CEO · NIS2 Article 32

NIS2 Article 32: CEO Management-Ban Request Power

NIS2 Article 32(5)(b) gives competent authorities a request power, routed through national law, to seek temporary management-function bans for CEO- or legal-representative-level managers of essential entities.

In brief: NIS2 Article 32(5)(b) lets competent authorities of essential entities ask the relevant national bodies, courts, or tribunals to temporarily prohibit a CEO- or legal-representative-level manager from exercising managerial functions. Article 20(1) places the underlying cybersecurity risk-management approval and oversight duty on the management body, while personal-liability mechanisms depend on Member State transposition. A four-eyes-approved, versioned, audit-trailed terminology record is one concrete artifact of Article 20(1) approval engagement.

When a supervisor can request a management-function ban

Most regulatory regimes start with the entity: corrective orders and fines. NIS2 goes further for essential entities by requiring Member States to give competent authorities a request power aimed at the named person exercising CEO- or legal-representative-level managerial functions.

Article 32(5)(b) verbatim:

"request that the relevant bodies, courts or tribunals, in accordance with national law, prohibit temporarily any natural person who is responsible for discharging managerial responsibilities at chief executive officer or legal representative level in the essential entity from exercising managerial functions in that entity." NIS2 Directive (EU) 2022/2555, Article 32(5)(b)

The power in Art. 32(5)(b) sits inside Chapter VII (Supervision and Enforcement) and is separate from the underlying duty in Article 20(1), which places cybersecurity risk-management approval and oversight on the management body of essential and important entities. Article 32(5)(b) is for essential entities; the comparable important-entity enforcement article does not contain the same management-ban request power.

The measure is not automatic. It applies through national law after specified prior enforcement measures under Article 32(4) have not led to effective action. The company continues to exist; the named person can be temporarily prohibited from exercising managerial functions in that essential entity.

What this costs the CEO personally

Article 32(5)(b): request power to seek a temporary prohibition on a CEO- or legal-representative-level manager of an essential entity exercising managerial functions, routed through the relevant national body, court, or tribunal.

Article 20(1): management bodies of essential and important entities must approve cybersecurity risk-management measures and oversee implementation. Personal liability for breach of that duty depends on national transposition.

Germany: the German NIS2 implementation law was published as BGBl. 2025 I No. 301 on 5 December 2025 and entered into force the following day. Treat German management-body liability questions as national-law questions for counsel.

A national order affecting a named CEO or legal representative is board-level and counsel-level information. Depending on the facts and jurisdiction, it can matter for debt covenants, D&O renewal questionnaires, M&A disclosure schedules, and investor updates. The Commission issued reasoned opinions to 19 Member States on 7 May 2025 for failure to notify full NIS2 transposition, while Germany's implementation law entered into force on 6 December 2025.

The board meeting question

Boards of NIS2-scoped entities now ask the same question at every cybersecurity agenda item: can we produce evidence that the management body has approved the cybersecurity risk-management measures, on the record, with dates and names? Article 20(1) makes that approval a legal duty; Article 32(5)(b) gives supervisors a management-ban request power for essential entities when prior measures have not worked. The CEO owns the audit-ready answer.

The calendar is tight. Member States had until 17 October 2024 to transpose NIS2; the Commission called on 19 Member States to complete transposition on 7 May 2025. A CEO preparing the next board deck, D&O renewal submission, or acquisition diligence data room cannot leave the Article 20(1) approval trail blank.

How terminology governance helps

Compliance Glossary for Confluence is not a legal shield. It does not build a NIS2 ICT risk-management program or replace Article 21 technical controls. What it produces is one specific artifact: a time-stamped, four-eyes-approved, versioned record of the cybersecurity terminology the management body has formally endorsed — direct evidence of Article 20(1) approval engagement on the vocabulary that defines Article 21 measures.

The economics

For current pricing, see the Atlassian Marketplace.

Frequently asked questions

Can a CEO actually be suspended under NIS2?

NIS2 Article 32(5)(b) requires Member States to give competent authorities power to request that the relevant national bodies, courts, or tribunals temporarily prohibit a CEO- or legal-representative-level manager of an essential entity from exercising managerial functions. It is not automatic, applies through national law, and follows specified prior enforcement measures.

Does NIS2 Article 32 apply to the CEO personally or to the entity?

Both layers exist, but routed differently. Entity-level fines sit in Article 34. The management-ban request power sits in Article 32(5)(b) for essential entities. The underlying duty is Article 20(1) on the management body. Personal-liability mechanisms depend on Member State transposition and should be checked jurisdiction by jurisdiction.

Which sources were checked?

Sources checked 2026-06-22: NIS2 Directive (EU) 2022/2555, the European Commission NIS2 page, the Commission 7 May 2025 reasoned-opinion notice, and Germany's BGBl. 2025 I No. 301.

What evidence does NIS2 Article 20(1) expect the CEO to produce?

Article 20(1) requires management bodies of essential and important entities to approve cybersecurity risk-management measures and oversee their implementation. Supervisors expect a paper trail of active involvement: dated approvals by named management-body members, version history on approved definitions and measures, and the ability to produce those records inside the investigation window.

Does Compliance Glossary prevent a CEO suspension?

No. The product is not a legal shield and does not replace a NIS2 risk-management program or incident-response plan. It produces one specific governance artifact: a versioned, four-eyes-approved, audit-trailed record of the cybersecurity terminology the management body has formally endorsed. That record is evidence of Article 20(1) approval engagement, not a guarantee against enforcement.

Install before the next board meeting

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading