NIS2 · Malta

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

NIS2 step by step for the drinking water sector in Malta

Published: · AIPOS OÜ · nis2europe.eu

This roadmap sets out seven steps that follow the obligations of the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The Order covers the drinking water sector through its First Schedule and divides the companies concerned into the classes of essential entity and important entity under article 4. The Critical Infrastructure Protection Department is the national supervisory authority under article 7.

The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.

This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.

1. Step 1: Whether the Order covers the company

The First Schedule to S.L. 460.41 lists Drinking water as a sector of high criticality and covers water suppliers and distributors that provide water intended for human consumption within the meaning of Article 2, point (1)(a) of Directive (EU) 2020/2184, while a distributor is left outside the sector entry where such distribution is only a non-essential part of its wider business of distributing other commodities and goods. Under article 4(1)(a), an entity of a type listed in the First Schedule that exceeds the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC is an essential entity. Under article 4(2), entities of a type referred to in the First or Second Schedule that do not meet the conditions for the first class are important entities, and the CIP Department may also identify entities in either class pursuant to articles 3(3)(b) to (e). Article 23(1) places entities established in Malta under Maltese jurisdiction, and article 7(4) requires essential and important entities providing services in Malta to register on the national self-registration mechanism, with changes reported within two (2) weeks under article 7(5).

NACE 36

See also the sector page: Drinking water · NIS2 entity categories — Malta

Start the free applicability check

2. Step 2: Duties of the management body

Article 18(1) provides that management bodies of essential and important entities approve the cybersecurity risk-management measures required by article 19 and oversee how those measures are implemented. The same sub-article states that the natural persons who make up the management body may be held liable for infringements of that article, in accordance with articles 31(10)(b) and 33. Article 18(3) requires members of the management body to follow training so that they can carry out their tasks, and article 18(4) requires the entity to offer similar training to its employees on a regular basis. Article 31(10)(b) further allows the CIP Department to request the relevant bodies, courts or tribunals to prohibit temporarily a person holding chief executive or legal representation responsibilities in an essential entity from exercising managerial functions there.

NIS2 management body training obligation by country

3. Step 3: The risk analysis foundation

Article 19(1)(a) obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage risks to the security of the network and information systems used for their operations and services, and to limit the impact of incidents on service recipients and on other services. Article 19(1)(b) links the level of security to the risks posed, taking account of the state of the art, relevant European and international standards and the cost of implementation, and it directs that proportionality be judged against the entity's exposure to risk, its size and the likelihood and severity of incidents, including their societal and economic impact. Article 19(2)(a) places policies on risk analysis and information system security among the minimum content of those measures. Article 19(1)(c)(ii) assigns the appointed security liaison officer the role of ensuring that the entity conducts and maintains appropriate risk assessments, while article 7(3)(c) makes the CIP Department responsible for ensuring that such risk assessments are carried out.

The platform generates this document automatically — it is included in the document package. Services

4. Step 4: The catalogue of security measures

Article 19(2) requires an all-hazards approach protecting network and information systems and their physical environment, and sets a minimum catalogue: risk analysis and information system security policies, incident handling, business continuity including backup management, disaster recovery and crisis management, and supply chain security covering relationships with direct suppliers and service providers. The catalogue continues with security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, procedures for assessing how effective the measures are, basic cyber hygiene and cybersecurity training, cryptography and, where appropriate, encryption, human resources security together with insider risk management, access control and asset management, multi-factor or continuous authentication and secured voice, video, text and emergency communications where appropriate, and logging and traceability of network and information systems. Article 19(1)(c) adds the appointment of a security liaison officer with the necessary expertise, and article 19(1)(d) requires monitoring services from an internal or an autonomous CSIRT. The Order sets this catalogue identically for all essential and important entities in scope and states no measure specific to the drinking water sector; where an entity finds that it does not comply, article 19(4) requires corrective measures without undue delay.

