How a Company-Specific NIS2 Document Is Produced in Minutes (Malta)
Malta law · S.L. 460.41
The legal basis is fixed before drafting starts
In Malta, NIS2 is transposed by the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). What a cybersecurity risk-management policy and the surrounding documentation must contain is not a matter of style — it is written into the Order itself.
Article 19(1)(a) requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the network and information systems they use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents. Article 19(2) then lists what those measures must include at least, from policies on risk analysis and information system security through to logging and traceability.
This is why document production is no longer a research project. The legal text is stable and public; the wording of each obligation can be verified once, in advance, and reused. What remains is mapping the fixed obligations onto one specific company.
The whole set: five core documentation areas
Before looking at any single document, it helps to see the full picture. Five areas form the backbone of a NIS2 document set in Malta:
| Area | What the Order requires | Provision |
|---|---|---|
| Risk-management policy | Policies on risk analysis and information system security, based on an all-hazards approach protecting network and information systems and their physical environment | article 19(2)(a), article 19(2) opening words |
| Incident handling | Incident handling as a listed minimum measure; significant incidents are notified to the national CSIRT | article 19(2)(b), article 20(1) |
| Business continuity | Business continuity, such as backup management and disaster recovery, and crisis management | article 19(2)(c) |
| Supply-chain security | Supply chain security, including security-related aspects of relationships with direct suppliers and service providers | article 19(2)(d), article 19(3) |
| Management responsibility | Management bodies approve the cybersecurity risk-management measures and oversee their implementation; members must follow training | article 18(1), article 18(3) |
Risk-management policy. Article 19(2)(a) makes policies on risk analysis and information system security a minimum element. Article 19(1)(b) adds that the level of security must be appropriate to the risks posed, taking into account the state of the art and, where applicable, relevant European and international standards, as well as the cost of implementation.
Incident handling. Beyond article 19(2)(b), article 20(5) sets the reporting sequence: an early warning within twenty-four (24) hours of becoming aware of the significant incident, an incident notification within seventy-two (72) hours, and a final report not later than one (1) month after the incident notification. Documented handling steps are what make those timings achievable in practice.
Business continuity. Article 19(2)(c) covers backup management, disaster recovery and crisis management. Article 19(1)(c)(i) also assigns the security liaison officer the task of facilitating the development, implementation, maintenance and review of business continuity plans.
Supply-chain security. Article 19(3) requires entities to take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices, including secure development procedures.
Management responsibility. Under article 18(1) the management body approves the measures and oversees implementation, and the natural persons composing it may be held liable for infringements in accordance with articles 31(10)(b) and 33.
Your company profile decides which obligations apply
The second fixed input is the company itself. Article 4(1) treats as essential entities, among others, entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC, and qualified trust service providers, top-level domain name registries and DNS service providers regardless of their size. Article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as essential entities are considered important entities.
So three profile facts — sector or sub-sector under the First or Second Schedule, size against the Recommendation 2003/361/EC ceilings, and the resulting classification — determine which obligations attach to your organisation. Jurisdiction follows article 23: entities within the scope of the Order fall under the jurisdiction of Malta if they are established in Malta, with the exceptions listed in article 23(1)(a) to (c).
The classification also changes how supervision works. For essential entities, article 29(2) allows on-site inspections and off-site supervision, regular and targeted security audits, ad hoc audits and security scans. For important entities, article 30(1) frames supervision as ex post action taken when there is evidence, indication or information of non-observance.
Why every statement carries a source reference
A company-specific document is only useful if a third party can check it. The Order tells you exactly who will ask.
Under article 29(2)(e), the CIP Department — or, where designated, the competent authority — may request information necessary to assess the cybersecurity risk-management measures adopted, including documented cybersecurity policies. Article 29(2)(g) allows requests for evidence of implementation of cybersecurity policies, and article 29(2)(j) requests for evidence of operator security plans, business continuity plans and, where necessary, termination plans. Article 30(2)(d), (f) and (i) mirror these powers for important entities.
Buying organisations ask too, and the Order explains why: article 19(3) obliges entities to weigh the cybersecurity practices and secure development procedures of their direct suppliers. A supplier that can show a document in which each legal statement names the law and the exact provision — for example S.L. 460.41 article 19(2)(c) — answers that question in one step, rather than in a round of emails.
That is the whole point of pre-verified verbatim sources: the legal wording is quoted and referenced once, the company profile is filled in, and the assembled document can be checked claim by claim by an auditor, a procurement team or the supervisory authority.
