NIS2 · Malta

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

NIS2 step by step for digital infrastructure providers in Malta

Published: · AIPOS OÜ · nis2europe.eu

This roadmap sets out seven steps that follow from the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The order divides the companies within its scope into two statutory classes, the essential entity and the important entity, and article 4 determines which class a digital infrastructure provider falls into. The CIP Department is the national supervisory authority under article 7, while the First Schedule designates the Malta Communications Authority (MCA) as competent authority for the digital infrastructure sector.

The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.

This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.

1. Scope: does the order cover the company

The First Schedule of S.L. 460.41 covers the digital infrastructure sector, listing providers of internet exchange points, DNS service providers other than operators of root name servers, top-level domain name registries, providers of cloud computing services, providers of data centre services, providers of content delivery networks, trust service providers and providers of electronic communications services and of publicly available electronic communications services. Under article 4(1)(a) a listed type of entity that exceeds the ceilings for medium-sized enterprises set by Article 2(1) of the Annex to Commission Recommendation 2003/361/EC counts as an essential entity, and article 4(1)(b) places qualified trust service providers, top-level domain name registries and DNS service providers in that class irrespective of their size. Article 4(1)(c) adds providers of public electronic communications networks or of publicly available electronic communications services that qualify as medium-sized enterprises, while article 4(2) treats every other listed entity that is not covered by article 4(1) as an important entity. Article 23 governs which Member State has jurisdiction, with article 23(1)(b) tying DNS, TLD, cloud, data centre and content delivery network providers to the Member State of their main establishment in the Union.

NACE 61NACE 63.11

See also the sector page: Digital infrastructure · NIS2 entity categories — Malta

Start the free applicability check

2. Management body: approval, oversight and training

Article 18(1) provides that the management bodies of essential and important entities approve the cybersecurity risk-management measures required by article 19 and supervise how those measures are put into practice. The same provision states that the natural persons who make up the management body may be held liable for infringements of article 19 by the entity, in the manner set out in articles 31(10)(b) and 33. Article 18(3) requires the members of the management body to undergo training so that they can perform their tasks. Article 18(4) obliges the entity to offer comparable training to its staff on a regular basis, so that employees can recognise risks and judge the effect of cybersecurity practices on the services provided.

NIS2 management body training obligation by country

3. Risk analysis as the foundation

Article 19(1)(a) requires essential and important entities to adopt appropriate and proportionate technical, operational and organisational measures that manage the risks to the network and information systems used for their operations or services, and that limit the impact of incidents on service recipients and on other services. Article 19(1)(b) links the level of security to the risks involved, taking account of the state of the art, applicable European and international standards and the cost of implementation, and it measures proportionality against the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) names policies on risk analysis and on the security of information systems as part of the minimum content of those measures. Article 19(1)(c)(ii) further requires the appointed security liaison officer to see that the entity carries out and keeps up to date appropriate risk assessments, and article 7(3)(c) places supervision of that duty with the CIP Department or the designated competent authority.

The platform generates this document automatically — it is included in the document package. Services

4. The catalogue of risk-management measures

Article 19(2) builds the measures on an all-hazards approach covering both the network and information systems and their physical surroundings, and sets a minimum content that includes risk analysis and information system security policies, incident handling, business continuity with backup management, disaster recovery and crisis management, supply chain security in relation to direct suppliers and service providers, security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure, procedures for assessing how effective the measures are, basic cyber hygiene and cybersecurity training, the use of cryptography and, where suitable, encryption, human resources security together with insider risk management, access control and asset management, multi-factor or continuous authentication and secured communications where appropriate, and the logging and traceability of systems. Two national additions apply to every entity within scope: article 19(1)(c) requires the appointment of a security liaison officer with the necessary expertise who also acts as the contact point towards the supervisory authority, and article 19(1)(d) requires the entity to receive monitoring services from an internal or an autonomous CSIRT meeting article 9(1). The order sets out no separate measures catalogue for the digital infrastructure sector, so article 19 applies in the same terms to all essential and important entities. Article 19(3) adds that supplier-specific vulnerabilities and the quality of suppliers' products and practices are taken into account, and article 19(4) requires corrective action without undue delay where an entity finds that it does not meet those measures.

