencies or comply with the requirements of the competent authority for which such temporary suspensions or prohibitions were applied. The imposition of such temporary suspensions or prohibitions should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to issue the certification suspension and temporary management prohibition measures referred to in recital 133. ILR decisions can be appealed before the administrative tribunal, securing the right to effective remedy required by the Charter.

Luxgap practice: for Luxembourg essential entities (Creos, Encevo, POST, LuxConnect, eBRC, CHL, etc.), we recommend maintaining a timestamped remediation log transmissible to the ILR within 5 working days of any injunction, to prove that intermediate measures have not yet been exhausted.