Malta's NIS2 Law: The Complete Guide for Managing Directors

Published: · AIPOS OÜ · nis2europe.eu

What the Maltese NIS2 law is and when it applies

Malta transposes the EU NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). This national Order gives effect in Malta to Directive (EU) 2022/2555 — the NIS2 Directive — which was adopted on 14 December 2022 and repealed the earlier NIS Directive (Directive (EU) 2016/1148).

In plain terms, S.L. 460.41 is the rulebook that decides which Maltese organisations must manage cybersecurity risk, how they must report incidents, and what happens if they do not. It also designates the national authority that supervises compliance and the national CSIRT that receives incident reports.

For a managing director, three things matter from the outset:

The official consolidated text is published at legislation.mt. The binding version is always the official Maltese legal text of S.L. 460.41.

Who is in scope: essential and important entities

S.L. 460.41 splits regulated organisations into two statutory categories: essential entity and important entity. The category you fall into determines how strictly you are supervised and how high your maximum penalties can be.

Under article 4, the following are treated as essential entities, among others:

Under article 4(2), entities of a type referred to in the First or Second Schedule that do not qualify as essential entities are treated as important entities. This also covers entities specifically identified as important entities by the CIP Department (or, where designated, the competent authority).

Practical takeaway: the size thresholds are tied to the EU medium-sized enterprise ceilings, and the relevant sectors and sub-sectors are set out in the First and Second Schedules to the Order. If your activity appears there, you should assume you are in scope and confirm your classification.

The registration duty and its deadline

S.L. 460.41 establishes a national self-registration mechanism. Under article 7, the CIP Department must set up this mechanism for essential and important entities providing services in Malta, for the CSIRTs providing monitoring services within such entities, and for entities providing domain name registration services in Malta.

Under article 7(4), essential and important entities providing services in Malta (as well as entities providing domain name registration services in Malta) shall register on the national self-registration mechanism and provide at least:

Keeping your registration current is a legal duty. Under article 7(5), entities must notify the CIP Department of any change to the submitted details without delay and, in any event, within two (2) weeks of the date of the change.

The exact electronic registration channel and any precise onboarding deadline are to be confirmed — [TÄPSUSTAB PARTNER-JURIST].

The ten risk-management measure areas (the article 21(2) checklist)

The heart of the law is the risk-management obligation. Under article 19 of S.L. 460.41 (which implements article 21(2) of Directive (EU) 2022/2555), essential and important entities must take appropriate and proportionate technical, operational and organisational measures, based on an all-hazards approach.

Use the following as a board-level checklist. Under article 19(2), the measures must include at least:

Beyond the ten-plus areas, article 19(1) also requires entities to appoint a security liaison officer with the necessary expertise and to receive CSIRT monitoring services from either an internal or an autonomous CSIRT. Under article 19(4), where an entity finds it does not comply, it must take all necessary, appropriate and proportionate corrective measures without undue delay.

Incident notification: what to report and by when

Under article 20, essential and important entities must immediately notify the national CSIRT of any incident that has a significant impact on the provision of their services. The mere act of notifying does not, in itself, increase the entity's liability.

The reporting timeline under article 20(5) is staged. The entity must submit to the national CSIRT:

StageDeadlineContent
Early warningWithin 24 hours of becoming aware of the significant incidentWhere applicable, whether the incident is suspected to be caused by unlawful or malicious acts, or could have a cross-border impact
Incident notificationWithin 72 hours of becoming awareUpdate to the early warning plus an initial assessment of severity and impact and, where available, indicators of compromise
Intermediate reportUpon request of the national CSIRTRelevant status updates
Final reportNot later than 1 month after the incident notificationDetailed description, severity and impact, likely root cause, applied and ongoing mitigation measures, and cross-border impact where applicable

For an ongoing incident at the time the final report is due, the entity must provide a progress report then and a final report within one month of handling the incident (article 20(5)(e)).

Special rule for trust service providers: by way of derogation, a trust service provider must notify significant incidents affecting its trust services within 24 hours of becoming aware (article 20(6)).

Where appropriate, entities must also inform the recipients of their services of significant incidents or significant cyber threats that may affect them (article 20(2) and (4)). The national CSIRT aims to provide initial feedback, where possible within 24 hours of receiving the early warning (article 20(7)).

Fines and management liability

The penalties under S.L. 460.41 are substantial and are tied to your classification. Under article 32, where an entity infringes article 19 or article 20:

These administrative penalties are imposed in addition to the enforcement measures available under articles 29, 30 and 31 (article 32(1)). Under article 33, the Enforcement Committee has the power to impose the administrative fines on any entity reported by the CIP Department (or the designated competent authority) as non-compliant. Before deciding, the Committee allows the entity to provide documentation or make submissions, and it must give reasons for its decision and set a timeframe for payment and for remedying the breach.

Management liability is explicit. Under article 18, management bodies of essential and important entities must approve the cybersecurity risk-management measures and oversee their implementation. The natural persons composing the management bodies may be held liable for infringements of article 19. Members of the management bodies are also required to follow training, and entities must offer similar training to employees on a regular basis (article 18(3) and (4)).

The supervisory authority and what supervision looks like

The Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring the implementation of the Order at national level and ensuring compliance with it (article 7). The First and Second Schedules may designate specific competent authorities for particular sectors or sub-sectors, all operating under the supervision of the CIP Department.

Supervision of essential entities (article 29) is proactive and can include:

Supervision of important entities (article 30) is primarily ex post — that is, the authority acts where there is evidence, indication or information of non-compliance, in particular with articles 19 and 20.

Enforcement measures for both categories include warnings, binding instructions, orders to cease infringing conduct, orders to bring measures into compliance within a set period, designation of a monitoring officer (for essential entities), and orders to make aspects of infringements public. All measures must be effective, proportionate and dissuasive.

Not sure where you stand? A structured scoping exercise — checking your sector against the First and Second Schedules, confirming your essential/important classification, mapping your controls against the article 19 checklist and testing your incident-reporting readiness — is the fastest way to see your gaps before the CIP Department does. Use our free NIS2 scoping and gap tool to get started.

Frequently asked questions

What is the Maltese law that implements NIS2?

Malta implements the NIS2 Directive (EU) 2022/2555 through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, S.L. 460.41. It sets out scope, risk-management measures, incident reporting, penalties and supervision.

What are the incident reporting deadlines under S.L. 460.41?

Under article 20, entities must submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report not later than one month after the incident notification. Trust service providers must notify within 24 hours.

How high can the fines be under Malta's NIS2 law?

Under article 32, essential entities face a maximum of €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face a maximum of €7 000 000 or 1.4% of total worldwide annual turnover, whichever is higher.

Who supervises NIS2 compliance in Malta?

The Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority under article 7. It monitors implementation, runs the self-registration mechanism, and exercises supervisory and enforcement powers over essential and important entities under articles 29 and 30.

Explore the topics in depth

NIS2 articles and guides

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan Services

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home