NIS2 in Malta for the transport sector: a seven-step roadmap under S.L. 460.41
This roadmap sets out seven steps drawn from the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). The order distinguishes two statutory classes, the essential entity and the important entity, and the transport sector appears in the First Schedule with its air, rail, water, road and public transport subsectors. The CIP Department is the national supervisory authority, and incident notifications go to the national CSIRT.
The free applicability check takes about three minutes. The full NIS2 document package is usually generated within an hour of payment — not in days or weeks.
This guide describes the requirements of the law at a general level and is not legal advice. Applicability depends on the company's profile (sector, size, services) — the free applicability check shows whether and to what extent the law applies to your company.
1. Step 1: Whether the order covers the transport company
The First Schedule to S.L. 460.41 lists Transport as a sector of high criticality, with subsectors for air, rail, water, road and public transport, naming for example air carriers used for commercial purposes, airport managing bodies, air traffic control operators, rail infrastructure managers and railway undertakings, inland, sea and coastal passenger and freight water transport companies, managing bodies of ports and operators of vessel traffic services, road authorities responsible for traffic management control and operators of Intelligent Transport Systems, as well as public service operators. Under article 4(1)(a) an entity of a type indicated in the First Schedule is an essential entity where it exceeds the ceilings for medium-sized enterprises set in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC. Under article 4(2) entities of a type referred to in the First or Second Schedule that do not qualify as essential entities are important entities, and the CIP Department or, where designated, the competent authority may also identify entities under articles 3(3)(b) to (e). Article 23(1) provides that entities within the scope of the order fall under the jurisdiction of Malta if they are established in Malta.
NACE 51NACE 52.23NACE 49.1NACE 49.2NACE 52.21NACE 50
See also the sector page: Transport · NIS2 entity categories — Malta
2. Step 2: The management body and training
Article 18(1) provides that management bodies of essential and important entities approve the cybersecurity risk-management measures set out in article 19 and oversee their implementation. The same sub-article states that the natural persons composing those management bodies may be held liable for infringements of that article, in accordance with articles 31(10)(b) and 33. Article 18(3) requires members of the management bodies to follow training in order to carry out their tasks. Article 18(4) provides that essential and important entities offer similar training to their employees on a regular basis, so that staff can identify risks and assess cybersecurity risk-management practices and their impact on the entity's services.
3. Step 3: Risk analysis as the foundation
Article 19(2)(a) places policies on risk analysis and information system security among the minimum content of the risk-management measures. Article 19(1)(a) and (b) frame those measures as appropriate and proportionate technical, operational and organisational measures giving a level of security appropriate to the risks posed, taking account of the state of the art, relevant European and international standards and the cost of implementation, and weighing the entity's exposure to risks, its size and the likelihood and severity of incidents. Article 19(1)(c) requires the appointment of a security liaison officer who ensures that the entity conducts and maintains appropriate risk assessments and that it maintains and exercises an operator security plan. Article 7(3)(c) and (d) place the CIP Department, unless another competent authority is responsible for the sector, in charge of ensuring that risk assessments are carried out and that operator security plans and business continuity plans are drawn up and maintained.
The platform generates this document automatically — it is included in the document package. Services
4. Step 4: The catalogue of cybersecurity measures
Article 19(2) requires an all-hazards approach protecting network and information systems and their physical environment, and lists as a minimum: risk analysis and information system security policies, incident handling, business continuity such as backup management and disaster recovery and crisis management, supply chain security covering direct suppliers and service providers, security in acquisition, development and maintenance including vulnerability handling and disclosure, policies and procedures to assess the effectiveness of the measures, basic cyber hygiene practices and cybersecurity training, cryptography and where appropriate encryption, human resources security, insider risk management policy, access control policies and asset management, multi-factor or continuous authentication and secured voice, video, text and emergency communications where appropriate, and logging and traceability. The order sets no separate measures catalogue for the transport sector: article 19 applies in the same terms to all essential and important entities, and the First Schedule names the CIP Department as national supervisory authority for the air, water, road and public transport subsectors, while for the rail subsector the competent authority column states that it is not applicable. Article 19(1)(c) additionally requires a security liaison officer with the necessary expertise, and article 19(1)(d) requires CSIRT monitoring services from an internal or an autonomous CSIRT. Under article 19(4), where an entity finds that it does not comply with the measures in article 19(2), it takes all necessary, appropriate and proportionate corrective measures without undue delay.
