NIS2 · Malta

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

NIS2 step by step: public administration in Malta

Published: · AIPOS OÜ · nis2europe.eu

This roadmap sets out seven steps that follow the obligations of the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The order divides entities covered by its Schedules into the classes of essential entity and important entity, and the First Schedule lists public administration among the sectors of high criticality with the CIP Department as national supervisory authority.

The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.

This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.

1. Scope: when the order covers a public administration entity

Article 4(1)(a) of S.L. 460.41 treats an entity of a type indicated in the First Schedule as an essential entity where it exceeds the ceilings for medium-sized enterprises set under Article 2(1) of the Annex to Commission Recommendation 2003/361/EC. Item 10 of the First Schedule covers public administration entities of central government and at regional level as defined under national law, together with public administration entities providing broadcasting and transmission services, and names the CIP Department as the national supervisory authority for that sector. Article 4(1)(d) classifies public administration entities mentioned in article 3(3)(f)(i) as an essential entity, and article 4(2) places Schedule types that do not qualify under article 4(1) in the class of important entity. Article 23(1)(c) attaches jurisdiction over a public administration entity to the Member State that established it.

NACE 84

See also the sector page: Public administration · NIS2 entity categories — Malta

Start the free applicability check

2. Management body: approval, oversight and training

Article 18(1) provides that the management bodies of an essential entity and of an important entity approve the cybersecurity risk-management measures under article 19 and oversee how those measures are implemented. The same sub-article states that the natural persons composing the management body may be held liable for the entity's infringements of article 19, in accordance with articles 31(10)(b) and 33. Article 18(2) leaves untouched the national liability rules that apply to public institutions and to public servants and elected or appointed officials. Article 18(3) requires members of management bodies to follow training for their tasks, and article 18(4) requires the entity to offer comparable training to employees on a regular basis.

NIS2 management body training obligation by country

3. Risk analysis as the foundation

Article 19(1)(a) obliges an essential entity and an important entity to take appropriate and proportionate technical, operational and organisational measures against the risks to the network and information systems used for their operations or services, and to limit the effect of incidents on service recipients. Article 19(1)(b) ties the level of security to the risks posed, taking account of the state of the art, applicable European and international standards and the cost of implementation, with proportionality assessed against the entity's exposure to risk, its size and the likelihood and severity of incidents. Article 19(2)(a) names policies on risk analysis and information system security within the minimum catalogue of measures. Article 19(1)(c)(ii) assigns the security liaison officer the task of ensuring that the entity conducts and maintains appropriate risk assessments, and article 7(3)(c) makes the CIP Department responsible for ensuring that such risk assessments are carried out.

The platform generates this document automatically — it is included in the document package. Services

4. The catalogue of risk-management measures

Article 19(2) bases the measures on an all-hazards approach and sets a minimum that runs from risk analysis and information system security policies and incident handling, through business continuity covering backups, disaster recovery and crisis management, supply chain security in relation to direct suppliers and service providers, and security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure. The same sub-article continues with procedures for assessing how effective the measures are, basic cyber hygiene and cybersecurity training, rules on cryptography and, where suitable, encryption, human resources security together with insider risk management, access control and asset management, multi-factor or continuous authentication and secured communication channels where appropriate, and, under point (k), logging and traceability of network and information systems. Article 19(1)(c) adds the appointment of a security liaison officer and article 19(1)(d) the receipt of monitoring services from an internal or an autonomous CSIRT. The order applies this catalogue in the same way to every essential entity and important entity within its scope, and the First Schedule sets no separate measure for the public administration sector, while article 19(4) requires corrective measures without undue delay where an entity finds that it does not comply.

NIS2 risk-management measures vs ISO 27001, DORA and GDPR

5. Incident notification and its stages

Article 20(1) requires an essential entity and an important entity to notify the national CSIRT immediately of an incident with a significant impact on the provision of their services, after which the national CSIRT informs the CIP Department in writing. Article 20(5)(a) sets an early warning within twenty-four (24) hours of the entity becoming aware of a significant incident, indicating where applicable any suspicion of unlawful or malicious acts or possible cross-border effect. Article 20(5)(b) sets an incident notification within seventy-two (72) hours of the entity becoming aware of the significant incident, updating the earlier information and giving an initial assessment, and article 20(5)(c) allows the national CSIRT to ask for an intermediate report. Article 20(5)(d) sets a final report not later than one (1) month after the incident notification, and article 20(5)(e) provides for a progress report where the incident is still running, followed by a final report within one (1) month of the handling of the incident.

NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services

6. Written policies, plans and evidence

The minimum catalogue in article 19(2) is framed as policies and procedures, among them risk analysis and information system security policies under point (a), procedures for assessing the effectiveness of the measures under point (f) and rules on cryptography under point (h), which the entity keeps and maintains in written form. Article 19(1)(c)(iii) places on the security liaison officer the duty to see that the entity maintains and exercises an operator security plan, while article 7(3)(d) makes the CIP Department responsible for ensuring that operator security plans and business continuity plans are drawn up and kept up to date. Article 29(2)(e) and (g) allow the supervisory authority to request information on the risk-management measures adopted by an essential entity, including its documented cybersecurity policies, and evidence that those policies are implemented, such as the results of security audits with the underlying evidence. Article 30(2)(d), (f) and (i) provide the equivalent ex post requests for an important entity, covering documented policies, evidence of implementation and evidence of operator security plans and business continuity plans.

The package includes:

Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month Services

7. Administrative penalty ceilings

Article 32(3) provides that an essential entity infringing article 19 or article 20 faces an administrative penalty of a maximum of ten million euro (€10 000 000), or of two percent (2%) of the total worldwide annual turnover of the undertaking concerned in the preceding financial year, whichever is higher. Article 32(4) sets the ceiling for an important entity at a maximum of seven million euro (€7 000 000), or one point four percent (1.4%) calculated on the same turnover basis, whichever is higher. Article 32(5) states that administrative penalties may be imposed against public administration entities. Under article 33 the Enforcement Committee imposes the fine after allowing the entity to submit documentation or observations, and its reasoned decision indicates the amount, the period for payment and the period for remedying the breach.

NIS2 administrative fines by country

Frequently asked questions

Which authority supervises public administration entities in Malta?

Item 10 of the First Schedule to S.L. 460.41 names the CIP Department as the national supervisory authority for the public administration sector. Article 7(1) makes the CIP Department responsible for monitoring implementation of the order at national level and for ensuring compliance with it, covering the sectors and types of entities listed in the tables to the First and Second Schedules.

Is there a registration duty under the order?

Article 7(1)(c) tasks the CIP Department with setting up a national self-registration mechanism, and article 7(4) provides that essential and important entities providing services in Malta register on it, giving at least the entity's name, the CSIRT providing monitoring services and whether it is internal or autonomous, address and up-to-date contact details, the relevant sector or sub-sector where applicable, and the Member States where in-scope services are provided. Article 7(5) requires changes to those details to be notified to the CIP Department without delay and in any event within two (2) weeks of the change.

Where must a significant incident be reported first?

Article 20(1) directs the notification to the national CSIRT, which under article 8(1) is established within the Malta Information Technology Agency and handles incidents for the sectors and types of entities in the First and Second Schedules. The national CSIRT then informs the CIP Department in writing, and under article 20(7) it aims to respond to the notifying entity where possible within twenty-four (24) hours of receiving the early warning.

Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum 49d1499032e8).

Back to home