Does NIS2 Apply to Your Company in Malta? A Plain Guide to the Platform and the Maltese Order
What the platform is
NIS2Europe is an online platform that produces cybersecurity documentation for a company: policies, registers, procedures and evidence lists of the kind a company needs when it has to show how it manages the risks to its network and information systems.
The documents are not blank templates. They are written from the profile the company itself fills in — its sector, its size, its role in the supply chain — and every statement of law inside them is checked against the text of the national act that applies in Malta, the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41).
That matters because the Maltese Order does not simply repeat the directive. It sets out its own articles, its own Schedules of sectors, and its own supervisory arrangements. A document that quotes only Directive (EU) 2022/2555 says less to a Maltese supervisor than one that points to the article of the Order that actually binds the company.
The subject matter of the documents follows article 19(2) of the Order, which lists the minimum content of cybersecurity risk-management measures — among them policies on risk analysis and information system security, incident handling, business continuity, supply chain security, cryptography, access control and asset management, and logging and traceability of network and information systems.
Who it is for under Maltese law
Article 4 of S.L. 460.41 divides organisations into two statutory categories.
An essential entity is, among others, an entity of a type indicated in the First Schedule which exceeds the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of the Annex to Commission Recommendation 2003/361/EC; qualified trust service providers, top-level domain name registries and DNS service providers regardless of their size; providers of public electronic communications networks or of publicly available electronic communications services that qualify as medium-sized enterprises; and entities designated by the CIP Department under articles 3(3)(b) to (e).
The second category is defined by exclusion:
> "For the purposes of this order, entities of a type referred to in the First or Second Schedule which do not qualify as essential entities pursuant to sub-article (1) shall be considered to be important entities." > — S.L. 460.41, article 4(2)
The First Schedule covers sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. The Second Schedule covers postal and courier services, waste management, chemicals, food, several branches of manufacturing, digital providers such as online marketplaces, online search engines and social networking services platforms, and research organisations.
There is a third group of readers. Article 19(2)(d) of the Order makes supply chain security — including security-related aspects of the relationship between an entity and its direct suppliers and service providers — a mandatory measure, and article 19(3) requires entities to take into account the vulnerabilities specific to each direct supplier. So a small firm that is not itself in scope may still be asked by a customer for written security evidence. Documentation is the practical answer to that request.
How it works: four steps
1. The company fills in its profile. Sector and sub-sector as they appear in the First or Second Schedule, size against the Recommendation 2003/361/EC ceilings, and the role the company plays — operator, service provider, or supplier to an in-scope customer.
2. The document is generated from that profile. The structure, the chapters and the examples follow the profile, so a data centre service provider and a food business engaged in wholesale distribution do not receive the same text.
3. A three-stage check runs. The draft is compared, statement by statement, against the statutory text of S.L. 460.41. Any sentence that asserts a legal duty the Order does not support is corrected or removed, and references are aligned to the article and sub-article actually cited.
4. The company downloads the finished document. It is the company's own document, to be approved internally — article 18(1) requires management bodies of essential and important entities to approve the cybersecurity risk-management measures and oversee their implementation.
Development in numbers
Development is continuous, not uninterrupted: when a national law changes, the templates are updated without a new order, and a maintenance client receives the updated document automatically.
- Platform development: 4496 changes since 06.06.2026
- Changes in the last 7 days: 1092
- Last change: 10.09.2026 23:09 (Europe/Tallinn)
- Tests: 641 green / 0 red
- Quality gate, latest run: 5/5 first pass
- Countries covered: 24
What it can and cannot do
What it delivers. Documents and evidence lists that a supervisor, an auditor or a procuring customer can read side by side with the law. Article 29(2) allows the CIP Department to make requests for information necessary to assess the cybersecurity risk-management measures adopted, including documented cybersecurity policies, requests to access data, documents and information, and requests for evidence of implementation of cybersecurity policies. Article 30(2) sets out comparable ex post powers for important entities. Written documentation is exactly the material those powers call for.
What it is not. The platform is not an audit and not a certificate.
- An audit — including the targeted security audits mentioned in articles 29(2)(b) and 30(2)(b) — is carried out by an independent body, the CIP Department or the designated competent authority.
- A certificate under a European cybersecurity certification scheme is issued by a conformity assessment body, not by a document generator.
The platform never replaces either of them, and producing a document does not by itself settle whether the measures behind it satisfy article 19. It prepares the paperwork; the substance remains the company's responsibility.
