NIS2 Fines and Sanctions in Malta: Amounts, Percentages and Management Responsibility
Who enforces NIS2 penalties in Malta?
In Malta, the NIS2 Directive is transposed by the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring implementation of the order and ensuring compliance with it (article 7).
When the CIP Department, or where designated the competent authority, finds non-compliance, it can request the imposition of an administrative penalty by the Enforcement Committee (article 29(7) and article 30(7)). The Committee has the power to impose the administrative fines established by the order on any entity reported as non-compliant (article 33).
Before deciding, the Committee must allow the entity to provide documentation or make submissions (article 33(2)). Its decision indicates the amount of the penalty, a timeframe for payment and a timeframe to remedy the breach, with reasons given (article 33(5)).
Maximum fines for essential and important entities
The core numbers are set out in article 32. Fines apply specifically to infringements of the cybersecurity risk-management measures (article 19) or the reporting obligations (article 20).
| Classification | Maximum administrative penalty |
|---|---|
| Essential entity | A maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher (article 32(3)) |
| Important entity | A maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of the total worldwide annual turnover in the preceding financial year, whichever is higher (article 32(4)) |
Two points matter for your budget planning:
- The rule is "whichever is higher" — for a larger group, the turnover-based percentage can far exceed the fixed euro ceiling.
- Administrative penalties are imposed in addition to the enforcement measures listed in article 29(6)(a) to (k), article 30(6)(a) to (k) and article 31(10) (article 32(1)).
Administrative penalties may also be imposed against public administration entities (article 32(5)).
Enforcement measures come before (and alongside) fines
A financial penalty is not the only tool. The CIP Department, or where designated the competent authority, holds a broad set of supervisory and enforcement powers.
For essential entities, supervisory measures include on-site inspections and off-site supervision, regular and targeted security audits, ad hoc audits, security scans, and requests for information and evidence (article 29(2)). Enforcement powers include issuing warnings, adopting binding instructions, ordering the entity to cease infringing conduct, ordering compliance with articles 19 and 20, designating a monitoring officer, and ordering the entity to make aspects of infringements public (article 29(6)).
For important entities, the CIP Department acts through ex post supervisory measures where there is evidence, indication or information of non-compliance (article 30(1)). Its supervisory and enforcement toolkit is comparable, including inspections, targeted audits, binding instructions and cease orders (article 30(2) and article 30(6)).
In every case, supervisory and enforcement measures must be effective, proportionate and dissuasive, taking into account the circumstances of each individual case (article 29(1) and article 30(1)).
Management and personal responsibility
NIS2 in Malta does not treat cybersecurity as a purely technical matter delegated down the organisation. It reaches the top of the entity.
Under article 18, the CIP Department, or where designated the competent authority, ensures that the management bodies of essential and important entities approve the cybersecurity risk-management measures under article 19 and oversee their implementation (article 18(1)).
Crucially, the order states that the natural persons composing the management bodies may be held liable for infringements by the entity of article 19, in accordance with articles 31(10)(b) and 33 (article 18(1)). This liability applies without prejudice to national law on the liability rules applicable to public institutions and to public servants and elected or appointed officials (article 18(2)).
Management bodies are also required to follow training to carry out their tasks, and entities must offer similar training to their employees on a regular basis so they can identify risks and assess cybersecurity practices (article 18(3) and article 18(4)).
The exact procedural detail for how personal liability is pursued in a given case is [TÄPSUSTAB PARTNER-JURIST].
How to reduce your exposure before enforcement begins
The obligations that trigger fines are concrete and testable, so the most effective way to reduce risk is to close gaps before the CIP Department acts.
Priorities include:
- Confirm your classification as an essential entity or important entity under article 4, since this determines your maximum penalty exposure.
- Implement the article 19 measures — an all-hazards approach covering risk analysis, incident handling, business continuity, supply chain security, cyber hygiene and training, cryptography, access control, multi-factor authentication and logging (article 19(2)).
- Prepare your reporting process for the article 20 deadlines: an early warning within 24 hours, an incident notification within 72 hours, and a final report not later than one month after the notification (article 20(5)).
- Get management engaged — the board must approve and oversee the measures, and members must be trained (article 18).
A structured scoping and gap assessment helps you see where you stand against articles 18, 19 and 20 today. Use our free scoping and gap tool to map your current position and prioritise the fixes that matter most.
Frequently asked questions
What is the maximum NIS2 fine for an essential entity in Malta?
For infringements of articles 19 or 20, essential entities are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher (article 32(3)).
What is the maximum fine for an important entity?
For infringements of articles 19 or 20, important entities are subject to administrative penalties of a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of the total worldwide annual turnover in the preceding financial year, whichever is higher (article 32(4)).
Can managers be held personally liable under NIS2 in Malta?
Yes. Management bodies of essential and important entities must approve the cybersecurity risk-management measures and oversee their implementation, and the natural persons composing those management bodies may be held liable for infringements of article 19, in accordance with articles 31(10)(b) and 33 (article 18(1)).
Who imposes the fines and who reports non-compliance?
The CIP Department, or where designated the competent authority, may request the imposition of an administrative penalty (article 29(7) and article 30(7)). The Enforcement Committee then has the power to impose the administrative fines established by the order (article 33).
Check your NIS2 compliance
The complete NIS2 guide — Malta →
This article is general information, not legal advice. A partner lawyer confirms your specific situation.