Malta's NIS2 Law: The Complete Guide for Managing Directors
What the Maltese NIS2 law is and when it applies
Malta transposes the EU NIS2 Directive through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). This national Order gives effect in Malta to Directive (EU) 2022/2555 — the NIS2 Directive — which was adopted on 14 December 2022 and repealed the earlier NIS Directive (Directive (EU) 2016/1148).
In plain terms, S.L. 460.41 is the rulebook that decides which Maltese organisations must manage cybersecurity risk, how they must report incidents, and what happens if they do not. It also designates the national authority that supervises compliance and the national CSIRT that receives incident reports.
For a managing director, three things matter from the outset:
- Your organisation may fall in scope even if you have never thought of yourself as a "critical" company.
- Cybersecurity is now a board-level obligation, not just an IT matter.
- Non-compliance carries administrative penalties and potential personal liability for the people who run the entity.
The official consolidated text is published at legislation.mt. The binding version is always the official Maltese legal text of S.L. 460.41.
Who is in scope: essential and important entities
S.L. 460.41 splits regulated organisations into two statutory categories: essential entity and important entity. The category you fall into determines how strictly you are supervised and how high your maximum penalties can be.
Under article 4, the following are treated as essential entities, among others:
- Entities of a type listed in the First Schedule that exceed the ceilings for medium-sized enterprises under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC;
- Qualified trust service providers, top-level domain name registries and DNS service providers, regardless of their size;
- Providers of public electronic communications networks or publicly available electronic communications services that qualify as medium-sized enterprises under the same Recommendation;
- Certain public administration entities;
- Entities designated as critical entities under the Resilience of Critical Entities and Infrastructures Order;
- Entities previously identified before 16 January 2023 as operators of essential services under the NIS 2 Directive or national law.
Under article 4(2), entities of a type referred to in the First or Second Schedule that do not qualify as essential entities are treated as important entities. This also covers entities specifically identified as important entities by the CIP Department (or, where designated, the competent authority).
Practical takeaway: the size thresholds are tied to the EU medium-sized enterprise ceilings, and the relevant sectors and sub-sectors are set out in the First and Second Schedules to the Order. If your activity appears there, you should assume you are in scope and confirm your classification.
The registration duty and its deadline
S.L. 460.41 establishes a national self-registration mechanism. Under article 7, the CIP Department must set up this mechanism for essential and important entities providing services in Malta, for the CSIRTs providing monitoring services within such entities, and for entities providing domain name registration services in Malta.
Under article 7(4), essential and important entities providing services in Malta (as well as entities providing domain name registration services in Malta) shall register on the national self-registration mechanism and provide at least:
- the name of the entity;
- the name of the CSIRT providing monitoring services and whether it is internal or autonomous;
- address and up-to-date contact details, including email addresses, IP ranges and telephone numbers;
- where applicable, the relevant sector and sub-sector listed in the First or Second Schedule;
- where applicable, a list of the Member States where they provide services within scope.
Keeping your registration current is a legal duty. Under article 7(5), entities must notify the CIP Department of any change to the submitted details without delay and, in any event, within two (2) weeks of the date of the change.
The exact electronic registration channel and any precise onboarding deadline are to be confirmed — [TÄPSUSTAB PARTNER-JURIST].
The ten risk-management measure areas (the article 21(2) checklist)
The heart of the law is the risk-management obligation. Under article 19 of S.L. 460.41 (which implements article 21(2) of Directive (EU) 2022/2555), essential and important entities must take appropriate and proportionate technical, operational and organisational measures, based on an all-hazards approach.
Use the following as a board-level checklist. Under article 19(2), the measures must include at least:
- (a) policies on risk analysis and information system security;
- (b) incident handling;
- (c) business continuity, such as backup management and disaster recovery, and crisis management;
- (d) supply chain security, including security aspects of relationships with direct suppliers and service providers;
- (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
- (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures;
- (g) basic cyber hygiene practices and cybersecurity training;
- (h) policies and procedures on the use of cryptography and, where appropriate, encryption;
- (i) human resources security, insider risk management policy, access control policies and asset management;
- (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems, where appropriate;
- (k) logging and traceability of network and information systems.
Beyond the ten-plus areas, article 19(1) also requires entities to appoint a security liaison officer with the necessary expertise and to receive CSIRT monitoring services from either an internal or an autonomous CSIRT. Under article 19(4), where an entity finds it does not comply, it must take all necessary, appropriate and proportionate corrective measures without undue delay.
Incident notification: what to report and by when
Under article 20, essential and important entities must immediately notify the national CSIRT of any incident that has a significant impact on the provision of their services. The mere act of notifying does not, in itself, increase the entity's liability.
