NIS2: essential entity — Malta

The NIS2 law of Malta (Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order) defines who is a “essential entity”. Below is the relevant provision of the law, verbatim, with the official source reference.

What the law says

shall be considered to be essential entities: (a) entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of the Annex to the Commission Recommendation 2003/361/EC; (b) qualified trust service providers and top-level domain

Reference: S.L. 460.41, article 4

The size threshold is based on the medium-sized enterprise definition of Commission Recommendation 2003/361/EC, to which the provision refers.

View official source

Is your company in scope?

The scope of the obligations depends on entity type and size — within the same sector a company can be an essential entity, an important entity, or out of scope. The free applicability check gives the exact answer.

Start the free applicability check

Frequently asked questions

Who is a “essential entity” (Malta)?

The law of Malta (S.L. 460.41, S.L. 460.41, article 4) defines this directly — the provision text is on this page, verbatim.

Is my company a “essential entity”?

It depends on the sector of activity and the size of the company — the basis is in the provision (S.L. 460.41, article 4). The free applicability check gives the precise answer.

In which law is “essential entity” defined?

Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order — S.L. 460.41, S.L. 460.41, article 4. The official source link is on this page.

Back to home