Step one of five: the risk-management policy
Of the five areas, the risk-management policy comes first, because the other four sit on top of it.
- It sets the scope of the approach. Article 19(2) requires an all-hazards approach aimed at protecting network and information systems and their physical environment from incidents.
- It records proportionality reasoning. Article 19(1)(b) requires due consideration of the degree of the entity's exposure to risks, its size, and the likelihood and severity of incidents, including their societal and economic impact.
- It names responsibilities. Article 19(1)(c) requires the appointment of a security liaison officer with the necessary expertise, who ensures that appropriate risk assessments are conducted and maintained and acts as the point of contact with the CIP Department or the designated competent authority.
- It is approved at the top. Article 18(1) requires the management body to approve the measures and oversee their implementation.
- It triggers correction. Article 19(4) provides that where an entity finds it does not meet the measures in article 19(2), it shall take all necessary, appropriate and proportionate corrective measures without undue delay.
Administrative penalties are set out in article 32: for infringements of article 19 or article 20, essential entities face a maximum of ten million euro (€10 000 000) or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher; important entities face a maximum of seven million euro (€7 000 000) or 1.4%, whichever is higher. Documentation does not remove those duties — it records how the entity discharges them.
For procedural details such as the exact electronic notification or self-registration channel, please confirm with the published guidance of the Critical Infrastructure Protection Department (CIP Department) as the official source.
Frequently asked questions
What makes a NIS2 document "company-specific" rather than a generic template?
Two inputs. First, the fixed legal basis: S.L. 460.41 article 19(2) lists the minimum measures every essential and important entity must cover, so the required content is the same for everyone. Second, the company profile: your sector or sub-sector under the First or Second Schedule, your size measured against the ceilings in Article 2(1) of the Annex to Commission Recommendation 2003/361/EC, and the resulting classification under article 4 determine which obligations attach and how supervision applies (article 29 for essential entities, article 30 for important entities).
Which minimum measures must a Maltese risk-management policy address?
Article 19(2) of S.L. 460.41 lists at least: policies on risk analysis and information system security; incident handling; business continuity, such as backup management and disaster recovery, and crisis management; supply chain security; security in acquisition, development and maintenance, including vulnerability handling and disclosure; policies and procedures to assess the effectiveness of the measures; basic cyber hygiene practices and cybersecurity training; cryptography and, where appropriate, encryption; human resources security, insider risk management policy, access control policies and asset management; multi-factor or continuous authentication and secured communications where appropriate; and logging and traceability.
Why should each legal statement in the document name the law and provision?
Because the readers are checkers. Article 29(2)(e) lets the supervisory authority request documented cybersecurity policies, article 29(2)(g) evidence of their implementation, and article 29(2)(j) evidence of business continuity plans — with equivalent powers in article 30(2) for important entities. A source reference lets an auditor, a customer's procurement team or the authority verify each claim against the text of S.L. 460.41 instead of taking it on trust.
Who inside the company has to sign off the documented measures?
Article 18(1) of S.L. 460.41 requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures under article 19 and to oversee their implementation; the natural persons composing those bodies may be held liable for infringements in accordance with articles 31(10)(b) and 33. Article 18(3) adds that members of the management body are required to follow training, and article 18(4) that entities offer similar training to employees on a regular basis.
Related topics
These topics are covered in depth on a separate page:
- trahvisummad ja sanktsioonid — NIS2 Fines and Sanctions in Malta: What to Know
- ülioluline vs oluline üksuse eristus — NIS2 in Malta: Who Is in Scope (S.L. 460.41)
- intsidenditeavituse tähtajad — NIS2 Incident Reporting Deadlines in Malta Explained
- RIA järelevalvevolitused — NIS2 Supervision & Enforcement in Malta: CIP Powers
- juhatuse liikme kohustused — NIS2 Malta: Management Liability & Duties
Your profile after the first document
- ✓ Cybersecurity risk management policy
- ○ Incident handling plan
- ○ Business continuity plan
- ○ Supply chain security policy
- ○ Management accountability and training documents
1 of 5 complete — the remaining four documents are produced with the full package.
Start with your first document — €19, ready in minutes Order the complete documentation — from 3 400 EUR
Check your NIS2 compliance
Start the free applicability check
Run the free self-assessment Run the free external security check
The complete NIS2 guide — Malta →
View the free sample package →
This article is general information, not legal advice. Consult a qualified professional for your specific situation.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum 24e02d3688af).