NIS2 incident notification in Malta: a practical step-by-step guide
Step 1 — When does the notification duty actually start?
In Malta, the reporting duty sits in article 20 of the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Article 20(1) requires essential entities and important entities to *immediately notify the national CSIRT of any incident that has a significant impact on the provision of their services*.
So the trigger is not "any alert" and not "any malware find". The trigger is significant impact on the provision of your services, and the clock starts from the moment you become aware of that significant incident (article 20(5)).
Important source note: the national extract of article 20 does not itself spell out the test for what makes an incident "significant". On this point the national text is silent, and directive (EU) 2022/2555 art 23(3) provides the baseline definition: an incident is significant if
- it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; or
- it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
Any further sector-specific or quantitative thresholds applicable in Malta: [Verify this: Critical Infrastructure Protection Department (official source).].
Two practical points that reduce hesitation in the first hour:
- Article 20(1) states expressly that the mere act of notification shall not subject the notifying entity to an increased liability. Reporting is not a confession.
- Beyond the authorities, article 20(2) requires you, where appropriate, to notify the recipients of your services without undue delay of significant incidents likely to adversely affect those services; article 20(4) adds a duty to communicate remedies to recipients potentially affected by a significant cyber threat.
Step 2 — Whom do you notify, and through which channel?
Primary recipient: the national CSIRT. Article 20(1) points the notification to the national CSIRT, which under article 8(1) of S.L. 460.41 is established within the Malta Information Technology Agency and is responsible for incident handling.
You do not have to chase the rest of the chain. Article 20(1) provides that the national CSIRT shall *immediately notify in writing* the Critical Infrastructure Protection Department (CIP Department) and any other designated competent authority concerned. The CIP Department is the national supervisory authority monitoring implementation and compliance (article 7(1)) and also exercises the single point of contact liaison function for cross-border cooperation (article 7(3)).
The channel/form. The exact electronic notification portal or form to be used: [Verify this: Critical Infrastructure Protection Department (official source).]. Two things you can and should fix in advance:
- Register first. Article 7(3)(c) and article 7(4) require essential and important entities providing services in Malta to register on the national self-registration mechanism established by the CIP Department, providing the entity name, the CSIRT providing monitoring services, address and up-to-date contact details (including email addresses, IP ranges and telephone numbers), the relevant sector/sub-sector, and the Member States where in-scope services are provided.
- Keep it current. Article 7(5): changes to those details must be notified to the CIP Department without delay and in any event within two (2) weeks of the change. Stale contact data is the most common reason an incident notification fails to reach the right desk.
Name your security liaison officer (article 19(1)(c)) as the operational point of contact towards the CIP Department or designated competent authority — that is one of the officer's statutory tasks under article 19(1)(c)(iv).
Step 3 — In what form and stages: the four submissions
Article 20(5) of S.L. 460.41 sets out a staged reporting flow to the national CSIRT. Each stage has its own content requirement.
| Stage | Content required by article 20(5) |
|---|---|
| Early warning | Where applicable, indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact |
| Incident notification | Update the early-warning information and give an initial assessment of the incident, including its severity and impact, plus, where available, indicators of compromise |
| Intermediate report | Relevant status updates — submitted upon the request of the national CSIRT |
| Final report | (i) a detailed description of the incident, including severity and impact; (ii) the type of threat or root cause likely to have triggered it; (iii) applied and ongoing mitigation measures; (iv) where applicable, the cross-border impact |
| Progress report (ongoing incident) | If the incident is still ongoing when the final report is due, submit a progress report at that time, and the final report within one (1) month of handling the incident (article 20(5)(e)) |
One notification is not enough. Treat the early warning as a short alert, the 72-hour notification as your first real assessment, and the final report as the closing forensic and lessons-learned document.
Step 4 — The deadlines, exactly as Maltese law states them
All deadlines below run from becoming aware of the significant incident and appear in article 20(5) and 20(6) of S.L. 460.41:
| Submission | Deadline |
|---|---|
| Initial notification to the national CSIRT | Immediately (article 20(1)) |
| Early warning | Without undue delay and in any event within twenty-four (24) hours |
| Incident notification | Without undue delay and in any event within seventy-two (72) hours |
| Intermediate report | On request of the national CSIRT (no fixed period stated) |
| Final report | Not later than one (1) month after submission of the incident notification |
| Final report where the incident is still ongoing | Within one (1) month of handling the incident, preceded by a progress report |
| Trust service providers — derogation from the 72-hour stage | Notify without undue delay and in any event within twenty-four (24) hours of becoming aware of a significant incident affecting the provision of trust services (article 20(6)) |
What you get back: under article 20(7) the national CSIRT shall provide, without undue delay and where possible within twenty-four (24) hours of receiving the early warning, a response with initial feedback and, on request, guidance or operational advice on mitigation measures — plus additional technical support where the capability is available.
