NIS2 Supervision and Enforcement in Malta: What the CIP Department Can Do

Published: · AIPOS OÜ · nis2europe.eu

Who supervises NIS2 in Malta?

Malta transposed the NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Under this Order, the Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring implementation of the Order at national level and ensuring compliance with it (article 7).

In practice, this means the CIP Department is the body that will identify and designate your organisation as an essential entity or an important entity, monitor your cybersecurity risk-management measures (article 19), monitor your incident reporting obligations (article 20), and — where deficiencies are found — apply supervisory and enforcement measures (articles 29 and 30).

Note that for certain sectors and sub-sectors, the First and Second Schedules may designate a different competent authority. Those designated competent authorities operate under the supervision of the CIP Department as the national supervisory authority (article 7(2)). For readability, this article refers throughout to "the CIP Department, or where designated the competent authority".

Supervision of essential entities: the ex-ante model

For essential entities, the Order sets out a proactive (ex-ante) supervisory regime. When exercising its supervisory tasks in relation to essential entities, the CIP Department has the power to subject those entities at least to the following (article 29(2)):

Targeted security audits are based on risk assessments conducted by the authority or the audited entity (article 29(3)). Importantly, the costs of a targeted security audit carried out by an independent body are paid by the audited essential entity, except in duly substantiated cases where the authority decides otherwise (article 29(4)).

When making information requests, the authority must state the purpose of the request and specify the information requested (article 29(5)).

Supervision of important entities: the ex-post model

For important entities, the Order applies a lighter, reactive (ex-post) model. The CIP Department takes action, where necessary, through ex post supervisory measures — that is, when it is provided with evidence, indication or information that an important entity allegedly does not comply with the Order, in particular articles 19 and/or 20 (article 30(1)).

When exercising supervisory tasks in relation to important entities, the authority has the power to apply at least (article 30(2)):

Key difference: essential entities face regular, proactive audits and checks (ex-ante), whereas important entities are generally supervised only when there is an indication of non-compliance (ex-post). Both regimes require the supervisory and enforcement measures to be effective, proportionate and dissuasive, taking into account the circumstances of each individual case (articles 29(1) and 30(1)).

Enforcement measures: warnings, binding orders and more

If supervision reveals problems, the CIP Department has a graduated toolkit of enforcement measures. For essential entities, the authority may (article 29(6)):

For important entities, a broadly similar list of enforcement measures applies (article 30(6)) — with the notable difference that the appointment of a dedicated monitoring officer is not listed for important entities.

The authority may impose these measures periodically on essential entities (article 29(8)).

Administrative penalties

In addition to the enforcement measures above, the CIP Department may request the imposition of an administrative penalty by the Enforcement Committee (articles 29(7), 30(7) and 33). Administrative penalties are imposed in addition to the enforcement measures, not instead of them (article 32(1)).

Where an entity infringes article 19 (risk-management measures) or article 20 (reporting), the maximum penalties are (article 32):

Entity typeMaximum administrative penalty
Essential entity€10 000 000, or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher
Important entity€7 000 000, or 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher

The Enforcement Committee decides whether an entity is compliant. Before deciding, it must allow the entity to provide documentation or make submissions (article 33(2)). If it finds non-compliance, it imposes an administrative fine, indicates the amount, sets a timeframe for payment and for remedying the breach, and gives reasons for its decision (articles 33(4) and 33(5)).

Management bodies also have skin in the game: they must approve the cybersecurity risk-management measures and oversee their implementation, and the natural persons composing them may be held liable for infringements (article 18(1)).

Want to know where you stand before an inspector does? Use our free scoping and gap tool to check whether you are likely an essential or important entity and to identify the gaps a CIP Department audit would flag.

Frequently asked questions

What is the difference between supervision of essential and important entities in Malta?

Essential entities face a proactive (ex-ante) regime with regular and targeted audits, on-site inspections and random checks under article 29. Important entities are supervised mainly ex-post — that is, when the CIP Department has evidence or an indication of non-compliance — under article 30. Both sets of measures must be effective, proportionate and dissuasive.

Can the CIP Department order an audit at my expense?

Yes. Under S.L. 460.41, the costs of a targeted security audit carried out by an independent body are paid by the audited entity, except in duly substantiated cases where the authority decides otherwise (article 29(4) for essential entities and article 30(4)).

What fines can be imposed for NIS2 breaches in Malta?

For infringements of article 19 or article 20, essential entities face administrative penalties of up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 000 000 or 1.4% of turnover, whichever is higher (article 32). Penalties are imposed by the Enforcement Committee (article 33).

Can managers be held personally liable?

Yes. Under article 18, management bodies of essential and important entities must approve and oversee the cybersecurity risk-management measures, and the natural persons composing them may be held liable for infringements of article 19 by the entity, in accordance with the Order.

Check your NIS2 compliance

Run the free gap analysis

Start the free scoping test Run the free surface scan

The complete NIS2 guide — Malta

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home