The competent authority in Malta
The Order names the supervisor directly:
> "The CIP Department shall be the national supervisory authority responsible for monitoring the implementation of this order at national level and ensuring compliance therewith" > — S.L. 460.41, article 7(1)
The Critical Infrastructure Protection Department (CIP Department) establishes the criteria for identifying and designating essential and important entities, operates the national self-registration mechanism, maintains the register, monitors risk-management measures under article 19 and reporting obligations under article 20, and exercises the supervisory and enforcement powers of articles 29 and 30. It also acts as single point of contact and as coordinator for coordinated vulnerability disclosure under article 13.
The First and Second Schedules designate the competent authority for each sector. For most sectors this is the CIP Department as national supervisory authority; for digital infrastructure, postal and courier services and digital providers, the Schedules name the Malta Communications Authority (MCA).
For practical details the Order does not spell out — the exact electronic notification or registration channel, for instance — please confirm against the published guidance of the Critical Infrastructure Protection Department (official source).
How to use and pay
Does NIS2 apply to your company? Free check
Answer two questions — the result is immediate, without registration.
Prices
€19 — one-time payment. The same price in every country.
- BASIC: 1 890 EUR
- RECOMMENDED: 2 490 EUR
After payment the document is generated from your profile, passes the check and is available for download — the document is delivered right after payment. The order is final: digital legal content carries no right of withdrawal.
API
The API is for software vendors, consultancies and IT service providers that serve many companies at once.
One API key in the X-API-Key header. A free sandbox key immediately on signup — no payment needed to start.
- NIS2 document package (5 documents): 1 890 EUR
- NIS2 technical security check — external attack-surface check + report: 290 EUR
- Supply-chain attestation (NIS2 Art. 21(2)(d)): 2 190 EUR
- Re-sign — document update to the current legal baseline: 490 EUR
- Combo — document package + technical security check + 12 months of maintenance: 2 490 EUR
- Maintenance (monthly) — document re-sign under the law in force: 290 EUR/month
- Maintenance (12 months prepaid) — document re-sign under the law in force: 2 900 EUR/year
- NIS2 ↔ ISO 27001 / DORA / GDPR mapping document: 390 EUR
- Incident-notification template pack (24 h / 72 h / 1 month): 390 EUR
- Single document from the package: 890 EUR
- API licence Professional: 990 EUR/month
- API licence Enterprise (SLA, multiple keys, priority queue): 2 900 EUR/month
Frequently asked questions
Our company is in a Second Schedule sector but well below the medium-sized ceilings. Are we outside the Order entirely?
Not automatically. Article 4(1) also allows the CIP Department, or where designated the competent authority, to identify entities of a type referred to in the First or Second Schedule as essential entities pursuant to articles 3(3)(b) to (e), and article 4(2) states that entities of those Schedule types which do not qualify as essential entities are considered to be important entities. Size is one factor among several, and some categories — qualified trust service providers, top-level domain name registries and DNS service providers — fall in regardless of their size. Confirm your position against the Schedules and the published guidance of the Critical Infrastructure Protection Department.
We are established outside Malta but sell into the Maltese market. Does S.L. 460.41 reach us?
Article 23(1) provides that entities falling within the scope of the Order fall under the jurisdiction of Malta if they are established in Malta, with exceptions. Providers of publicly available electronic communications services fall under the jurisdiction of the Member State where they provide their services. Cloud, data centre, content delivery network, managed service and managed security service providers, online marketplaces, online search engines and social networking services platforms fall under the jurisdiction of the Member State of their main establishment in the Union, determined under article 23(2). An entity in that group that is not established in the Union but offers services within it must designate a representative under article 23(3).
Can the platform tell us whether our security measures are good enough?
No. It produces documentation and evidence lists built from your profile and checked against the wording of S.L. 460.41. Whether the measures themselves are appropriate and proportionate is judged under article 19(1) by reference to your exposure to risk, your size and the likelihood and severity of incidents — and it is assessed by the CIP Department or the designated competent authority through the supervisory measures in articles 29 and 30, not by a document.
Do we still need an independent auditor if we use the platform?
The platform does not perform audits and does not issue certificates. Articles 29(2)(b) and 30(2)(b) refer to targeted security audits carried out by an independent body, the CIP Department or the designated competent authority, and article 29(2)(g) refers to requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence. Those roles belong to auditors and conformity assessment bodies; the documentation supports them rather than substituting for them.
AIPOS OÜ · Registry code 16966532 · Pargi tn 1, Kabala küla, Türi vald, 72001 Järva maakond, Estonia · info@nis2europe.eu
Services · Prices · Frequently asked questions · How NIS2Europe generates and validates your documents · Terms of purchase · Privacy