NIS2 step by step for healthcare providers in Malta
In Malta, cybersecurity duties for the health sector follow from the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The Order distinguishes two statutory classes, essential entity and important entity, and article 7 makes the Critical Infrastructure Protection Department the national supervisory authority. This roadmap sets out seven steps that follow the structure of the Order, from classification under article 4 to the administrative penalties in article 32.
The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.
This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.
1. Step 1: Scope and classification under article 4
The First Schedule to S.L. 460.41 lists Health as a sector of high criticality and covers, among others, healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU, EU reference laboratories referred to in Article 15 of Regulation (EU) 2022/2371, entities carrying out research and development activities of medicinal products, entities manufacturing basic pharmaceutical products and pharmaceutical preparations, entities manufacturing medical devices considered critical during a public health emergency, and entities holding a distribution authorisation under Article 79 of Directive 2001/83/EC. Under article 4(1)(a), an entity of a type indicated in the First Schedule is an essential entity where it exceeds the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC. Article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as essential entities are considered to be important entities, including those identified as such by the CIP Department under articles 3(3)(b) to (e). Article 23(1) links jurisdiction to establishment in Malta, and article 7(4) requires essential and important entities providing services in Malta to register on the national self-registration mechanism established by the CIP Department.
NACE 86NACE 21NACE 32.50
See also the sector page: Healthcare · NIS2 entity categories — Malta
2. Step 2: Management body approval, oversight and training
Article 18(1) provides that management bodies of essential and important entities approve the cybersecurity risk-management measures under article 19 and oversee their implementation. The same sub-article states that the natural persons composing the management bodies may be held liable for infringements of that article in accordance with articles 31(10)(b) and 33. Article 18(3) requires members of management bodies to follow training in order to carry out their tasks. Article 18(4) adds that essential and important entities offer similar training to their employees on a regular basis, so that they can identify risks and assess cybersecurity risk-management practices and their impact on the entity's services.
3. Step 3: Risk analysis as the legal foundation
Article 19(1)(a) obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage risks to the security of the network and information systems they use for their operations or services, and to limit the impact of incidents on service recipients and other services. Article 19(1)(b) ties the security level to the risks posed, taking account of the state of the art, relevant European and international standards and implementation cost, while proportionality is judged by the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) names policies on risk analysis and information system security as a minimum element of those measures. Article 19(1)(c) further requires the appointment of a security liaison officer who, among other duties, ensures that the entity conducts and maintains appropriate risk assessments and maintains and exercises an operator security plan, and who acts as the point of contact with the CIP Department.
The platform generates this document automatically — it is included in the document package. Services
4. Step 4: The catalogue of risk-management measures
Article 19(2) builds the measures on an all-hazards approach protecting network and information systems and their physical environment, and lists as a minimum: risk analysis and information system security policies, incident handling, business continuity including backup management, disaster recovery and crisis management, supply chain security, security in acquisition, development and maintenance including vulnerability handling and disclosure, procedures to assess the effectiveness of the measures, basic cyber hygiene practices and cybersecurity training, cryptography and where appropriate encryption, human resources security, insider risk management policy, access control and asset management, multi-factor or continuous authentication with secured voice, video, text and emergency communications where appropriate, and logging and traceability. S.L. 460.41 sets no separate health-sector variant of this catalogue: article 19 applies in the same terms to all essential and important entities, with proportionality assessed individually under article 19(1)(b). Article 19(3) requires supply chain decisions to take account of vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices. Article 19(4) provides that an entity finding itself non-compliant with the measures in article 19(2) takes all necessary, appropriate and proportionate corrective measures without undue delay.
5. Step 5: Incident notification to the national CSIRT
Article 20(1) requires essential and important entities to notify the national CSIRT immediately of any incident having a significant impact on the provision of their services, and the national CSIRT in turn notifies the CIP Department in writing. Under article 20(5)(a), an early warning is submitted without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident, indicating where applicable whether the incident is suspected to stem from unlawful or malicious acts or could have cross-border impact. Under article 20(5)(b), an incident notification follows without undue delay and in any event within seventy-two (72) hours of becoming aware of the significant incident, updating the early warning with an initial assessment of severity and impact and, where available, indicators of compromise. Article 20(5)(c) allows the national CSIRT to request an intermediate report, and article 20(5)(d) sets a final report not later than one (1) month after submission of the incident notification, covering the description of the incident, the likely threat type or root cause, applied and ongoing mitigation measures and any cross-border impact.
NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services
6. Step 6: Written records the Order presupposes
The measures in article 19(2) are expressed as policies and procedures, which the Order treats as documented rather than informal. Article 29(2)(e) empowers the CIP Department to request information needed to assess an essential entity's cybersecurity risk-management measures, including documented cybersecurity policies, and article 29(2)(g) allows requests for evidence of implementation of those policies, such as the results of security audits by a qualified auditor and the underlying evidence. Article 29(2)(j) covers requests for evidence of operator security plans, business continuity plans and, where necessary, termination plans, and articles 30(2)(d), 30(2)(f) and 30(2)(i) mirror these powers for important entities on an ex post basis. Article 7(4) and article 7(5) also require registration details to be kept current, with changes notified to the CIP Department without delay and in any event within two (2) weeks of the date of the change.
The package includes:
- Cybersecurity Risk Management Policy
- Incident Handling Plan
- Business Continuity Plan
- Supply Chain Security Policy
- Management Responsibility Statement and Training Framework
- Fill-in assistant in the portal
Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month — Services
7. Step 7: Administrative penalty ceilings
Article 32(3) provides that essential entities infringing articles 19 or 20 are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher. Article 32(4) sets the ceiling for important entities at a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of that turnover, whichever is higher. Under article 33, the Enforcement Committee imposes these fines on entities reported as non-compliant, after allowing the entity to provide documentation or submissions, and its decision states the amount, the payment timeframe and the timeframe for remedying the breach. Article 32(1) provides that administrative penalties are imposed in addition to the enforcement measures available under articles 29(6), 30(6) and 31(10).
Frequently asked questions
Which authority supervises healthcare entities in Malta under S.L. 460.41?
Article 7(1) designates the CIP Department as the national supervisory authority responsible for monitoring implementation of the Order and ensuring compliance, covering the sectors, sub-sectors and types of entities listed in the tables to the First and Second Schedules. In the First Schedule, the competent authority stated for the Health sector is the CIP Department as the national supervisory authority. Incident notifications under article 20(1) go to the national CSIRT, which is established within the Malta Information Technology Agency under article 8(1).
What separates an essential entity from an important entity in the health sector?
Article 4(1)(a) treats an entity of a type listed in the First Schedule as an essential entity where it exceeds the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC. Article 4(2) treats First or Second Schedule entities that do not qualify as essential entities as important entities. The CIP Department, or where designated the competent authority, may also identify entities in either class under articles 3(3)(b) to (e).
Do the reporting deadlines differ for healthcare entities?
Article 20(5) applies the same stages to essential and important entities: an early warning within twenty-four (24) hours of becoming aware of the significant incident, an incident notification within seventy-two (72) hours, and a final report not later than one (1) month after the incident notification. Article 20(5)(e) provides that where the incident is still ongoing at the time of the final report, a progress report is given then and a final report within one (1) month of the handling of the incident. A separate twenty-four (24) hour derogation in article 20(6) concerns trust service providers rather than the health sector.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum ba9f1e741434).