The reporting timeline under article 20(5) is staged. The entity must submit to the national CSIRT:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware of the significant incident | Where applicable, whether the incident is suspected to be caused by unlawful or malicious acts, or could have a cross-border impact |
| Incident notification | Within 72 hours of becoming aware | Update to the early warning plus an initial assessment of severity and impact and, where available, indicators of compromise |
| Intermediate report | Upon request of the national CSIRT | Relevant status updates |
| Final report | Not later than 1 month after the incident notification | Detailed description, severity and impact, likely root cause, applied and ongoing mitigation measures, and cross-border impact where applicable |
For an ongoing incident at the time the final report is due, the entity must provide a progress report then and a final report within one month of handling the incident (article 20(5)(e)).
Special rule for trust service providers: by way of derogation, a trust service provider must notify significant incidents affecting its trust services within 24 hours of becoming aware (article 20(6)).
Where appropriate, entities must also inform the recipients of their services of significant incidents or significant cyber threats that may affect them (article 20(2) and (4)). The national CSIRT aims to provide initial feedback, where possible within 24 hours of receiving the early warning (article 20(7)).
Fines and management liability
The penalties under S.L. 460.41 are substantial and are tied to your classification. Under article 32, where an entity infringes article 19 or article 20:
- Essential entities face administrative penalties of a maximum of €10 000 000, or a maximum of 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs — whichever is higher (article 32(3)).
- Important entities face administrative penalties of a maximum of €7 000 000, or a maximum of 1.4% of the total worldwide annual turnover in the preceding financial year — whichever is higher (article 32(4)).
These administrative penalties are imposed in addition to the enforcement measures available under articles 29, 30 and 31 (article 32(1)). Under article 33, the Enforcement Committee has the power to impose the administrative fines on any entity reported by the CIP Department (or the designated competent authority) as non-compliant. Before deciding, the Committee allows the entity to provide documentation or make submissions, and it must give reasons for its decision and set a timeframe for payment and for remedying the breach.
Management liability is explicit. Under article 18, management bodies of essential and important entities must approve the cybersecurity risk-management measures and oversee their implementation. The natural persons composing the management bodies may be held liable for infringements of article 19. Members of the management bodies are also required to follow training, and entities must offer similar training to employees on a regular basis (article 18(3) and (4)).
The supervisory authority and what supervision looks like
The Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority responsible for monitoring the implementation of the Order at national level and ensuring compliance with it (article 7). The First and Second Schedules may designate specific competent authorities for particular sectors or sub-sectors, all operating under the supervision of the CIP Department.
Supervision of essential entities (article 29) is proactive and can include:
- on-site inspections and off-site supervision, including random checks;
- regular and targeted security audits by an independent body or the authority;
- ad hoc audits, including where justified by a significant incident;
- security scans, requests for information, and requests to access data and documents;
- requests for evidence of implemented policies, CSIRT monitoring, operator security plans and business continuity plans.
Supervision of important entities (article 30) is primarily ex post — that is, the authority acts where there is evidence, indication or information of non-compliance, in particular with articles 19 and 20.
Enforcement measures for both categories include warnings, binding instructions, orders to cease infringing conduct, orders to bring measures into compliance within a set period, designation of a monitoring officer (for essential entities), and orders to make aspects of infringements public. All measures must be effective, proportionate and dissuasive.
Not sure where you stand? A structured scoping exercise — checking your sector against the First and Second Schedules, confirming your essential/important classification, mapping your controls against the article 19 checklist and testing your incident-reporting readiness — is the fastest way to see your gaps before the CIP Department does. Use our free NIS2 scoping and gap tool to get started.
Frequently asked questions
What is the Maltese law that implements NIS2?
Malta implements the NIS2 Directive (EU) 2022/2555 through the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, S.L. 460.41. It sets out scope, risk-management measures, incident reporting, penalties and supervision.
What are the incident reporting deadlines under S.L. 460.41?
Under article 20, entities must submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report not later than one month after the incident notification. Trust service providers must notify within 24 hours.
How high can the fines be under Malta's NIS2 law?
Under article 32, essential entities face a maximum of €10 000 000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face a maximum of €7 000 000 or 1.4% of total worldwide annual turnover, whichever is higher.
Who supervises NIS2 compliance in Malta?
The Critical Infrastructure Protection Department (CIP Department) is the national supervisory authority under article 7. It monitors implementation, runs the self-registration mechanism, and exercises supervisory and enforcement powers over essential and important entities under articles 29 and 30.
Explore the topics in depth
Check your NIS2 compliance
Run the free gap analysis Run the free surface scan Services
This article is general information, not legal advice. A partner lawyer confirms your specific situation.