NIS2 Supervision and Enforcement in Malta: What the CIP Department Can Do
Who supervises NIS2 in Malta?
Malta transposed the NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). Under this Order, the Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring implementation of the Order at national level and ensuring compliance with it (article 7).
In practice, this means the CIP Department is the body that will identify and designate your organisation as an essential entity or an important entity, monitor your cybersecurity risk-management measures (article 19), monitor your incident reporting obligations (article 20), and — where deficiencies are found — apply supervisory and enforcement measures (articles 29 and 30).
Note that for certain sectors and sub-sectors, the First and Second Schedules may designate a different competent authority. Those designated competent authorities operate under the supervision of the CIP Department as the national supervisory authority (article 7(2)). For readability, this article refers throughout to "the CIP Department, or where designated the competent authority".
Supervision of essential entities: the ex-ante model
For essential entities, the Order sets out a proactive (ex-ante) supervisory regime. When exercising its supervisory tasks in relation to essential entities, the CIP Department has the power to subject those entities at least to the following (article 29(2)):
- On-site inspections and off-site supervision, including random checks conducted by trained professionals
- Regular and targeted security audits carried out by an independent body or by the authority
- Ad hoc audits, including where justified by a significant incident or an infringement
- Security scans based on objective, non-discriminatory, fair and transparent risk-assessment criteria
- Requests for information needed to assess your cybersecurity risk-management measures, including documented cybersecurity policies
- Requests to access data, documents and information necessary to carry out supervisory tasks
- Requests for evidence of implemented cybersecurity policies (such as audit results), CSIRT monitoring services, operator security plans, business continuity plans and, where necessary, termination plans
Targeted security audits are based on risk assessments conducted by the authority or the audited entity (article 29(3)). Importantly, the costs of a targeted security audit carried out by an independent body are paid by the audited essential entity, except in duly substantiated cases where the authority decides otherwise (article 29(4)).
When making information requests, the authority must state the purpose of the request and specify the information requested (article 29(5)).
Supervision of important entities: the ex-post model
For important entities, the Order applies a lighter, reactive (ex-post) model. The CIP Department takes action, where necessary, through ex post supervisory measures — that is, when it is provided with evidence, indication or information that an important entity allegedly does not comply with the Order, in particular articles 19 and/or 20 (article 30(1)).
When exercising supervisory tasks in relation to important entities, the authority has the power to apply at least (article 30(2)):
- On-site inspections and off-site ex post supervision conducted by trained professionals
- Targeted security audits carried out by an independent body or the authority
- Security scans based on objective, non-discriminatory, fair and transparent criteria
- Requests for information to assess, ex post, your cybersecurity risk-management measures
- Requests to access data, documents and information, and requests for evidence of implemented policies, CSIRT monitoring, operator security plans and business continuity plans
Key difference: essential entities face regular, proactive audits and checks (ex-ante), whereas important entities are generally supervised only when there is an indication of non-compliance (ex-post). Both regimes require the supervisory and enforcement measures to be effective, proportionate and dissuasive, taking into account the circumstances of each individual case (articles 29(1) and 30(1)).
Enforcement measures: warnings, binding orders and more
If supervision reveals problems, the CIP Department has a graduated toolkit of enforcement measures. For essential entities, the authority may (article 29(6)):
- Issue warnings about infringements, including failure to cooperate with supervisory measures
- Adopt binding instructions or an order to remedy deficiencies or infringements, with time-limits
- Order the entity to cease infringing conduct and desist from repeating it
- Order the entity to bring its risk-management measures into line with article 19 and/or fulfil the reporting obligations under article 20
- Order the entity to inform affected customers of a significant cyber threat
- Order implementation of security-audit recommendations within a reasonable deadline
- Designate a monitoring officer to oversee compliance with articles 19 and 20
- Order the entity to make public aspects of infringements
- Order the entity to receive CSIRT monitoring services and to register under the national self-registration mechanism
For important entities, a broadly similar list of enforcement measures applies (article 30(6)) — with the notable difference that the appointment of a dedicated monitoring officer is not listed for important entities.
The authority may impose these measures periodically on essential entities (article 29(8)).
Administrative penalties
In addition to the enforcement measures above, the CIP Department may request the imposition of an administrative penalty by the Enforcement Committee (articles 29(7), 30(7) and 33). Administrative penalties are imposed in addition to the enforcement measures, not instead of them (article 32(1)).
Where an entity infringes article 19 (risk-management measures) or article 20 (reporting), the maximum penalties are (article 32):
| Entity type | Maximum administrative penalty |
|---|---|
| Essential entity | €10 000 000, or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher |
| Important entity | €7 000 000, or 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher |
The Enforcement Committee decides whether an entity is compliant. Before deciding, it must allow the entity to provide documentation or make submissions (article 33(2)). If it finds non-compliance, it imposes an administrative fine, indicates the amount, sets a timeframe for payment and for remedying the breach, and gives reasons for its decision (articles 33(4) and 33(5)).
Management bodies also have skin in the game: they must approve the cybersecurity risk-management measures and oversee their implementation, and the natural persons composing them may be held liable for infringements (article 18(1)).
Want to know where you stand before an inspector does? Use our free scoping and gap tool to check whether you are likely an essential or important entity and to identify the gaps a CIP Department audit would flag.
Frequently asked questions
What is the difference between supervision of essential and important entities in Malta?
Essential entities face a proactive (ex-ante) regime with regular and targeted audits, on-site inspections and random checks under article 29. Important entities are supervised mainly ex-post — that is, when the CIP Department has evidence or an indication of non-compliance — under article 30. Both sets of measures must be effective, proportionate and dissuasive.
Can the CIP Department order an audit at my expense?
Yes. Under S.L. 460.41, the costs of a targeted security audit carried out by an independent body are paid by the audited entity, except in duly substantiated cases where the authority decides otherwise (article 29(4) for essential entities and article 30(4)).
What fines can be imposed for NIS2 breaches in Malta?
For infringements of article 19 or article 20, essential entities face administrative penalties of up to €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 000 000 or 1.4% of turnover, whichever is higher (article 32). Penalties are imposed by the Enforcement Committee (article 33).
Can managers be held personally liable?
Yes. Under article 18, management bodies of essential and important entities must approve and oversee the cybersecurity risk-management measures, and the natural persons composing them may be held liable for infringements of article 19 by the entity, in accordance with the Order.
Check your NIS2 compliance
The complete NIS2 guide — Malta →
This article is general information, not legal advice. A partner lawyer confirms your specific situation.