NIS2 step by step for energy companies in Malta
This roadmap sets out seven steps under the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The order distinguishes two classes, the essential entity and the important entity, and the energy sector appears in the First Schedule with the Critical Infrastructure Protection Department named as national supervisory authority. It covers classification, governance, risk management, security measures, incident reporting to the national CSIRT, documentation and administrative penalties.
The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.
This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.
1. Step 1: Sector coverage and entity class
The First Schedule to S.L. 460.41 lists Energy as a sector of high criticality, with the sub-sectors electricity, district heating and cooling, oil, gas and hydrogen, and it names the Critical Infrastructure Protection Department as the national supervisory authority for each of them. Within electricity the listed types include electricity undertakings carrying out the supply function within the meaning of Directive (EU) 2019/944, distribution system operators, transmission system operators, producers, nominated electricity market operators, market participants providing aggregation, demand response or energy storage services, and operators of recharging points. Under article 4(1)(a) an entity of a type in the First Schedule that exceeds the ceilings for medium-sized enterprises set in Article 2(1) of the Annex to Commission Recommendation 2003/361/EC is an essential entity, while article 4(2) treats a listed entity that does not meet that condition as an important entity. Article 23(1) places entities established in Malta under Maltese jurisdiction, and article 4(1)(e) allows the CIP Department, or the designated competent authority, to identify further listed entities as essential entities.
NACE 35.1NACE 35.30NACE 35.2NACE 06NACE 19.20NACE 49.50
See also the sector page: Energy · NIS2 entity categories — Malta
2. Step 2: Management body approval and training
Article 18(1) provides that the management bodies of essential and important entities approve the cybersecurity risk-management measures referred to in article 19 and oversee how those measures are implemented. The same sub-article states that the natural persons who make up the management body may be held liable for infringements of that article by the entity, in accordance with articles 31(10)(b) and 33. Article 18(3) requires members of the management body to follow training so that they can carry out their tasks. Article 18(4) adds that the entity offers comparable training to its employees on a regular basis, so that they can recognise risks and judge the effect of cybersecurity practices on the services the entity provides.
3. Step 3: Risk analysis as the foundation
Article 19(1)(a) obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems used for their operations or services. Article 19(1)(b) links the level of security to the risks posed, taking account of the state of the art, applicable European and international standards and the cost of implementation, and it directs that proportionality is judged against the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) places policies covering risk analysis and the security of information systems at the head of the mandatory catalogue. Article 19(1)(c)(ii) assigns the security liaison officer the task of ensuring that the entity carries out and keeps up to date appropriate risk assessments, and article 7(3)(c) makes the supervisory authority responsible for ensuring that such assessments are performed.
The platform generates this document automatically — it is included in the document package. Services
4. Step 4: The catalogue of security measures
Article 19(2) requires an all-hazards approach protecting network and information systems and their physical environment, and it lists as a minimum: risk analysis and information system security policies, incident handling, business continuity such as backup management, disaster recovery and crisis management, supply chain security in the relationship with direct suppliers and service providers, security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure, procedures to assess how effective the measures are, basic cyber hygiene and cybersecurity training, cryptography and where appropriate encryption, human resources security, insider risk management, access control and asset management, multi-factor or continuous authentication together with secured voice, video, text and emergency communications where appropriate, and logging and traceability. Article 19(1)(c) additionally requires the appointment of a security liaison officer with the necessary expertise, who supports business continuity and where needed termination plans, maintains and exercises an operator security plan and acts as contact point with the authority, while article 19(1)(d) requires monitoring services from an internal or an autonomous CSIRT. Article 19(3) directs that supply chain choices take into account the vulnerabilities of each direct supplier, the quality of their products and practices and the results of the coordinated security risk assessments of critical supply chains. The order sets this catalogue for all essential and important entities alike and does not lay down a separate measures list for the energy sector; where an entity finds it does not comply, article 19(4) requires corrective measures without undue delay.