Step 5 — What happens after you report, and what if you do not
Criminal dimension. Where the significant incident is reasonably suspected to be a criminal offence, article 20(8) provides that the national CSIRT, the CIP Department or the designated competent authority shall also give guidance on reporting the incident to the Executive Police.
Cross-border and public communication. Under article 20(9), where the incident concerns Malta and at least one other Member State, the national CSIRT (in prior coordination with the CIP Department) informs the other affected Member State and ENISA, while preserving your security, commercial interests and confidentiality. Under article 20(10), where public awareness is necessary or otherwise in the public interest, the national CSIRT may — after consulting you — inform the public or require you to do so.
Non-compliance is expressly enforceable. The CIP Department or designated competent authority may order an entity to fulfil the reporting obligations established in article 20 in a specified manner and within a specified period (article 29(6)(d) for essential entities, article 30(6)(d) for important entities), among a wide range of supervisory and enforcement measures, including audits and binding instructions.
Administrative penalties (article 32). For infringements of articles 19 or 20:
- essential entities: up to €10 000 000 or 2% of total worldwide annual turnover in the preceding financial year of the undertaking, whichever is higher;
- important entities: up to €7 000 000 or 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher.
Fines are imposed by the Enforcement Committee, which must first allow the entity to submit documentation or make submissions (article 33). And note article 18: management bodies must approve and oversee the cybersecurity risk-management measures, and the natural persons composing them may be held liable for infringements.
Before the next incident — a 30-minute checklist
- Confirm whether you are an essential entity or an important entity under article 4 (First/Second Schedule, size criteria).
- Complete or refresh your self-registration and contact data (article 7(4)–(5)).
- Write a one-page notification runbook: who declares "significant", who drafts the 24-hour early warning, who owns the 72-hour assessment and the one-month final report.
- Pre-draft templates matching the article 20(5) content lists.
Not sure whether the order applies to you at all, or where your reporting readiness gaps are? Use our free scoping and gap tool to check your classification and generate a prioritised action list in minutes.
Frequently asked questions
Do I report to the CIP Department or to the national CSIRT?
Article 20(1) of S.L. 460.41 directs essential and important entities to immediately notify the national CSIRT, which is established within the Malta Information Technology Agency (article 8(1)). The national CSIRT then immediately notifies the CIP Department in writing, together with any other designated competent authority concerned. You file once; the escalation is done for you.
What exactly counts as a "significant incident" in Malta?
Article 20(1) of S.L. 460.41 refers to an incident that has a significant impact on the provision of your services, but the national extract does not set out the test itself. On this point the national text is silent and directive (EU) 2022/2555 art 23(3) provides the baseline: an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss for the entity, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Further national thresholds: [Verify this: Critical Infrastructure Protection Department (official source).].
Is the deadline always 24 hours and 72 hours?
Under article 20(5) of S.L. 460.41 the early warning is due within twenty-four (24) hours and the incident notification within seventy-two (72) hours of becoming aware, with the final report not later than one (1) month after the incident notification. There is a derogation in article 20(6): a trust service provider must notify within twenty-four (24) hours of becoming aware of a significant incident affecting the provision of its trust services.
What can happen if we fail to report on time?
The CIP Department or designated competent authority can order the entity to fulfil the article 20 reporting obligations in a specified manner and period (article 29(6)(d) for essential entities, article 30(6)(d) for important entities) and can request an administrative penalty. Under article 32, infringements of articles 19 or 20 can lead to up to €10 000 000 or 2% of total worldwide annual turnover for essential entities, and up to €7 000 000 or 1.4% for important entities, whichever is higher. Penalties are imposed by the Enforcement Committee under article 33.
Check your NIS2 compliance
The complete NIS2 guide — Malta →
View the free sample package →
This article is general information, not legal advice. Consult a qualified professional for your specific situation.