NIS2 in Malta for manufacturing companies: the seven-step roadmap under S.L. 460.41
Under the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41), manufacturing is listed in the Second Schedule, so companies in the sector fall under the order as either an 'essential entity' or an 'important entity' according to article 4. The roadmap below sets out seven steps drawn from the order, from classification under article 4 to the administrative penalty ceilings in article 32. The Critical Infrastructure Protection Department acts as the national supervisory authority under article 7.
The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.
This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.
1. Step 1: Scope and classification under article 4
The Second Schedule to S.L. 460.41 lists Manufacturing as a sector, with sub-sectors covering the manufacture of medical devices and in vitro diagnostic medical devices, computer, electronic and optical products, electrical equipment, machinery and equipment n.e.c., motor vehicles, trailers and semi-trailers, and other transport equipment. Article 4(1)(a) treats entities of a type indicated in the First Schedule that exceed the ceilings for medium-sized enterprises under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC as an 'essential entity'. Article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as essential entities are considered an 'important entity', which is the ordinary position for the Second Schedule manufacturing sub-sectors. Article 23(1) links jurisdiction to establishment in Malta, and article 7(4) requires in-scope entities providing services in Malta to register on the national self-registration mechanism, with changes notified within two (2) weeks under article 7(5).
NACE 26NACE 27NACE 28NACE 29NACE 30NACE 32.50
See also the sector page: Manufacturing · NIS2 entity categories — Malta
2. Step 2: The management body approves and oversees
Article 18(1) provides that management bodies of essential and important entities approve the cybersecurity risk-management measures set out in article 19 and oversee their implementation. The same sub-article states that the natural persons composing the management body may be held liable for infringements of article 19 by the entity, in accordance with articles 31(10)(b) and 33. Article 18(3) requires members of the management body to follow training in order to carry out their tasks. Article 18(4) adds that the entity offers similar training to its employees on a regular basis, so that they can identify risks and assess cybersecurity risk-management practices.
3. Step 3: Risk analysis as the foundation
Article 19(1)(a) obliges in-scope entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems they use for their operations or services. Article 19(1)(b) ties the level of security to the risks posed, taking into account the state of the art, relevant European and international standards and the cost of implementation, and requires proportionality to be judged against the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) names policies on risk analysis and information system security as a minimum element of the measures. Under article 19(1)(c)(ii) the appointed security liaison officer ensures that the entity conducts and maintains appropriate risk assessments, while article 7(3)(c) places the supervision of those assessments with the CIP Department.
The platform generates this document automatically — it is included in the document package. Services
4. Step 4: The catalogue of risk-management measures
Article 19(2) requires an all-hazards approach protecting both the network and information systems and their physical environment, and lists as a minimum: policies on risk analysis and information system security, incident handling, business continuity including backup management, disaster recovery and crisis management, supply chain security covering relationships with direct suppliers and service providers, security in acquisition, development and maintenance including vulnerability handling and disclosure, policies and procedures to assess the effectiveness of the measures, basic cyber hygiene practices and cybersecurity training, cryptography and where appropriate encryption, human resources security, insider risk management, access control and asset management, multi-factor or continuous authentication and secured communications where appropriate, and logging and traceability. The order sets no separate measures catalogue for manufacturing: article 19 applies in the same terms to all essential and important entities, with proportionality assessed case by case under article 19(1)(b). Article 19(1)(c) additionally requires the appointment of a security liaison officer with the necessary expertise, and article 19(1)(d) requires monitoring services from an internal or an autonomous CSIRT. Where an entity finds that it does not comply with the measures in article 19(2), article 19(4) provides that corrective measures follow without undue delay.
