NIS2 · Malta

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

How a Company-Specific NIS2 Document Is Produced in Minutes (Malta)

Malta law · S.L. 460.41

Published: · AIPOS OÜ · nis2europe.eu

The legal basis is fixed before drafting starts

In Malta, NIS2 is transposed by the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). What a cybersecurity risk-management policy and the surrounding documentation must contain is not a matter of style — it is written into the Order itself.

Article 19(1)(a) requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the network and information systems they use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents. Article 19(2) then lists what those measures must include at least, from policies on risk analysis and information system security through to logging and traceability.

This is why document production is no longer a research project. The legal text is stable and public; the wording of each obligation can be verified once, in advance, and reused. What remains is mapping the fixed obligations onto one specific company.

The whole set: five core documentation areas

Before looking at any single document, it helps to see the full picture. Five areas form the backbone of a NIS2 document set in Malta:

AreaWhat the Order requiresProvision
Risk-management policyPolicies on risk analysis and information system security, based on an all-hazards approach protecting network and information systems and their physical environmentarticle 19(2)(a), article 19(2) opening words
Incident handlingIncident handling as a listed minimum measure; significant incidents are notified to the national CSIRTarticle 19(2)(b), article 20(1)
Business continuityBusiness continuity, such as backup management and disaster recovery, and crisis managementarticle 19(2)(c)
Supply-chain securitySupply chain security, including security-related aspects of relationships with direct suppliers and service providersarticle 19(2)(d), article 19(3)
Management responsibilityManagement bodies approve the cybersecurity risk-management measures and oversee their implementation; members must follow trainingarticle 18(1), article 18(3)

Risk-management policy. Article 19(2)(a) makes policies on risk analysis and information system security a minimum element. Article 19(1)(b) adds that the level of security must be appropriate to the risks posed, taking into account the state of the art and, where applicable, relevant European and international standards, as well as the cost of implementation.

Incident handling. Beyond article 19(2)(b), article 20(5) sets the reporting sequence: an early warning within twenty-four (24) hours of becoming aware of the significant incident, an incident notification within seventy-two (72) hours, and a final report not later than one (1) month after the incident notification. Documented handling steps are what make those timings achievable in practice.

Business continuity. Article 19(2)(c) covers backup management, disaster recovery and crisis management. Article 19(1)(c)(i) also assigns the security liaison officer the task of facilitating the development, implementation, maintenance and review of business continuity plans.

Supply-chain security. Article 19(3) requires entities to take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices, including secure development procedures.

Management responsibility. Under article 18(1) the management body approves the measures and oversees implementation, and the natural persons composing it may be held liable for infringements in accordance with articles 31(10)(b) and 33.

Your company profile decides which obligations apply

The second fixed input is the company itself. Article 4(1) treats as essential entities, among others, entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC, and qualified trust service providers, top-level domain name registries and DNS service providers regardless of their size. Article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as essential entities are considered important entities.

So three profile facts — sector or sub-sector under the First or Second Schedule, size against the Recommendation 2003/361/EC ceilings, and the resulting classification — determine which obligations attach to your organisation. Jurisdiction follows article 23: entities within the scope of the Order fall under the jurisdiction of Malta if they are established in Malta, with the exceptions listed in article 23(1)(a) to (c).

The classification also changes how supervision works. For essential entities, article 29(2) allows on-site inspections and off-site supervision, regular and targeted security audits, ad hoc audits and security scans. For important entities, article 30(1) frames supervision as ex post action taken when there is evidence, indication or information of non-observance.

Why every statement carries a source reference

A company-specific document is only useful if a third party can check it. The Order tells you exactly who will ask.

Under article 29(2)(e), the CIP Department — or, where designated, the competent authority — may request information necessary to assess the cybersecurity risk-management measures adopted, including documented cybersecurity policies. Article 29(2)(g) allows requests for evidence of implementation of cybersecurity policies, and article 29(2)(j) requests for evidence of operator security plans, business continuity plans and, where necessary, termination plans. Article 30(2)(d), (f) and (i) mirror these powers for important entities.

Buying organisations ask too, and the Order explains why: article 19(3) obliges entities to weigh the cybersecurity practices and secure development procedures of their direct suppliers. A supplier that can show a document in which each legal statement names the law and the exact provision — for example S.L. 460.41 article 19(2)(c) — answers that question in one step, rather than in a round of emails.

That is the whole point of pre-verified verbatim sources: the legal wording is quoted and referenced once, the company profile is filled in, and the assembled document can be checked claim by claim by an auditor, a procurement team or the supervisory authority.

Step one of five: the risk-management policy

Of the five areas, the risk-management policy comes first, because the other four sit on top of it.

Administrative penalties are set out in article 32: for infringements of article 19 or article 20, essential entities face a maximum of ten million euro (€10 000 000) or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher; important entities face a maximum of seven million euro (€7 000 000) or 1.4%, whichever is higher. Documentation does not remove those duties — it records how the entity discharges them.

For procedural details such as the exact electronic notification or self-registration channel, please confirm with the published guidance of the Critical Infrastructure Protection Department (CIP Department) as the official source.

Frequently asked questions

What makes a NIS2 document "company-specific" rather than a generic template?

Two inputs. First, the fixed legal basis: S.L. 460.41 article 19(2) lists the minimum measures every essential and important entity must cover, so the required content is the same for everyone. Second, the company profile: your sector or sub-sector under the First or Second Schedule, your size measured against the ceilings in Article 2(1) of the Annex to Commission Recommendation 2003/361/EC, and the resulting classification under article 4 determine which obligations attach and how supervision applies (article 29 for essential entities, article 30 for important entities).

Which minimum measures must a Maltese risk-management policy address?

Article 19(2) of S.L. 460.41 lists at least: policies on risk analysis and information system security; incident handling; business continuity, such as backup management and disaster recovery, and crisis management; supply chain security; security in acquisition, development and maintenance, including vulnerability handling and disclosure; policies and procedures to assess the effectiveness of the measures; basic cyber hygiene practices and cybersecurity training; cryptography and, where appropriate, encryption; human resources security, insider risk management policy, access control policies and asset management; multi-factor or continuous authentication and secured communications where appropriate; and logging and traceability.

Why should each legal statement in the document name the law and provision?

Because the readers are checkers. Article 29(2)(e) lets the supervisory authority request documented cybersecurity policies, article 29(2)(g) evidence of their implementation, and article 29(2)(j) evidence of business continuity plans — with equivalent powers in article 30(2) for important entities. A source reference lets an auditor, a customer's procurement team or the authority verify each claim against the text of S.L. 460.41 instead of taking it on trust.

Who inside the company has to sign off the documented measures?

Article 18(1) of S.L. 460.41 requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures under article 19 and to oversee their implementation; the natural persons composing those bodies may be held liable for infringements in accordance with articles 31(10)(b) and 33. Article 18(3) adds that members of the management body are required to follow training, and article 18(4) that entities offer similar training to employees on a regular basis.

Related topics

These topics are covered in depth on a separate page:

Your profile after the first document

1 of 5 complete — the remaining four documents are produced with the full package.

Start with your first document — €19, ready in minutes Order the complete documentation — from 3 400 EUR

Check your NIS2 compliance

Start the free applicability check

Run the free self-assessment Run the free external security check

The complete NIS2 guide — Malta

View the free sample package

This article is general information, not legal advice. Consult a qualified professional for your specific situation.

Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum 24e02d3688af).

Back to home