NIS2 risk-management measures vs ISO 27001, DORA and GDPR

5. Incident notification and its deadlines

Under article 20(1) essential and important entities notify the national CSIRT immediately of any incident with a significant impact on the provision of their services, and the national CSIRT then informs the CIP Department and any designated competent authority in writing. Article 20(5)(a) sets an early warning to be submitted without undue delay and in any event within twenty-four (24) hours of the entity becoming aware of the significant incident, and article 20(5)(b) sets an incident notification without undue delay and in any event within seventy-two (72) hours of becoming aware, containing an initial assessment of severity and impact and any available indicators of compromise. Article 20(5)(c) allows the national CSIRT to request an intermediate status report, and article 20(5)(d) requires a final report not later than one (1) month after the incident notification, describing the incident, the likely root cause, the mitigation applied and any cross-border effect; where the incident is still ongoing at that point, article 20(5)(e) provides for a progress report and a final report within one (1) month of the handling of the incident. By way of derogation, article 20(6) requires a trust service provider to notify the national CSIRT of significant incidents affecting its trust services without undue delay and in any event within twenty-four (24) hours of becoming aware of the incident.

NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services

6. Written records the order presupposes

Several duties in S.L. 460.41 can only be demonstrated in writing: article 19(2)(a) speaks of policies on risk analysis and information system security, and article 19(2)(f) of policies and procedures for assessing the effectiveness of the risk-management measures. Article 29(2) allows the supervisory authority to ask an essential entity for information on its risk-management measures, including documented cybersecurity policies, for evidence that those policies are implemented, such as audit results, and for evidence of operator security plans, business continuity plans and, where needed, termination plans; article 30(2) gives equivalent powers in relation to important entities on an ex post basis. Article 7(3)(d) places the drawing up and maintenance of operator security plans and business continuity plans under the supervision of the CIP Department or the designated competent authority. Article 7(4) requires entities providing services in Malta to register on the national self-registration mechanism with the listed contact and sector details, and article 7(5) requires any change to those details to be notified without delay and in any event within two (2) weeks of the change.

The package includes:

Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month Services

7. Administrative penalty ceilings

Article 32(3) provides that essential entities which infringe article 19 or article 20 are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of the undertaking's total worldwide turnover for the preceding financial year, whichever amount is higher. Article 32(4) sets the corresponding ceilings for important entities at a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of that turnover, whichever amount is higher. Under article 33 the Enforcement Committee decides on such penalties on a report from the CIP Department or the designated competent authority, and it first allows the entity to submit documents or observations. Article 31(1) requires the authority to notify its preliminary findings in writing before imposing enforcement measures and to give the entity a period of up to fifteen (15) working days to respond and to propose remedies.

NIS2 administrative fines by country

Frequently asked questions

Which authority supervises digital infrastructure providers in Malta?

Article 7(1) makes the CIP Department the national supervisory authority responsible for monitoring implementation of S.L. 460.41 and ensuring compliance with it across the sectors and entity types in the First and Second Schedules. For the digital infrastructure sector the First Schedule designates the Malta Communications Authority (MCA) as competent authority, and article 7(2) requires designated competent authorities to work under the supervision of the CIP Department. Incident notifications under article 20(1) go to the national CSIRT, which is established within the Malta Information Technology Agency by article 8(1).

Does size decide whether a digital infrastructure provider is an essential entity?

Not in every case. Article 4(1)(a) uses the medium-sized enterprise ceilings of Article 2(1) of the Annex to Commission Recommendation 2003/361/EC for First Schedule entity types in general, but article 4(1)(b) classifies qualified trust service providers, top-level domain name registries and DNS service providers as essential entities regardless of size. Article 4(1)(c) covers providers of public electronic communications networks and of publicly available electronic communications services that are medium-sized, and article 4(2) places the remaining listed entities in the important entity class.

What happens if an entity discovers that its measures fall short of article 19?

Article 19(4) provides that an entity which finds it does not comply with the measures in article 19(2) takes all necessary, appropriate and proportionate corrective measures without undue delay, following article 29 for essential entities and article 30 for important entities. Article 31(4) adds that where the deficiency is remedied within the period given and the entity agrees in writing to abide by any enforcement measure, the authority may decide not to take the matter further. Published guidance from the CIP Department or the designated competent authority is the reference point for the practical detail of these procedures.

Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum 135edbf1dcee).

Back to home