NIS2 in Malta: Understanding the National Transposition Law and What It Adds
From EU Directive to Maltese Law
The EU NIS2 framework is set out in Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. A directive is not directly binding on companies — each Member State must transpose it into its own national law.
In Malta, that transposition is the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41).
For Maltese businesses, the practical takeaway is simple: your obligations flow from S.L. 460.41, and the article references you should be citing internally are those of the national Order — even where they mirror the directive almost word-for-word. For example:
- The governance duties on management bodies sit in article 18 of the Order (the equivalent of Article 20 of the directive).
- The cybersecurity risk-management measures sit in article 19 of the Order (the equivalent of Article 21(2) of the directive).
- The incident reporting timeline sits in article 20 of the Order.
Understanding this relationship matters because when a supervisor or auditor engages with your organisation, they act under the Maltese Order, not the directive text itself.
Who Supervises NIS2 in Malta
Under article 7 of S.L. 460.41, the Critical Infrastructure Protection Department (CIP Department) is designated as the national supervisory authority responsible for monitoring the implementation of the Order at national level and ensuring compliance with it.
According to article 7, the CIP Department is responsible, among other things, for:
- establishing the criteria for identifying and designating essential and important entities;
- establishing a national self-registration mechanism for entities providing services in Malta;
- adopting the National Cybersecurity Strategy;
- acting as coordinator for coordinated vulnerability disclosure (also confirmed in article 13); and
- acting as the single point of contact for cross-border cooperation with authorities of other Member States, the European Commission and ENISA.
Alongside the CIP Department, a national CSIRT is established within the Malta Information Technology Agency (article 8). The national CSIRT handles incident notifications, while the CIP Department oversees supervision and enforcement. Note that the Order also allows for designated competent authorities for specific sectors or sub-sectors (listed in the First and Second Schedules), all operating under the supervision of the CIP Department as national supervisory authority.
Important: the exact electronic notification or registration channel and the precise operational deadlines for using it are [TÄPSUSTAB PARTNER-JURIST].
Essential vs Important Entities
The Order distinguishes two categories of regulated organisations, using the statutory terms directly.
Under article 4(1), an organisation is an essential entity where, for example, it is:
- a type indicated in the First Schedule that exceeds the ceilings for medium-sized enterprises (per Commission Recommendation 2003/361/EC);
- a qualified trust service provider, top-level domain name registry or DNS service provider, regardless of size;
- a provider of public electronic communications networks or services that qualifies as a medium-sized enterprise; or
- a public administration entity, or an entity designated as critical, as further set out in article 4.
Under article 4(2), entities of a type referred to in the First or Second Schedule that do not qualify as essential entities are considered important entities.
The distinction is not just terminology — it drives the supervisory regime (proactive supervision for essential entities under article 29; largely ex-post supervision for important entities under article 30) and the maximum penalties (see below).
What the National Order Adds on Top of the Directive
While S.L. 460.41 closely tracks the directive, it fleshes out several operational details that Maltese entities need to plan for:
1. A named security liaison officer. Article 19(1)(c) requires essential and important entities to appoint a security liaison officer with the necessary expertise, who facilitates business continuity plans, ensures risk assessments and operator security plans are maintained, and acts as the point of contact with the CIP Department.
2. Mandatory CSIRT monitoring services. Article 19(1)(d) requires entities to receive CSIRT monitoring services from either an internal CSIRT or an autonomous CSIRT.
3. National self-registration. Under article 7(4), entities must register on the national self-registration mechanism and provide details such as the entity name, the CSIRT providing monitoring services, contact details, IP ranges and applicable sector. Under article 7(5), any change to these details must be notified without delay and within two (2) weeks of the change.
4. Concrete reporting deadlines. Article 20(5) sets out the notification chain to the national CSIRT:
| Step | Deadline |
|---|---|
| Early warning | within 24 hours of becoming aware of the significant incident |
| Incident notification | within 72 hours of becoming aware |
| Intermediate report | upon request of the national CSIRT |
| Final report | not later than one (1) month after the incident notification |
A trust service provider must notify within 24 hours with regard to significant incidents affecting its trust services (article 20(6)).
5. Training obligations. Article 18(3)–(4) requires members of management bodies to follow training, and requires entities to offer similar training to employees on a regular basis.
Enforcement and Penalties
The CIP Department (or a designated competent authority) has extensive supervisory and enforcement powers.
For essential entities, article 29 allows measures including on-site inspections, off-site supervision, regular and targeted security audits, ad hoc audits, security scans, and requests for information and evidence — plus enforcement measures such as binding instructions and orders to bring measures into compliance.
For important entities, article 30 provides for largely ex-post supervision (taken when there is evidence of non-compliance), together with comparable enforcement powers.
On top of enforcement measures, administrative penalties apply under article 32:
- Essential entities that infringe articles 19 or 20 face a maximum of €10 000 000, or up to 2% of total worldwide annual turnover in the preceding financial year, whichever is higher (article 32(3)).
- Important entities that infringe articles 19 or 20 face a maximum of €7 000 000, or up to 1.4% of total worldwide annual turnover, whichever is higher (article 32(4)).
Under article 33, administrative fines are imposed by the Enforcement Committee on entities reported by the CIP Department as non-compliant, after allowing the entity to make submissions.
Not sure whether your organisation is in scope, or which category applies? Use our free scoping and gap tool to map your obligations against S.L. 460.41 before a supervisor does.
Frequently asked questions
What is the name of Malta's NIS2 law?
Malta transposes the NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). This national Order is the source of your day-to-day obligations, even where its wording mirrors Directive (EU) 2022/2555.
Who is the competent authority for NIS2 in Malta?
Under article 7 of S.L. 460.41, the Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring implementation and ensuring compliance. A national CSIRT, established within the Malta Information Technology Agency, handles incident notifications, and sector-specific designated competent authorities may also apply.
What are the incident reporting deadlines under the Maltese Order?
Under article 20(5), entities submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report upon request, and a final report within one month of the incident notification. The exact electronic notification channel is to be confirmed by a partner lawyer.
What are the maximum penalties under S.L. 460.41?
Under article 32, essential entities that infringe articles 19 or 20 face up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 000 000 or 1.4% of turnover, whichever is higher. Fines are imposed by the Enforcement Committee under article 33.
Check your NIS2 compliance
The complete NIS2 guide — Malta →
This article is general information, not legal advice. A partner lawyer confirms your specific situation.