NIS2 Country Guide

NIS2 Malta: Compliance, Authorities & Key Requirements

Malta transposed NIS2 through S.L. 460.41 - the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, made by Legal Notice 71 of 2025 and amended by Legal Notice 89 of 2026. This page works from the consolidated text dated 23 January 2026: what the self-registration mechanism actually asks for, the qualified auditor you have to appoint, the Enforcement Committee that imposes the fines, and the EUR 100 per day penalty that can be backdated.

Malta S.L. 460.41 (LN 71 of 2025) Amended: LN 89 of 2026 Regulator: CIP Department Last updated: 13 August 2026

Introduction: NIS2 Directive & the Maltese context

The NIS2 Directive strengthens cybersecurity across the EU. Malta has transposed NIS2 via Legal Notice 71 of 2025 — Measures for a High Common Level of Cybersecurity Across the European Union (Malta) Order (S.L. 460.41), effective 8 April 2025. If you operate in Malta (or offer services there), assess whether you are an essential or important entity and prepare accordingly.

Quick link: Read our overview “What is NIS2?” and “NIS vs NIS2” for background before diving into Malta’s specifics.
The Order has been amended since it was made. Legal Notice 89 of 2026 rewrote it in around thirty places and deleted four articles outright. Everything on this page comes from the consolidated text dated 23 January 2026, not from the 2025 legal notice as originally published.
We print no registration deadline. A date of 30 October 2025 circulates for the Maltese register, including on earlier versions of guidance elsewhere. It appears nowhere in the Order, which requires the prescribed information to be submitted "by the prescribed date" and leaves that date to be set outside the instrument. We would rather state nothing than a deadline we cannot source.

NIS2 Directive implementation in Malta

Malta transposed NIS2 through Legal Notice 71 of 2025, which made S.L. 460.41 - the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order. The Order was subsequently amended by Legal Notice 89 of 2026, and the consolidated text in force carries the date 23 January 2026.

Status

Transposed and in force. Legislation Malta records the Order as fully in force.

Legal instrument

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Legal Notice 71 of 2025 as amended by Legal Notice 89 of 2026.

Registration

Article 7 requires the CIP Department to run a national self-registration mechanism and to maintain a register, reviewing and updating it regularly. See self-registration.

CategoryNotes
Essential sectorsEnergy, transport, banking & FMIs, health, drinking & wastewater, digital infrastructure, public administration.
Important sectorsPostal & courier, waste management, food, manufacturing, chemicals, digital providers, research.
Size criteriaThe Order applies the Commission Recommendation 2003/361/EC definitions rather than restating figures. Essential ≥250 employees or >€50m turnover (or >€43m balance sheet); important ≥50 employees or >€10m turnover.
Size-independent limbsArticle 3(3) brings entities in regardless of size where the entity is the sole provider of a service critical to societal or economic activity, where disruption could induce significant systemic risk, where it is critical at national level, or where it is a public administration entity — including a local government authority whose services, following a risk assessment, could be significantly disrupted.
Exclusions and overlapsBodies relating to national security, defence and law enforcement are excluded. The Order also stands down where sector-specific EU law imposes at least equivalent obligations — and expressly does not apply to entities exempted from the scope of DORA.

Compliance & certification

Malta follows NIS2’s two-tier model (Essential / Important) and applies EU size criteria in line with the directive.

Obligations

  • Risk management & security policy across IT/OT
  • Incident handling & reporting (24h early warning, 72h initial, 1-month final)
  • Business continuity & crisis management
  • Supply-chain security & vendor risk
  • Vulnerability disclosure (VDP) & secure development
  • Executive/board accountability & training

Standards & alignment

No single certification mandated. Alignment with ISO/IEC 27001:2023, NIST CSF 2.0, and relevant sector standards (e.g., IEC 62443) is recommended.

Evidence & audits

Maintain policies, risk registers, supplier due diligence, incident logs, and training records to demonstrate compliance during supervisory checks.

Note on evidence: in Malta this is not only good practice. Article 14 requires you to appoint a qualified auditor, from a list the CIP Department maintains, to verify that the risk-management measures are actually implemented — see the qualified auditor.

