NIS2 · Malta

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

NIS2 in Malta for the banking sector: the seven steps set out by law

Published: · AIPOS OÜ · nis2europe.eu

This roadmap sets out seven steps that follow from the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The Order covers the Banking sector through its First Schedule and divides the entities in scope into an essential entity and an important entity under article 4. The Critical Infrastructure Protection Department (CIP Department) acts as the national supervisory authority, and incident notifications are addressed to the national CSIRT.

The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.

This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.

1. Step 1. Whether the Order covers the bank

The First Schedule to S.L. 460.41 lists Banking among the sectors of high criticality and covers credit institutions within the meaning of Article 4, point (1), of Regulation (EU) No 575/2013, with the CIP Department named there as the national supervisory authority. Under article 4(1)(a), a First Schedule entity that goes beyond the medium-sized enterprise ceilings set under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC is an essential entity. Article 4(2) provides that entities of a type listed in the First or Second Schedule which do not fall under article 4(1) are an important entity, and article 4(1)(e) allows the CIP Department to identify further entities as an essential entity. Article 23(1) places entities established in Malta under Maltese jurisdiction for the purposes of the Order.

NACE 64.19

See also the sector page: Banking · NIS2 entity categories — Malta

Start the free applicability check

2. Step 2. The management body and training

Article 18(1) provides that the management bodies of an essential entity and an important entity approve the cybersecurity risk-management measures under article 19 and oversee how they are implemented. The same sub-article states that the natural persons who make up those management bodies may be held liable for infringements of that article, by reference to articles 31(10)(b) and 33. Article 18(3) requires members of the management bodies to follow training so that they can carry out their tasks. Article 18(4) adds that entities offer comparable training to their staff on a regular basis, so that employees can recognise risks and judge the effect of cybersecurity practices on the services provided.

NIS2 management body training obligation by country

3. Step 3. Risk analysis as the foundation

Article 19(1)(a) obliges an essential entity and an important entity to take appropriate and proportionate technical, operational and organisational measures for the risks facing the network and information systems used in their operations or services. Article 19(1)(b) ties the level of security to the risks at hand, taking account of the state of the art, relevant European and international standards and the cost of implementation, while proportionality is judged against the entity's exposure, its size and the likelihood and severity of incidents. Article 19(2)(a) names policies on risk analysis and information system security as part of the minimum content of those measures. Under article 19(1)(c)(ii) the security liaison officer sees to it that the entity carries out and keeps up appropriate risk assessments, and article 7(3)(c) places supervision of that duty with the CIP Department.

The platform generates this document automatically — it is included in the document package. Services

4. Step 4. The catalogue of security measures

Article 19(2) builds the measures on an all-hazards approach that protects network and information systems and their physical environment, and sets a minimum catalogue. That catalogue covers risk analysis and information system security policies, incident handling, business continuity including backups, disaster recovery and crisis management, supply chain security in relations with direct suppliers and service providers, and security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure. It further covers procedures for assessing how effective the measures are, basic cyber hygiene and cybersecurity training, cryptography and where appropriate encryption, human resources security, insider risk management, access control and asset management, multi-factor or continuous authentication and secured communications, and logging and traceability. The Order sets no separate banking catalogue, since article 19 applies in the same terms to every essential entity and important entity, and article 19(1)(c) and 19(1)(d) add the appointment of a security liaison officer and the receipt of monitoring services from an internal or an autonomous CSIRT.

NIS2 risk-management measures vs ISO 27001, DORA and GDPR

5. Step 5. Notifying incidents and the deadlines

Article 20(1) provides that an essential entity and an important entity notify the national CSIRT immediately of any incident having a significant impact on the provision of their services, after which the national CSIRT informs the CIP Department in writing. Under article 20(5)(a) an early warning is submitted without undue delay and in any case no later than twenty-four (24) hours after the entity becomes aware of the significant incident. Article 20(5)(b) then sets an incident notification within seventy-two (72) hours of the entity becoming aware of it, with an initial assessment of severity and impact, while article 20(5)(c) allows the national CSIRT to ask for an intermediate report. Article 20(5)(d) sets a final report no later than one (1) month after the incident notification is submitted, and article 20(2) adds notification of service recipients where an incident is likely to affect them adversely.

NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services

6. Step 6. Written records behind the duties

The duties in article 19(2) are framed as policies and procedures, which means the measures exist in written and maintained form, covering risk analysis and information system security, the assessment of effectiveness, cryptography, and human resources and access control. Article 29(2)(e) and 29(2)(g) allow the CIP Department to request information on the measures adopted by an essential entity, including documented cybersecurity policies, and evidence that those policies are implemented, such as audit results and the underlying material. Article 29(2)(j) extends this to evidence of operator security plans, business continuity plans and, where needed, termination plans, and articles 30(2)(d), 30(2)(f) and 30(2)(i) provide equivalent ex post powers for an important entity. Article 7(4) requires registration details on the national self-registration mechanism, and article 7(5) requires changes to those details to be notified without delay and in any event within two (2) weeks.

The package includes:

Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month Services

7. Step 7. Administrative fine ceilings

Article 32(3) provides that an essential entity infringing article 19 or article 20 is subject to administrative penalties with a ceiling of ten million euro (€10 000 000), or two percent (2%) of the total worldwide annual turnover of the undertaking concerned in the preceding financial year, whichever of the two is higher. Article 32(4) sets the corresponding ceiling for an important entity at seven million euro (€7 000 000), or one point four percent (1.4%) of that turnover, again whichever is higher. Article 32(1) states that such penalties come in addition to the enforcement measures in articles 29(6), 30(6) and 31(10). Under article 33 the Enforcement Committee imposes the fine, and article 33(2) provides that the entity is first allowed to submit documentation or make submissions.

NIS2 administrative fines by country

Frequently asked questions

Which banks in Malta fall within the scope of S.L. 460.41?

The First Schedule lists Banking as a sector of high criticality and covers credit institutions within the meaning of Article 4, point (1), of Regulation (EU) No 575/2013. Article 4(1)(a) classifies such an entity as an essential entity where it goes beyond the medium-sized enterprise ceilings set under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC, while article 4(2) classifies the remaining listed entities as an important entity. Article 4(1)(e) also allows the CIP Department to identify a listed entity as an essential entity.

Which authority supervises the sector and where do incident notifications go?

The First Schedule names the CIP Department as the national supervisory authority for Banking, and article 7(1) gives it responsibility for monitoring implementation of the Order and ensuring compliance with it. Article 20(1) directs incident notifications to the national CSIRT, which then informs the CIP Department in writing. Article 7(4) requires entities providing services in Malta to register on the national self-registration mechanism with the details listed there.

What are the fine ceilings under the Order?

For an infringement of article 19 or article 20, article 32(3) sets the ceiling for an essential entity at ten million euro (€10 000 000) or two percent (2%) of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher. Article 32(4) sets the ceiling for an important entity at seven million euro (€7 000 000) or one point four percent (1.4%) on the same basis. Article 33 places the power to impose the fine with the Enforcement Committee, which first allows the entity to make submissions.

Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum ba9f1e741434).

Back to home