5. Step 5: Notifying significant incidents
Article 20(1) requires essential and important entities to notify the national CSIRT immediately of any incident with a significant impact on the provision of their services, and the national CSIRT then informs the CIP Department, and any other designated competent authority, in writing. Under article 20(5)(a) an early warning is submitted without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident, indicating where applicable a suspicion of unlawful or malicious acts or a possible cross-border effect. Under article 20(5)(b) an incident notification follows without undue delay and in any event within seventy-two (72) hours of becoming aware of the incident, updating the earlier information and giving an initial assessment of severity, impact and available indicators of compromise. Article 20(5)(c) provides for an intermediate report at the request of the national CSIRT, and article 20(5)(d) sets a final report not later than one (1) month after the incident notification; where the incident is still ongoing at that point, article 20(5)(e) provides for a progress report and a final report within one (1) month of the handling of the incident. Article 20(2) and 20(4) also address informing service recipients about significant incidents and about significant cyber threats, and the mere act of notification does not increase the notifying entity's liability.
NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services
6. Step 6: Written policies, plans and records
The measures in article 19(2) are expressed as policies and procedures, covering risk analysis and system security, effectiveness assessment, cryptography, access control and asset management, so the order presupposes that they exist in written and maintained form. Article 19(1)(c) refers to business continuity plans, where necessary termination plans, maintained risk assessments and an operator security plan that is kept current and exercised. In supervision, article 29(2) allows the authority to request documented cybersecurity policies, evidence that those policies are implemented such as audit results with the underlying evidence, evidence of CSIRT monitoring services and evidence of operator security plans and business continuity plans, and article 30(2) provides comparable ex post powers in relation to important entities. Article 7(4) requires registration in the national self-registration mechanism with the entity's name, its CSIRT, contact details including email addresses, IP ranges and telephone numbers, the relevant sector or sub-sector and the Member States served, and article 7(5) requires changes to be notified without delay and in any event within two (2) weeks of the change.
The package includes:
- Cybersecurity Risk Management Policy
- Incident Handling Plan
- Business Continuity Plan
- Supply Chain Security Policy
- Management Responsibility Statement and Training Framework
- Fill-in assistant in the portal
Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month — Services
7. Step 7: Administrative penalty ceilings
Article 32(3) provides that essential entities infringing article 19 or article 20 are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher. Article 32(4) sets the corresponding ceilings for important entities at a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of that worldwide annual turnover, whichever is higher. Article 32(1) states that such penalties come in addition to the enforcement measures available under articles 29(6), 30(6) and 31(10), and article 32(2) links the amount in each case to the elements listed in article 31(8). Under article 33 the Enforcement Committee imposes the fine, after allowing the entity to submit documentation or representations, and its decision states the amount, the payment period, the period for remedying the breach and the reasons.
Frequently asked questions
Which authority supervises energy companies in Malta under S.L. 460.41?
The First Schedule names the Critical Infrastructure Protection Department as the national supervisory authority for the electricity, district heating and cooling, oil, gas and hydrogen sub-sectors. Article 7(1) makes that department responsible for monitoring implementation of the order and ensuring compliance with it, including the criteria for identifying essential and important entities and the national self-registration mechanism. Incident notifications under article 20(1) go to the national CSIRT, which is established within the Malta Information Technology Agency by article 8(1).
What separates an essential entity from an important entity in the energy sector?
Article 4(1)(a) treats an entity of a type listed in the First Schedule that exceeds the ceilings for medium-sized enterprises under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC as an essential entity. Article 4(2) treats listed entities that do not meet that condition as important entities, including entities identified as such by the CIP Department or the designated competent authority under articles 3(3)(b) to (e). Article 4(1)(f) and (g) also place entities identified as critical entities, and those identified before 16 January 2023 as operators of essential services, in the essential entity class.
What incident reporting deadlines does article 20 set?
An early warning is due without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident. An incident notification with an initial assessment is due without undue delay and in any event within seventy-two (72) hours of becoming aware of it. A final report is due not later than one (1) month after the incident notification, and where the incident is still ongoing a progress report is given instead, with the final report within one (1) month of the handling of the incident.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum bee981bfeb87).