Self-registration & what you must declare

Article 7(1)(c) requires the CIP Department to establish a national self-registration mechanism — for essential and important entities, for entities providing domain name registration services, and, unusually, for CSIRTs providing monitoring services within those entities. Article 7(1)(d) requires it to maintain a register and update it regularly.

For DNS providers, TLD name registries, domain name registration services, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, online search engines and social networking platforms, Article 24(1) sets out exactly what must be submitted:

  • The name of the entity, and its sector, sub-sector and type under the First or Second Schedule.
  • The address of its main establishment and its other legal establishments in the Union, or of its representative if not established in the Union.
  • Up-to-date contact details, including email addresses and telephone numbers.
  • The Member States where it provides services.
  • The entity's IP ranges.
  • A detailed list of computer, network and operational technology resources used.
That last item is the most invasive registration requirement we have found in any transposition. Other member states ask for IP ranges; Malta asks for an asset inventory covering IT and OT. It is supplied on request rather than automatically, and — together with the IP ranges — it is the one category of information the CIP Department does not forward to ENISA.

Changes to any of the submitted information must be notified to the CIP Department without delay and in any event within three months of the change (Article 24(2)).

Management body duties & training

Article 18 defines the "management body" broadly — it includes the head of the entity and any other officers the head appoints for the purpose — and then places three duties on it.

  • Approve the cybersecurity risk-management measures under Article 19, and oversee their implementation.
  • The natural persons composing the management body may be held personally liable for the entity's infringements of Article 19, under Articles 31(10)(b) and 33.
  • Follow training in order to carry out those tasks (Article 18(3)) — and the entity must offer similar training to its employees on a regular basis (Article 18(4)).

Article 18(2) preserves the separate liability rules that apply to public institutions, public servants and elected or appointed officials — the duty applies, the consequences are governed elsewhere.

The qualified auditor

This is the obligation most likely to be missed, because it has no equivalent in most transpositions. Article 14: an essential or important entity shall appoint a qualified auditor to verify whether it has implemented the cybersecurity risk-management measures required by Article 19.

The list is the state's

The CIP Department maintains the list of qualified auditors and makes it available to essential and important entities. It also establishes the procedure by which an auditor is approved.

Who qualifies

A qualified auditor must hold a certification or cybersecurity standard determined by the CIP Department, and be experienced with the skillsets the Department determines.

How this differs

Lithuania requires an audit every three years and Croatia every two. Malta requires the appointment of an approved person — the obligation attaches to who verifies you, not only to how often.

Competent authorities & CSIRT

Supervision sits with the CIP Department, but the body that imposes the fines is a different one — a separation our earlier text did not carry. The Order also refers throughout to "the national CSIRT" rather than to a trading name.

RoleAuthorityNotes
Competent authority & single point of contactCritical Infrastructure Protection Department (CIP Department)Identifies and designates essential and important entities, runs the self-registration mechanism and register, supervises, and reports non-compliance to the Enforcement Committee. Referred to more than 180 times in the Order.
National CSIRTThe national CSIRTReceives significant-incident notifications under Article 20 and reports of incidents, cyber threats and near misses under Article 27, then informs the CIP Department in writing. The Order designates it by function, not by trading name.
Imposes the finesEnforcement CommitteeArticle 33: has the power to impose the administrative fines on any entity the CIP Department reports as non-compliant, after allowing that entity to submit documentation or make submissions. See the Enforcement Committee.
CooperationExecutive Police; Information and Data Protection CommissionerThe CIP Department, competent authorities and national CSIRT are required to cooperate with both.

Incident reporting & the liability shield

Article 20 runs the familiar chain — but it routes it through the national CSIRT rather than the regulator, and it opens with a sentence worth knowing before you ever need it.

"The mere act of notification shall not subject the notifying entity to an increased liability." Article 20(1) says so expressly. Reporting an incident cannot, of itself, be used against you — the clearest statutory reporting shield of any transposition on this site.
StageDeadlineContent
Early warning24 hours from becoming awareWhere applicable, whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border impact.
Incident notification72 hoursUpdates the early warning, with an initial assessment of severity and impact and, where available, indicators of compromise.
Intermediate reportOn the national CSIRT's requestRelevant status updates.
Final reportOne month after the incident notificationDetailed description, severity and impact, threat or root cause, mitigation measures applied, and cross-border impact.