NIS2 risk-management measures vs ISO 27001, DORA and GDPR

5. Step 5: Notifying significant incidents

Article 20(1) requires essential and important entities to notify the national CSIRT immediately of any incident that has a significant impact on the provision of their services, and the national CSIRT then informs the CIP Department in writing; article 8(1) places the national CSIRT within the Malta Information Technology Agency. Article 20(5)(a) sets an early warning without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident, indicating where applicable whether unlawful or malicious acts are suspected or a cross-border impact is possible. Article 20(5)(b) sets an incident notification without undue delay and in any event within seventy-two (72) hours of becoming aware of the significant incident, updating the earlier information with an initial assessment of severity and impact and, where available, indicators of compromise. Article 20(5)(c) allows the national CSIRT to request an intermediate report, and article 20(5)(d) sets a final report not later than one (1) month after the incident notification was submitted; where the incident is still ongoing at that point, article 20(5)(e) provides for a progress report and a final report within one (1) month of the entity's handling of the incident.

NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services

6. Step 6: Written records and evidence

The measures listed in article 19(2) are framed as policies and procedures, which means they exist in written and maintained form, and article 19(1)(c) tasks the security liaison officer with facilitating the development, implementation, maintenance and review of business continuity plans and, where needed, termination plans, and with ensuring that an operator security plan is maintained and exercised. Article 29(2) allows the CIP Department to ask an essential entity for information about its risk-management measures, including documented cybersecurity policies, for evidence of how those policies are implemented such as audit results and the underlying evidence, and for evidence of operator security plans, business continuity plans and termination plans. Article 30(2) gives comparable powers in relation to important entities, exercised ex post. Article 7(4) sets out the details to be provided on registration, and article 7(3)(d) makes the CIP Department responsible for ensuring that operator security plans and business continuity plans are drawn up and maintained.

The package includes:

Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month Services

7. Step 7: Administrative penalty ceilings

Article 32(3) provides that essential entities which infringe article 19 or article 20 are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or of a maximum of two percent (2%) of total worldwide annual turnover in the preceding financial year of the undertaking concerned, whichever is higher. Article 32(4) sets the corresponding ceilings for important entities at a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of that turnover, whichever is higher. Article 32(1) states that such penalties come in addition to the enforcement measures available under articles 29(6), 30(6) and 31(10), and article 32(2) requires regard to the elements listed in article 31(8) when the amount is determined. Under article 33, the Enforcement Committee imposes the administrative fine, after allowing the entity to submit documentation or representations, and states in its decision the amount, the payment timeframe and the time allowed to remedy the breach.

NIS2 administrative fines by country

Frequently asked questions

Which authority supervises drinking water entities in Malta?

Under article 7(1) of S.L. 460.41 the CIP Department is the national supervisory authority monitoring implementation of the Order and covering the sectors, sub-sectors and types of entities listed in the tables to the First and Second Schedules. In the First Schedule, the entry for the Drinking water sector names the CIP Department as the national supervisory authority. Significant incidents are notified to the national CSIRT under article 20(1), which then informs the CIP Department in writing.

What separates an essential entity from an important entity?

Article 4(1)(a) treats a First Schedule entity that exceeds the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC as an essential entity. Article 4(2) treats entities of a type referred to in the First or Second Schedule that do not fall under article 4(1) as important entities. Both classes may also arise from identification by the CIP Department pursuant to articles 3(3)(b) to (e).

Which reporting deadlines apply after a significant incident?

Article 20(5)(a) provides for an early warning to the national CSIRT within twenty-four (24) hours of becoming aware of the significant incident. Article 20(5)(b) provides for an incident notification within seventy-two (72) hours of becoming aware of it. Article 20(5)(d) provides for a final report not later than one (1) month after that incident notification, and article 20(5)(c) allows an intermediate report to be requested in the meantime.

Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum ba9f1e741434).

Back to home