NIS2 step by step in Malta: the roadmap for the food sector
In Malta, NIS2 is transposed by the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41), which is supervised by the Critical Infrastructure Protection Department (CIP Department). The order covers the production, processing and distribution of food in item 4 of its Second Schedule and sorts covered companies into two statutory classes, 'essential entity' and 'important entity', under article 4. This roadmap sets out, in seven steps, what the order provides for such companies, from coverage through to the administrative penalty ceilings in article 32.
The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.
This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.
1. Step 1: Coverage of food companies
Item 4 of the Second Schedule to S.L. 460.41 names, for the sector of production, processing and distribution of food, food businesses within the meaning of Article 3, point (2), of Regulation (EC) No 178/2002 that are engaged in wholesale distribution and in industrial production and processing, with the CIP Department named as the national supervisory authority. Article 4(1)(a) treats entities of a type listed in the First Schedule that go beyond the medium-sized enterprise ceilings set under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC as an 'essential entity'. Article 4(2) provides that entities of a type referred to in the Second Schedule which do not qualify under article 4(1) are considered an 'important entity', and the same provision covers entities designated by the CIP Department, or where designated the competent authority, under articles 3(3)(b) to (e). Article 23(1) places entities within the scope of the order under Maltese jurisdiction where they are established in Malta.
NACE 10
See also the sector page: Food · NIS2 entity categories — Malta
2. Step 2: Management body and training
Article 18(1) of S.L. 460.41 provides that the management bodies of essential and important entities approve the cybersecurity risk-management measures under article 19 and oversee how those measures are implemented. The same sub-article states that the natural persons who make up the management body may be held liable for the entity's infringements of that article, by reference to articles 31(10)(b) and 33. Article 18(3) requires members of the management bodies to follow training so that they can carry out their tasks. Article 18(4) adds that essential and important entities offer comparable training to their staff on a regular basis, so that employees can recognise risks and judge the effect of cybersecurity practices on the services provided.
3. Step 3: Risk analysis as the foundation
Article 19(1)(a) of S.L. 460.41 obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures for the risks affecting the network and information systems used in their operations or services, and to limit the impact of incidents on service recipients and on other services. Article 19(1)(b) ties the security level to the risks posed, taking account of the state of the art, applicable European and international standards and the cost of implementation, and it makes proportionality depend on the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) places policies on risk analysis and on information system security within the mandatory baseline. Article 19(1)(c)(ii) assigns to the security liaison officer the task of ensuring that the entity carries out and maintains appropriate risk assessments, and article 7(3)(c) gives the CIP Department the role of ensuring that such risk assessments are carried out.
The platform generates this document automatically — it is included in the document package. Services
4. Step 4: Catalogue of security measures
Article 19(2) of S.L. 460.41 builds the measures on an all-hazards approach protecting network and information systems and their physical environment, and lists as a minimum: risk analysis and information system security policies; incident handling; business continuity with backup management, disaster recovery and crisis management; supply chain security in relation to direct suppliers and service providers; security in the acquisition, development and maintenance of systems, including vulnerability handling and disclosure; procedures for assessing how effective the measures are; basic cyber hygiene and cybersecurity training; use of cryptography and, where suitable, encryption; human resources security, insider risk management, access control and asset management; multi-factor or continuous authentication and secured communications where appropriate; and logging and traceability. The order adds two national elements in article 19(1): the appointment of a security liaison officer with the tasks set out in points (i) to (iv), and the receipt of monitoring services from an internal or an autonomous CSIRT under point (d). This catalogue is worded for essential and important entities alike, and the order sets out no measure that applies only to the food sector. Article 19(3) directs entities to weigh the vulnerabilities of each direct supplier and the quality of their products and security practices, while article 19(4) provides that an entity which finds itself non-compliant takes corrective measures without undue delay.
5. Step 5: Incident notification and deadlines
Article 20(1) of S.L. 460.41 provides that essential and important entities notify the national CSIRT immediately of any incident with a significant impact on the provision of their services, and that the national CSIRT in turn informs the CIP Department in writing. Article 20(5)(a) sets an early warning without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident. Article 20(5)(b) sets an incident notification without undue delay and in any event within seventy-two (72) hours of becoming aware of the significant incident, with an initial assessment of severity and impact. Article 20(5)(c) allows the national CSIRT to request an intermediate status report, article 20(5)(d) sets a final report not later than one (1) month after the incident notification, and article 20(5)(e) provides for a progress report where the incident is still ongoing, followed by a final report within one (1) month of its handling.
NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services
6. Step 6: Written records and registration
Because article 19(2) of S.L. 460.41 requires policies on risk analysis and information system security, procedures for assessing the effectiveness of the measures and policies on cryptography, access control and asset management, those obligations are met in written and maintained form. Article 29(2) allows the CIP Department, or where designated the competent authority, to request from an essential entity documented cybersecurity policies, evidence that those policies are implemented, audit results and evidence of operator security plans and business continuity plans, and article 30(2) provides comparable ex post powers in relation to an important entity. Article 7(4) requires essential and important entities providing services in Malta to register on the national self-registration mechanism and to supply the details listed in points (a) to (e). Article 7(5) provides that changes to those details are notified to the CIP Department without delay and in any event within two (2) weeks of the change.
The package includes:
- Cybersecurity Risk Management Policy
- Incident Handling Plan
- Business Continuity Plan
- Supply Chain Security Policy
- Management Responsibility Statement and Training Framework
- Fill-in assistant in the portal
Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month — Services
7. Step 7: Administrative penalty ceilings
Article 32(3) of S.L. 460.41 provides that, for infringements of article 19 or article 20, an essential entity is subject to administrative penalties of a maximum of ten million euro (€10 000 000), or of a maximum of two percent (2%) of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher. Article 32(4) sets the corresponding figures for an important entity at a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of that turnover, whichever is higher. Article 32(1) states that such penalties come in addition to the enforcement measures available under articles 29(6), 30(6) and 31(10). Article 33 places the power to impose these administrative fines with the Enforcement Committee, which first allows the entity to submit documentation or observations and gives reasons for its decision.
Frequently asked questions
Which food companies in Malta come within the order?
Item 4 of the Second Schedule to S.L. 460.41 covers food businesses as defined in Article 3, point (2), of Regulation (EC) No 178/2002 that are engaged in wholesale distribution and in industrial production and processing. Under article 4(2), entities of a Second Schedule type that do not meet the criteria in article 4(1) are considered an 'important entity'. Article 23(1) links jurisdiction to establishment in Malta.
Who receives an incident notification, and by when?
Article 20(1) of S.L. 460.41 designates the national CSIRT as the recipient, and provides that the national CSIRT informs the CIP Department in writing. Article 20(5) sets an early warning within twenty-four (24) hours of becoming aware of the significant incident, an incident notification within seventy-two (72) hours, and a final report not later than one (1) month after that notification.
Does the management body carry duties of its own?
Article 18(1) of S.L. 460.41 provides that management bodies approve the cybersecurity risk-management measures under article 19 and oversee their implementation, and that the natural persons composing them may be held liable for the entity's infringements of that article in line with articles 31(10)(b) and 33. Article 18(3) requires those members to follow training, and article 18(4) provides for regular comparable training for employees.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum ba9f1e741434).