Notifications go to the national CSIRT, which must then immediately notify the CIP Department in writing — and any other designated competent authority that regulates the affected service.

Two duties run to your customers rather than to the state. Article 20(2): where appropriate, notify the recipients of your services, without undue delay, of significant incidents likely to adversely affect the provision of those services. Article 20(4): where applicable, tell recipients potentially affected by a significant cyber threat what measures or remedies they can take — and, where appropriate, tell them about the threat itself.

CSIRT scanning, near misses & disclosure

  • The national CSIRT may scan you. Article 13(2) allows proactive, non-intrusive scanning of publicly accessible network and information systems to detect vulnerable or insecurely configured systems. It must not negatively affect your services, and you must be notified in writing that it is happening.
  • Near misses are reportable. Article 27 covers incidents, cyber threats and near misses — the voluntary channel Denmark, Lithuania and Estonia also provide.
  • Coordinated vulnerability disclosure. The CIP Department acts as a trusted intermediary, facilitating the interaction between the person reporting a vulnerability and the entity using the potentially vulnerable product, and must immediately notify the national CSIRT in writing of vulnerabilities reported to it.
  • Its technical work is expressly authorised. Where the CIP Department carries out the technical operations strictly necessary to characterise a risk or threat, it is deemed duly authorised under article 337C(2) of the Criminal Code — a carve-out from the computer misuse offences that most transpositions leave unaddressed.
  • Outsourced CSIRTs are recognised. The Order defines an "autonomous CSIRT" as an outsourced CSIRT providing monitoring services to essential or important entities — and requires those to register through the national self-registration mechanism too.

National NIS2 timeline & key dates

27 Dec 2022 — NIS2 published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline for Member States.
8 Apr 2025 — Malta’s Legal Notice 71/2025 enters into force.
23 Jan 2026 — Date carried by the consolidated text of S.L. 460.41 following Legal Notice 89 of 2026, which rewrote the Order in around thirty places and deleted four articles.
Every two years — The CIP Department notifies the European Commission and the Cooperation Group of the number of essential and important entities (Article 24(5)).
Rolling, per entity — Registration through the national self-registration mechanism, with changes notified within three months.

Sector-specific notes (Malta)

  • Public administration: most administrative bodies are covered; exclusions apply for defence, law enforcement, and national security bodies.
  • Digital infrastructure & providers: DNS, TLD, cloud, data centres, CDNs — typically in scope, often irrespective of size.
  • Finance: the Order does not apply to entities exempted from the scope of DORA, and stands down wherever sector-specific EU law imposes obligations at least equivalent in effect — including the supervision and enforcement provisions.
  • Local government: a local council can be brought in by name. Article 3(3)(f)(ii) covers a local government authority which, following a risk assessment, provides services whose disruption may have a significant impact.
  • Managed service and managed security service providers: squarely in the Article 24 declaration regime, which is where the IP ranges and the IT/OT asset list are demanded.

Penalties for non-compliance

The turnover-based ceilings are the ones everyone quotes. Two things about them are usually left out: what they attach to, and the daily penalty that applies while a breach continues.

  • Essential entities: up to €10,000,000 or 2% of total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher.
  • Important entities: up to €7,000,000 or 1.4%, whichever is higher.
  • Both apply only to infringements of Articles 19 or 20 — the risk-management measures and the reporting duty. Article 32(3) and (4) attach to nothing else.
  • Daily penalty payments of €100 per breach, for each day the breach persists, where an entity repeatedly fails to cease or rectify it after a prior decision. A daily penalty may be backdated to the date the breach was committed.
  • Public administration entities can be fined too — Article 32(5), as substituted by Legal Notice 89 of 2026, expressly allows administrative penalties against them.
  • Administrative penalties are imposed in addition to the enforcement measures, not instead of them.
Personal exposure. Article 18(1) provides that the natural persons composing the management body may be held liable for the entity's infringements of Article 19, and Article 33 gives the Enforcement Committee the power to act on that.

