NIS2 Incident Reporting Deadlines and Notification Duty in Malta

Published: · AIPOS OÜ · nis2europe.eu

Who must report incidents under NIS2 in Malta?

Malta transposed the NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Under this Order, the incident notification duty applies to two categories of organisations:

If your organisation falls into either category, article 20 of S.L. 460.41 requires you to immediately notify the national CSIRT of any incident that has a significant impact on the provision of your services. The mere act of notification does not, in itself, subject the notifying entity to increased liability.

Not sure whether you are in scope as an essential entity or an important entity? Our free scoping and gap tool can help you get an initial picture in minutes.

Which authority receives the notification?

In Malta the reporting chain involves two distinct bodies:

When a significant incident is reported, the national CSIRT immediately notifies in writing the CIP Department and any other designated competent authority that regulates the affected entity (article 20(1)). In other words, you report to the national CSIRT, and the CSIRT escalates internally.

The national CSIRT is also required to provide a response — without undue delay and where possible within 24 hours of receiving the early warning — including initial feedback and, on request, guidance or operational advice on possible mitigation measures (article 20(7)).

Practical note: the exact electronic notification or registration channel is to be confirmed. [TÄPSUSTAB PARTNER-JURIST]

The three reporting deadlines: 24 hours, 72 hours and 1 month

Article 20(5) of S.L. 460.41 sets out a staged reporting timeline for significant incidents. Entities concerned must submit to the national CSIRT:

StageDeadlineWhat it must contain
Early warningWithout undue delay and in any event within 24 hours of becoming aware of the significant incidentWhere applicable, whether the incident is suspected to be caused by unlawful or malicious acts, or could have a cross-border impact
Incident notificationWithout undue delay and in any event within 72 hours of becoming aware of the significant incidentAn update to the early warning and an initial assessment of severity and impact, plus indicators of compromise where available
Intermediate reportUpon request of the national CSIRTRelevant status updates
Final reportNot later than 1 month after the submission of the incident notificationDetailed description of the incident (severity and impact), type of threat or root cause, applied and ongoing mitigation measures, and any cross-border impact

Where an incident is still ongoing at the time the final report is due, the entity must provide a progress report at that time and a final report within 1 month of concluding its handling of the incident (article 20(5)(e)).

Special rule for trust service providers: by way of derogation from the 72-hour notification, a trust service provider must notify the national CSIRT of significant incidents affecting its trust services within 24 hours of becoming aware of the incident (article 20(6)).

Duties beyond reporting to the CSIRT

The notification duty in article 20 is broader than just the three staged reports:

Incident reporting also sits alongside the cybersecurity risk-management measures required under article 19, which include incident handling, business continuity, supply chain security and logging and traceability (article 19(2)).

What happens if you fail to report?

Failure to comply with the reporting obligations in article 20 can trigger both supervisory and enforcement action, and administrative penalties.

The CIP Department (or where designated, the competent authority) may, among other measures, issue binding instructions, order the entity to fulfil the reporting obligations in article 20 in a specified manner and within a specified period, and request the Enforcement Committee to impose an administrative penalty (articles 29 and 30).

Under article 32, where they infringe articles 19 or 20:

Given these figures, having a tested incident notification process — with clear responsibilities for the 24-hour, 72-hour and 1-month deadlines — is essential. Start with our free scoping and gap tool to see where your current readiness stands.

Frequently asked questions

Who do I notify of a significant incident in Malta?

You notify the national CSIRT, which is established within the Malta Information Technology Agency. The national CSIRT then immediately notifies in writing the CIP Department and any other designated competent authority that regulates your entity (article 20(1)).

What are the NIS2 incident reporting deadlines in Malta?

Under article 20(5) of S.L. 460.41 you must submit an early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, and a final report not later than 1 month after the incident notification. An intermediate report may also be required upon the national CSIRT's request.

Is there a different deadline for trust service providers?

Yes. By way of derogation from the 72-hour incident notification, a trust service provider must notify the national CSIRT of significant incidents affecting its trust services within 24 hours of becoming aware of the incident (article 20(6)).

What penalties apply for failing to report an incident?

For infringements of articles 19 or 20, essential entities face administrative penalties of up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher; important entities face up to €7 000 000 or 1.4% of turnover, whichever is higher (article 32).

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

The complete NIS2 guide — Malta

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home