NIS2 Incident Reporting Deadlines and Notification Duty in Malta
Who must report incidents under NIS2 in Malta?
Malta transposed the NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Under this Order, the incident notification duty applies to two categories of organisations:
- essential entities — including, among others, entities of a type in the First Schedule that exceed the ceilings for medium-sized enterprises, qualified trust service providers, top-level domain name registries and DNS service providers regardless of size, and other entities designated by the Critical Infrastructure Protection Department (CIP Department) (article 4(1)).
- important entities — entities of a type referred to in the First or Second Schedule that do not qualify as essential entities (article 4(2)).
If your organisation falls into either category, article 20 of S.L. 460.41 requires you to immediately notify the national CSIRT of any incident that has a significant impact on the provision of your services. The mere act of notification does not, in itself, subject the notifying entity to increased liability.
Not sure whether you are in scope as an essential entity or an important entity? Our free scoping and gap tool can help you get an initial picture in minutes.
Which authority receives the notification?
In Malta the reporting chain involves two distinct bodies:
- The national CSIRT — established within the Malta Information Technology Agency, responsible for incident handling. This is the body that essential and important entities must notify directly of significant incidents (article 20(1)).
- The Critical Infrastructure Protection Department (CIP Department) — the national supervisory authority responsible for monitoring implementation of the Order and ensuring compliance (article 7(1)).
When a significant incident is reported, the national CSIRT immediately notifies in writing the CIP Department and any other designated competent authority that regulates the affected entity (article 20(1)). In other words, you report to the national CSIRT, and the CSIRT escalates internally.
The national CSIRT is also required to provide a response — without undue delay and where possible within 24 hours of receiving the early warning — including initial feedback and, on request, guidance or operational advice on possible mitigation measures (article 20(7)).
Practical note: the exact electronic notification or registration channel is to be confirmed. [TÄPSUSTAB PARTNER-JURIST]
The three reporting deadlines: 24 hours, 72 hours and 1 month
Article 20(5) of S.L. 460.41 sets out a staged reporting timeline for significant incidents. Entities concerned must submit to the national CSIRT:
| Stage | Deadline | What it must contain |
|---|---|---|
| Early warning | Without undue delay and in any event within 24 hours of becoming aware of the significant incident | Where applicable, whether the incident is suspected to be caused by unlawful or malicious acts, or could have a cross-border impact |
| Incident notification | Without undue delay and in any event within 72 hours of becoming aware of the significant incident | An update to the early warning and an initial assessment of severity and impact, plus indicators of compromise where available |
| Intermediate report | Upon request of the national CSIRT | Relevant status updates |
| Final report | Not later than 1 month after the submission of the incident notification | Detailed description of the incident (severity and impact), type of threat or root cause, applied and ongoing mitigation measures, and any cross-border impact |
Where an incident is still ongoing at the time the final report is due, the entity must provide a progress report at that time and a final report within 1 month of concluding its handling of the incident (article 20(5)(e)).
Special rule for trust service providers: by way of derogation from the 72-hour notification, a trust service provider must notify the national CSIRT of significant incidents affecting its trust services within 24 hours of becoming aware of the incident (article 20(6)).
Duties beyond reporting to the CSIRT
The notification duty in article 20 is broader than just the three staged reports:
- Informing service recipients: where appropriate, entities must notify, without undue delay, the recipients of their services of significant incidents likely to adversely affect service provision (article 20(2)).
- Cyber threats: where applicable, entities must communicate without undue delay to potentially affected recipients any measures or remedies they can take in response to a significant cyber threat, and where appropriate inform them of the threat itself (article 20(4)).
- Cross-border incidents: where an incident concerns Malta and at least one other Member State, the national CSIRT (with prior coordination with the CIP Department) informs the other affected Member State and ENISA without undue delay (article 20(9)).
Incident reporting also sits alongside the cybersecurity risk-management measures required under article 19, which include incident handling, business continuity, supply chain security and logging and traceability (article 19(2)).
What happens if you fail to report?
Failure to comply with the reporting obligations in article 20 can trigger both supervisory and enforcement action, and administrative penalties.
The CIP Department (or where designated, the competent authority) may, among other measures, issue binding instructions, order the entity to fulfil the reporting obligations in article 20 in a specified manner and within a specified period, and request the Enforcement Committee to impose an administrative penalty (articles 29 and 30).
Under article 32, where they infringe articles 19 or 20:
- essential entities are subject to administrative penalties of a maximum of €10 000 000, or a maximum of 2% of total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher (article 32(3)).
- important entities are subject to administrative penalties of a maximum of €7 000 000, or a maximum of 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher (article 32(4)).
Given these figures, having a tested incident notification process — with clear responsibilities for the 24-hour, 72-hour and 1-month deadlines — is essential. Start with our free scoping and gap tool to see where your current readiness stands.
Frequently asked questions
Who do I notify of a significant incident in Malta?
You notify the national CSIRT, which is established within the Malta Information Technology Agency. The national CSIRT then immediately notifies in writing the CIP Department and any other designated competent authority that regulates your entity (article 20(1)).
What are the NIS2 incident reporting deadlines in Malta?
Under article 20(5) of S.L. 460.41 you must submit an early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, and a final report not later than 1 month after the incident notification. An intermediate report may also be required upon the national CSIRT's request.
Is there a different deadline for trust service providers?
Yes. By way of derogation from the 72-hour incident notification, a trust service provider must notify the national CSIRT of significant incidents affecting its trust services within 24 hours of becoming aware of the incident (article 20(6)).
What penalties apply for failing to report an incident?
For infringements of articles 19 or 20, essential entities face administrative penalties of up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher; important entities face up to €7 000 000 or 1.4% of turnover, whichever is higher (article 32).
Check your NIS2 compliance
The complete NIS2 guide — Malta →
This article is general information, not legal advice. A partner lawyer confirms your specific situation.