NIS2: important entity — Malta
The NIS2 law of Malta (Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order) defines who is a “important entity”. Below is the relevant provision of the law, verbatim, with the official source reference.
What the law says
to sub-article (1) shall be considered to be important entities. This includes entities identified by the CIP Department or where designated the competent authority as important entities pursuant to articles 3(3)(b) to (e). PART II – ENFORCEMENT COMMITTEE, CRITICAL INFRASTRUCTURE PROTECTION DEPARTMENT AND CSIRTsReference: S.L. 460.41, article 4
The size threshold is based on the medium-sized enterprise definition of Commission Recommendation 2003/361/EC, to which the provision refers.
Is your company in scope?
The scope of the obligations depends on entity type and size — within the same sector a company can be an essential entity, an important entity, or out of scope. The free applicability check gives the exact answer.
Frequently asked questions
Who is a “important entity” (Malta)?
The law of Malta (S.L. 460.41, S.L. 460.41, article 4) defines this directly — the provision text is on this page, verbatim.
Is my company a “important entity”?
It depends on the sector of activity and the size of the company — the basis is in the provision (S.L. 460.41, article 4). The free applicability check gives the precise answer.
In which law is “important entity” defined?
Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order — S.L. 460.41, S.L. 460.41, article 4. The official source link is on this page.