The 10 NIS2 Cybersecurity Risk-Management Measures Under Article 21
What Article 21 requires — and how Malta transposes it
The heart of NIS2 for any business is Article 21 of Directive (EU) 2022/2555. It requires that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems they use, and to prevent or minimise the impact of incidents on service recipients (art 21(1)).
In Malta, this obligation is transposed by article 19 of the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Article 19(1) mirrors the directive almost word for word: entities must take proportionate measures and ensure a level of security appropriate to the risks posed, taking into account the state-of-the-art, relevant European and international standards, and the cost of implementation.
Proportionality is not a loophole — it is a documented judgement. When assessing what is appropriate, an entity must weigh:
- the degree of the entity's exposure to risks;
- the entity's size; and
- the likelihood of occurrence of incidents and their severity, including their societal and economic impact.
Crucially, article 19(2) confirms that the measures must be based on an all-hazards approach that protects both the network and information systems *and* the physical environment of those systems.
The ten measures as a practical checklist
Article 19(2) of S.L. 460.41 sets out the minimum measures — the same list as directive art 21(2), points (a) to (j), with one Maltese addition. Use this as your baseline checklist:
| # | Measure (S.L. 460.41 art 19(2)) |
|---|---|
| (a) | Policies on risk analysis and information system security |
| (b) | Incident handling |
| (c) | Business continuity, such as backup management and disaster recovery, and crisis management |
| (d) | Supply chain security, including security-related aspects of relationships with direct suppliers or service providers |
| (e) | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure |
| (f) | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures |
| (g) | Basic cyber hygiene practices and cybersecurity training |
| (h) | Policies and procedures regarding the use of cryptography and, where appropriate, encryption |
| (i) | Human resources security, insider risk management policy, access control policies and asset management |
| (j) | Multi-factor authentication or continuous authentication, secured voice, video and text communications, and secured emergency communication systems, where appropriate |
Note the Maltese specifics. Article 19(2)(i) explicitly adds an insider risk management policy to the human resources / access control / asset management measure. And S.L. 460.41 goes beyond the directive's ten points with an eleventh measure:
- (k) logging and traceability of network and information systems.
So in Malta, the practical checklist runs from (a) to (k), not just (a) to (j).
Supply chain and corrective duties
The supply chain measure (article 19(2)(d)) deserves particular attention because it drives obligations you may not fully control. Under article 19(3), when deciding which supply-chain measures are appropriate, entities must take into account:
- the vulnerabilities specific to each direct supplier and service provider;
- the overall quality of products and the cybersecurity practices of suppliers and service providers, including their secure development procedures; and
- the results of coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1) of the Directive.
Equally important is the corrective duty. Article 19(4) of S.L. 460.41 requires that where an entity finds it does not comply with the measures in article 19(2), it must take — without undue delay — all necessary, appropriate and proportionate corrective measures. This transposes directive art 21(4). Non-compliance is therefore not just about a gap; it is about how quickly and demonstrably you close it.
To support implementation, article 19(1)(c) requires entities to appoint a security liaison officer with the necessary expertise, who facilitates business continuity and termination plans, ensures risk assessments and an operator security plan are maintained, and acts as point of contact with the Critical Infrastructure Protection Department (CIP Department). Entities must also receive CSIRT monitoring services from an internal or autonomous CSIRT (article 19(1)(d)).
Governance, oversight and management liability
The ten measures are not solely an IT concern. Under article 18 of S.L. 460.41 (which transposes directive art 20(1)), the management bodies of essential and important entities must approve the cybersecurity risk-management measures taken under article 19 and oversee their implementation.
This comes with personal consequences. The natural persons composing the management bodies may be held liable for the entity's infringements of article 19, in accordance with articles 31(10)(b) and 33. In addition:
- Members of management bodies are required to follow training to carry out their tasks (article 18(3)).
- Entities must offer similar training to their employees on a regular basis, so staff can identify risks and assess cybersecurity risk-management practices (article 18(4)).
The CIP Department is Malta's national supervisory authority responsible for monitoring implementation and ensuring compliance (article 7). It monitors the risk-management measures undertaken by entities in accordance with article 19 and can request evidence of implementation through supervisory measures set out in articles 29 (essential entities) and 30 (important entities).
What happens if the measures fall short
Infringements of article 19 (or of the reporting obligations in article 20) carry significant financial exposure. Under article 32 of S.L. 460.41:
- Essential entities face administrative penalties of a maximum of €10 000 000, or a maximum of 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs — whichever is higher.
- Important entities face administrative penalties of a maximum of €7 000 000, or a maximum of 1.4% of the total worldwide annual turnover in the preceding financial year — whichever is higher.
Penalties are imposed by the Enforcement Committee, on referral from the CIP Department (article 33), and come in addition to enforcement measures such as binding instructions or orders to bring measures into compliance.
Not sure whether you are an essential entity or an important entity — or which of the eleven measures you already meet? Start with our free scoping and gap-analysis tool. It walks you through the article 19 checklist point by point, so you can see where you stand before the CIP Department comes knocking.
Frequently asked questions
How many cybersecurity risk-management measures does NIS2 require in Malta?
Directive art 21(2) lists ten minimum measures (points (a) to (j)). Malta's transposition in article 19(2) of S.L. 460.41 keeps all ten and adds an eleventh — point (k), logging and traceability of network and information systems. Article 19(2)(i) also expressly includes an insider risk management policy.
Which Maltese law transposes Article 21 of the NIS2 Directive?
Article 21 of Directive (EU) 2022/2555 is transposed by article 19 of the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Article 19(1) reflects the general obligation, and article 19(2) sets out the minimum measures.
Can company directors be held personally liable for weak cybersecurity measures?
Yes. Under article 18 of S.L. 460.41, management bodies must approve the article 19 measures and oversee their implementation, and the natural persons composing those bodies may be held liable for the entity's infringements in accordance with articles 31(10)(b) and 33.
What are the fines for not implementing the risk-management measures?
Under article 32 of S.L. 460.41, essential entities can face up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities can face up to €7 000 000 or 1.4% of total worldwide annual turnover, whichever is higher.
Check your NIS2 compliance
The complete NIS2 guide — Malta →
This article is general information, not legal advice. A partner lawyer confirms your specific situation.