5. Step 5: Incident notification and its deadlines
Article 20(1) provides that essential and important entities immediately notify the national CSIRT of any incident that has a significant impact on the provision of their services, and the national CSIRT in turn notifies the CIP Department in writing. Under article 20(5)(a) an early warning goes to the national CSIRT without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident. Under article 20(5)(b) an incident notification follows without undue delay and in any event within seventy-two (72) hours of becoming aware of the significant incident, updating the early warning with an initial assessment of severity and impact and, where available, indicators of compromise. Article 20(5)(c) allows the national CSIRT to request an intermediate report, and article 20(5)(d) sets a final report not later than one (1) month after the submission of the incident notification; where the incident is still ongoing at that point, article 20(5)(e) provides for a progress report and a final report within one (1) month of the handling of the incident.
NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services
6. Step 6: Written records the order presupposes
Article 19(2) frames its minimum elements as policies and procedures, which the order treats as written instruments rather than informal practice. Article 29(2)(e) empowers the supervisory authority to request information needed to assess the risk-management measures of an essential entity, including documented cybersecurity policies, and article 29(2)(g) allows requests for evidence of implementation such as the results of security audits and the underlying evidence. Article 29(2)(j) refers to evidence of operator security plans, business continuity plans and, where necessary, termination plans, and article 19(1)(c)(iii) places the maintenance and exercising of an operator security plan with the security liaison officer. For important entities, article 30(2)(d), (f) and (i) provide equivalent ex post powers to request documented cybersecurity policies, evidence of implementation and evidence of those plans.
The package includes:
- Cybersecurity Risk Management Policy
- Incident Handling Plan
- Business Continuity Plan
- Supply Chain Security Policy
- Management Responsibility Statement and Training Framework
- Fill-in assistant in the portal
Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month — Services
7. Step 7: Administrative penalty ceilings
Article 32(3) provides that, where they infringe article 19 or article 20, essential entities are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher. Article 32(4) sets the corresponding figures for important entities at a maximum of seven million euro (€7 000 000) or a maximum of one point four percent (1.4%) of that turnover, whichever is higher. Article 33 places the power to impose these fines with the Enforcement Committee, which under article 33(2) allows the entity to provide documentation or make submissions before deciding, and under article 33(5) states the amount, the payment timeframe and the timeframe for remedying the breach, with reasons. Article 32(1) provides that administrative penalties are imposed in addition to the enforcement measures available under articles 29(6), 30(6) and 31(10).
Frequently asked questions
Is a manufacturing company in Malta an essential entity or an important entity?
Manufacturing appears in the Second Schedule to S.L. 460.41. Article 4(1)(a) reserves the 'essential entity' class for entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC, while article 4(2) provides that entities of a type referred to in the First or Second Schedule which do not qualify as essential are considered an 'important entity'. Article 4(1)(e) and article 4(2) also allow the CIP Department, or where designated the competent authority, to identify an entity in either class pursuant to articles 3(3)(b) to (e).
Who supervises manufacturing entities and who receives incident notifications?
Under article 7(1) the CIP Department is the national supervisory authority responsible for monitoring implementation of the order and ensuring compliance with it, and the Second Schedule names the CIP Department as the national supervisory authority for the manufacturing sub-sectors. Incident notifications under article 20(1) go to the national CSIRT, which is established within the Malta Information Technology Agency under article 8(1). The national CSIRT then notifies the CIP Department in writing, and under article 20(7) it aims to respond to the early warning where possible within twenty-four (24) hours of receiving it.
Does the order require the entity to register anywhere?
Article 7(1)(c) tasks the CIP Department with establishing a national self-registration mechanism for essential and important entities providing services in Malta. Article 7(4) provides that those entities register on that mechanism and supply at least the entity name, the name of the CSIRT providing monitoring services and whether it is internal or autonomous, address and up-to-date contact details including email addresses, IP ranges and telephone numbers, the relevant sector and sub-sector where applicable, and where applicable a list of the Member States in which they provide in-scope services. Article 7(5) requires changes to those details to be notified to the CIP Department without delay and in any event within two (2) weeks of the date of the change.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum ba9f1e741434).