NIS2: essential entity — Malta
The NIS2 law of Malta (Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order) defines who is a “essential entity”. Below is the relevant provision of the law, verbatim, with the official source reference.
What the law says
shall be considered to be essential entities: (a) entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of the Annex to the Commission Recommendation 2003/361/EC; (b) qualified trust service providers and top-level domainReference: S.L. 460.41, article 4
The size threshold is based on the medium-sized enterprise definition of Commission Recommendation 2003/361/EC, to which the provision refers.
Is your company in scope?
The scope of the obligations depends on entity type and size — within the same sector a company can be an essential entity, an important entity, or out of scope. The free applicability check gives the exact answer.
Frequently asked questions
Who is a “essential entity” (Malta)?
The law of Malta (S.L. 460.41, S.L. 460.41, article 4) defines this directly — the provision text is on this page, verbatim.
Is my company a “essential entity”?
It depends on the sector of activity and the size of the company — the basis is in the provision (S.L. 460.41, article 4). The free applicability check gives the precise answer.
In which law is “essential entity” defined?
Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order — S.L. 460.41, S.L. 460.41, article 4. The official source link is on this page.