5. Step 5: Notifying significant incidents
Article 20(1) provides that essential and important entities immediately notify the national CSIRT of any incident that has a significant impact on the provision of their services, and that the national CSIRT in turn immediately notifies the CIP Department in writing; the mere act of notification does not subject the notifying entity to increased liability. Under article 20(5)(a) an early warning is submitted without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident, indicating where applicable whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact. Under article 20(5)(b) an incident notification follows without undue delay and in any event within seventy-two (72) hours of becoming aware of the significant incident, updating the earlier information and giving an initial assessment of severity and impact together with any available indicators of compromise. Article 20(5)(c) allows the national CSIRT to request an intermediate report, and article 20(5)(d) sets a final report not later than one (1) month after the submission of the incident notification, while article 20(5)(e) provides that where the incident is still ongoing at that point a progress report is given and a final report follows within one (1) month of the handling of the incident.
NIS2 incident reporting deadlines by EU country · The platform generates this document automatically — it is included in the document package. Services
6. Step 6: Written records the order presupposes
Article 19(2) frames much of the required content as policies and procedures, which presupposes written material covering risk analysis and information system security, the assessment of the effectiveness of the measures, cryptography, and human resources, insider risk and access control. Article 29(2)(e) to (j) empowers the CIP Department, or where designated the competent authority, to request from essential entities information on the risk-management measures adopted, including documented cybersecurity policies, access to data, documents and information, evidence of implementation such as security audit results with the underlying evidence, evidence of CSIRT monitoring services, and evidence of operator security plans, business continuity plans and where necessary termination plans, with article 30(2)(d) to (i) providing equivalent ex post powers in relation to important entities. Article 7(3)(d) refers to operator security plans and business continuity plans being drawn up and maintained, and article 19(1)(c) assigns their development, implementation, maintenance and review, together with risk assessments, to the security liaison officer. Article 7(4) and (5) require registration on the national self-registration mechanism with the listed contact and sector details, and notification of any change to those details without delay and in any event within two (2) weeks of the date of the change.
The package includes:
- Cybersecurity Risk Management Policy
- Incident Handling Plan
- Business Continuity Plan
- Supply Chain Security Policy
- Management Responsibility Statement and Training Framework
- Fill-in assistant in the portal
Maintenance (monthly) — document re-sign under the law in force — 290 EUR/month — Services
7. Step 7: The administrative penalty ceilings
Article 32(3) provides that essential entities which infringe articles 19 or 20 are subject to administrative penalties of a maximum of ten million euro (€10 000 000), or a maximum of two percent (2%) of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher. Article 32(4) sets the corresponding ceiling for important entities at a maximum of seven million euro (€7 000 000), or a maximum of one point four percent (1.4%) of that turnover, whichever is higher. Under article 33 the Enforcement Committee imposes these fines on entities reported as non-compliant, after allowing the entity to provide documentation or make submissions, and states in its decision the amount, the payment timeframe, the timeframe to remedy the breach and the reasons. Article 31(1) requires the preliminary findings of an infringement to be notified in writing beforehand, with a period not exceeding fifteen (15) working days for the entity to make submissions and propose remedies.
Frequently asked questions
Which authority supervises transport entities in Malta under S.L. 460.41?
Article 7(1) designates the CIP Department as the national supervisory authority monitoring implementation of the order and covering the sectors, subsectors and types of entities listed in the tables to the First and Second Schedules. In the First Schedule the competent authority column names the CIP Department as national supervisory authority for the air, water, road and public transport subsectors, while for the rail subsector it states that it is not applicable. Significant incidents are notified to the national CSIRT under article 20(1), which is established within the Malta Information Technology Agency under article 8(1).
What separates an essential entity from an important entity in the transport sector?
Under article 4(1)(a), an entity of a type indicated in the First Schedule, which includes the transport sector, is an essential entity where it exceeds the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC. Under article 4(2), entities of a type referred to in the First or Second Schedule that do not qualify as essential entities are important entities. Article 4(1)(e) and (f) also cover entities identified by the CIP Department or, where designated, the competent authority under articles 3(3)(b) to (e), and entities identified as critical entities under article 3(4).
Do the same security measures apply to a small transport operator and a large one?
Article 19 applies in the same terms to all essential and important entities, and its sub-article (2) sets the same minimum list for every entity in scope. Article 19(1)(b) provides that when assessing the proportionality of the measures, due consideration is given to the degree of the entity's exposure to risks, the entity's size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact. Supervision differs by class: article 29 sets out the supervisory and enforcement measures for essential entities, while article 30(1) provides for ex post supervisory measures in relation to important entities.
Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum dcb3533ca1c9).