NIS2 step by step for digital providers in Malta: the legal roadmap under S.L. 460.41
This roadmap sets out, in seven steps, what the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41) provides for the digital providers sector. The Second Schedule to that order covers providers of online marketplaces, providers of online search engines and providers of social networking services platforms. Article 4 divides entities within scope into two statutory classes, essential entity and important entity, and articles 18 to 20 set out governance, risk-management and reporting duties.
The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.
This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.
1. Step 1: Sector coverage and entity class
The Second Schedule to S.L. 460.41 lists, under the digital providers sector, providers of online marketplaces, providers of online search engines and providers of social networking services platforms, with the Malta Communications Authority (MCA) shown as the competent authority for that sector. Under article 4(1)(a), the size ceilings for medium-sized enterprises drawn from Article 2(1) of the Annex to Commission Recommendation 2003/361/EC operate for types of entity indicated in the First Schedule. Article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as an essential entity under article 4(1) are treated as an important entity, while article 4(1)(e) allows the CIP Department, or where designated the competent authority, to identify a First or Second Schedule entity as an essential entity under articles 3(3)(b) to (e). Article 23(1)(b) places providers of online marketplaces, online search engines and social networking services platforms under the jurisdiction of the Member State of their main establishment in the Union, determined in accordance with article 23(2).
NACE 63.12
See also the sector page: Digital providers · NIS2 entity categories — Malta
2. Step 2: Management body approval and training
Article 18(1) provides that management bodies of essential and important entities approve the cybersecurity risk-management measures set out in article 19 and oversee how those measures are implemented. The same sub-article states that the natural persons composing the management body may be held liable for infringements of that article by the entity, in accordance with articles 31(10)(b) and 33. Article 18(3) requires members of the management body to follow training so that they can carry out their tasks. Article 18(4) adds that the entity offers comparable training to its employees on a regular basis, so that they can identify risks and assess cybersecurity risk-management practices and their effect on the services provided.
3. Step 3: Risk analysis as the foundation
Article 19(1)(a) obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems used for their operations or services, and to limit the impact of incidents on the recipients of those services. Article 19(1)(b) links the level of security to the risks posed, taking account of the state of the art, relevant European and international standards and the cost of implementation, with proportionality assessed against the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) names policies on risk analysis and information system security among the minimum content of those measures. Under article 19(1)(c)(ii), the appointed security liaison officer ensures that the entity carries out and keeps up to date appropriate risk assessments.
The platform generates this document automatically — it is included in the document package. Services
4. Step 4: The catalogue of risk-management measures
Article 19(2) builds the measures on an all-hazards approach protecting network and information systems and their physical environment, and sets a minimum content: risk analysis and information system security policies, incident handling, business continuity covering backups, disaster recovery and crisis management, supply chain security in relation to direct suppliers and service providers, security in acquisition, development and maintenance including vulnerability handling and disclosure, procedures for assessing how effective the measures are, basic cyber hygiene and cybersecurity training, cryptography and where appropriate encryption, human resources security, insider risk management, access control and asset management, multi-factor or continuous authentication together with secured voice, video, text and emergency communications where appropriate, and logging and traceability. Article 19(1)(c) additionally requires the appointment of a security liaison officer with the necessary expertise, and article 19(1)(d) requires monitoring services from an internal or an autonomous CSIRT. Article 19(2) applies in the same terms to all essential and important entities, and the order does not set a separate measures catalogue for the digital providers sector. Where an entity finds that it does not meet those measures, article 19(4) requires corrective measures to be taken without undue delay.
5. Step 5: Incident notification and its deadlines
Article 20(1) provides that essential and important entities immediately notify the national CSIRT of any incident with a significant impact on the provision of their services, and that the national CSIRT then notifies the CIP Department and any other designated competent authority in writing. Under article 20(5)(a), an early warning is submitted without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident. Under article 20(5)(b), an incident notification follows without undue delay and in any event within seventy-two (72) hours of becoming aware of the significant incident, updating the earlier information and giving an initial assessment of severity, impact and any available indicators of compromise. Article 20(5)(c) allows the national CSIRT to request an intermediate report, and article 20(5)(d) sets a final report not later than one (1) month after the incident notification, with article 20(5)(e) providing for a progress report and a later final report where the incident is still ongoing.
NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services
6. Step 6: Written records the order presupposes
The measures in article 19(2) take the form of policies and procedures, and article 19(1)(c) places the development, implementation, maintenance and review of business continuity plans, the conduct of risk assessments and the upkeep and exercising of an operator security plan with the security liaison officer. Article 29(2) allows the supervisory authority to request information on the risk-management measures adopted, including documented cybersecurity policies, evidence of how those policies are implemented such as audit results, evidence of CSIRT monitoring services, and evidence of operator security plans, business continuity plans and, where needed, termination plans; article 30(2) gives comparable powers in relation to an important entity. Article 7(4) requires registration on the national self-registration mechanism with the entity name, the CSIRT providing monitoring services, contact details including email addresses, IP ranges and telephone numbers, the relevant sector or sub-sector and, where applicable, the Member States where in-scope services are provided. Article 7(5) provides that changes to those details are notified to the CIP Department without delay and in any event within two (2) weeks of the change.
The package includes:
- Cybersecurity Risk Management Policy
- Incident Handling Plan
- Business Continuity Plan
- Supply Chain Security Policy
- Management Responsibility Statement and Training Framework
- Fill-in assistant in the portal
Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month — Services
7. Step 7: Administrative penalty ceilings
Article 32(3) provides that, where they infringe article 19 or article 20, essential entities are subject to administrative penalties of a maximum of ten million euro (€10 000 000) or a maximum of two percent (2%) of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher. Article 32(4) sets the corresponding ceilings for important entities at a maximum of seven million euro (€7 000 000) or a maximum of one point four percent (1.4%) of that turnover, whichever is higher. Article 32(1) states that such penalties come in addition to the enforcement measures available under articles 29(6), 30(6) and 31(10). Under article 33, the Enforcement Committee imposes the fine, after allowing the entity to submit documentation or make submissions, and states in its decision the amount, the payment period and the time allowed to remedy the breach.
Frequently asked questions
Which authority supervises digital providers in Malta?
Under article 7(1) of S.L. 460.41, the CIP Department is the national supervisory authority responsible for monitoring implementation of the order and ensuring compliance with it, covering the sectors, sub-sectors and types of entity listed in the tables to the First and Second Schedules. In the Second Schedule, the Malta Communications Authority (MCA) is shown as the competent authority for the digital providers sector, and article 7(2) provides that designated competent authorities cooperate under the supervision of the CIP Department. Incident notifications under article 20(1) go to the national CSIRT, which is established within the Malta Information Technology Agency by article 8(1).
Is an online marketplace an essential entity or an important entity?
The digital providers sector appears in the Second Schedule. Article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as essential entities under article 4(1) are considered to be important entities. Article 4(1)(e) nonetheless allows the CIP Department, or where designated the competent authority, to identify an entity of a First or Second Schedule type as an essential entity pursuant to articles 3(3)(b) to (e).
Which Member State has jurisdiction over a platform operating in several countries?
Article 23(1)(b) provides that providers of online marketplaces, of online search engines and of social networking services platforms fall under the jurisdiction of the Member State of their main establishment in the Union. Article 23(2) locates that main establishment in the Member State where decisions on the cybersecurity risk-management measures are predominantly taken, failing which where cybersecurity operations are carried out, and failing that where the establishment with the highest number of employees in the Union is situated. Article 23(3) provides that an entity of that kind which is not established in the Union but offers services within it designates a representative established in one of the Member States where the services are offered.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum 377a947df672).