NIS2 in Malta: Understanding the National Transposition Law and What It Adds

Published: · AIPOS OÜ · nis2europe.eu

From EU Directive to Maltese Law

The EU NIS2 framework is set out in Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. A directive is not directly binding on companies — each Member State must transpose it into its own national law.

In Malta, that transposition is the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41).

For Maltese businesses, the practical takeaway is simple: your obligations flow from S.L. 460.41, and the article references you should be citing internally are those of the national Order — even where they mirror the directive almost word-for-word. For example:

Understanding this relationship matters because when a supervisor or auditor engages with your organisation, they act under the Maltese Order, not the directive text itself.

Who Supervises NIS2 in Malta

Under article 7 of S.L. 460.41, the Critical Infrastructure Protection Department (CIP Department) is designated as the national supervisory authority responsible for monitoring the implementation of the Order at national level and ensuring compliance with it.

According to article 7, the CIP Department is responsible, among other things, for:

Alongside the CIP Department, a national CSIRT is established within the Malta Information Technology Agency (article 8). The national CSIRT handles incident notifications, while the CIP Department oversees supervision and enforcement. Note that the Order also allows for designated competent authorities for specific sectors or sub-sectors (listed in the First and Second Schedules), all operating under the supervision of the CIP Department as national supervisory authority.

Important: the exact electronic notification or registration channel and the precise operational deadlines for using it are [TÄPSUSTAB PARTNER-JURIST].

Essential vs Important Entities

The Order distinguishes two categories of regulated organisations, using the statutory terms directly.

Under article 4(1), an organisation is an essential entity where, for example, it is:

Under article 4(2), entities of a type referred to in the First or Second Schedule that do not qualify as essential entities are considered important entities.

The distinction is not just terminology — it drives the supervisory regime (proactive supervision for essential entities under article 29; largely ex-post supervision for important entities under article 30) and the maximum penalties (see below).

What the National Order Adds on Top of the Directive

While S.L. 460.41 closely tracks the directive, it fleshes out several operational details that Maltese entities need to plan for:

1. A named security liaison officer. Article 19(1)(c) requires essential and important entities to appoint a security liaison officer with the necessary expertise, who facilitates business continuity plans, ensures risk assessments and operator security plans are maintained, and acts as the point of contact with the CIP Department.

2. Mandatory CSIRT monitoring services. Article 19(1)(d) requires entities to receive CSIRT monitoring services from either an internal CSIRT or an autonomous CSIRT.

3. National self-registration. Under article 7(4), entities must register on the national self-registration mechanism and provide details such as the entity name, the CSIRT providing monitoring services, contact details, IP ranges and applicable sector. Under article 7(5), any change to these details must be notified without delay and within two (2) weeks of the change.

4. Concrete reporting deadlines. Article 20(5) sets out the notification chain to the national CSIRT:

StepDeadline
Early warningwithin 24 hours of becoming aware of the significant incident
Incident notificationwithin 72 hours of becoming aware
Intermediate reportupon request of the national CSIRT
Final reportnot later than one (1) month after the incident notification

A trust service provider must notify within 24 hours with regard to significant incidents affecting its trust services (article 20(6)).

5. Training obligations. Article 18(3)–(4) requires members of management bodies to follow training, and requires entities to offer similar training to employees on a regular basis.

Enforcement and Penalties

The CIP Department (or a designated competent authority) has extensive supervisory and enforcement powers.

For essential entities, article 29 allows measures including on-site inspections, off-site supervision, regular and targeted security audits, ad hoc audits, security scans, and requests for information and evidence — plus enforcement measures such as binding instructions and orders to bring measures into compliance.

For important entities, article 30 provides for largely ex-post supervision (taken when there is evidence of non-compliance), together with comparable enforcement powers.

On top of enforcement measures, administrative penalties apply under article 32:

Under article 33, administrative fines are imposed by the Enforcement Committee on entities reported by the CIP Department as non-compliant, after allowing the entity to make submissions.

Not sure whether your organisation is in scope, or which category applies? Use our free scoping and gap tool to map your obligations against S.L. 460.41 before a supervisor does.

Frequently asked questions

What is the name of Malta's NIS2 law?

Malta transposes the NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). This national Order is the source of your day-to-day obligations, even where its wording mirrors Directive (EU) 2022/2555.

Who is the competent authority for NIS2 in Malta?

Under article 7 of S.L. 460.41, the Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring implementation and ensuring compliance. A national CSIRT, established within the Malta Information Technology Agency, handles incident notifications, and sector-specific designated competent authorities may also apply.

What are the incident reporting deadlines under the Maltese Order?

Under article 20(5), entities submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report upon request, and a final report within one month of the incident notification. The exact electronic notification channel is to be confirmed by a partner lawyer.

What are the maximum penalties under S.L. 460.41?

Under article 32, essential entities that infringe articles 19 or 20 face up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 000 000 or 1.4% of turnover, whichever is higher. Fines are imposed by the Enforcement Committee under article 33.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

The complete NIS2 guide — Malta

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home