The Enforcement Committee

Malta separates the regulator from the body that punishes. The CIP Department supervises and reports; the Enforcement Committee decides and fines. Article 33 gives the Committee the power to impose the administrative fines on any entity the CIP Department reports as non-compliant.

You are heard first

Before deciding whether an entity is compliant, the Committee shall allow the entity to provide documentation or make submissions as it deems fit (Article 33(2)).

Who sits on it

Each competent authority other than the CIP Department may appoint one representative. The Director General responsible for the CIP Department chairs it, the Director is deputy chairperson, and a third officer of the Department acts as secretary.

The detail that matters

The chairperson, deputy chairperson and secretary have no voting rights. The votes belong to the representatives of the other competent authorities — so the Department that brings the case does not vote on it.

How Malta differs

  • You must declare an asset inventory. Article 24(1)(g) requires "a detailed list of computer, network and operational technology resources used" — beyond the IP ranges other member states ask for, and the most invasive registration field on this site.
  • You must appoint a qualified auditor from a state-maintained list (Article 14), not merely commission an audit on a cycle.
  • The regulator does not impose the fine. The Enforcement Committee does — and the CIP Department members who chair it cannot vote.
  • The daily penalty can be backdated to the date the breach was committed, at €100 per breach per day.
  • Reporting is expressly shielded — the mere act of notification cannot increase your liability.
  • Outsourced "autonomous CSIRTs" are recognised and must self-register, which no other transposition on this site contemplates.
What we deliberately do not state. We print no entity count and no registration deadline. Article 24(1) requires submission "by the prescribed date" and leaves that date outside the instrument, so any specific date circulating for the Maltese register cannot be sourced to the Order.

How to prepare for NIS2 in Malta

  1. Determine scope: confirm Annex I/II services and size thresholds; classify EE/IE.
  2. Prepare your declaration, including the asset list: Article 24 asks for your IP ranges and a detailed list of the computer, network and operational technology resources you use. Build that inventory before you are asked for it — it is supplied on request, and it is the hardest item to produce at short notice.
  3. Appoint a qualified auditor: Article 14 requires one, and the CIP Department maintains the list to choose from and sets the approval procedure.
  4. Governance: secure board-level accountability and budget for cybersecurity.
  5. Risk management: map and implement controls aligned to Article 21 (IT/OT, VDP, BC/DR).
  6. Supply chain: assess MSPs/MSSPs and critical suppliers; add contractual security requirements.
  7. Incident readiness: build the 24h / 72h / one-month workflow to the national CSIRT, and include the two customer-facing duties — notifying the recipients of your services of significant incidents, and telling them what they can do about a significant cyber threat.
  8. Train & evidence: leadership training, staff awareness, and auditable records.

Official links & resources

Critical Infrastructure Protection Department — competent authority: designation, the national self-registration mechanism, the register, supervision and the list of qualified auditors.
The national CSIRT — receives significant-incident notifications under Article 20 and reports of incidents, cyber threats and near misses under Article 27.

FAQ: NIS2 in Malta

Which instrument transposes NIS2 in Malta?
S.L. 460.41, the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, made by Legal Notice 71 of 2025 and amended by Legal Notice 89 of 2026. The consolidated text carries the date 23 January 2026.
Who do I register with, and by when?
With the CIP Department, through the national self-registration mechanism it is required to establish under Article 7. We print no deadline: Article 24(1) requires submission "by the prescribed date" and leaves that date outside the Order, so any specific date circulating for the Maltese register cannot be sourced to the instrument.
What exactly do we have to declare?
Name, sector and type; the address of your main establishment and other EU establishments; contact details; the Member States you serve; your IP ranges; and a detailed list of the computer, network and operational technology resources you use. Changes must be notified within three months.
Who actually imposes the fine?
The Enforcement Committee, not the CIP Department. The Department reports non-compliance; the Committee decides, after allowing the entity to provide documentation or make submissions. Its chairperson, deputy chairperson and secretary — all CIP Department officers — have no voting rights.
Does NIS2 apply regardless of size?
General size thresholds apply (≥50 employees or ≥€10m), but some providers (e.g., DNS/TLD, trust services) may be covered regardless of size.
Is a specific certification required?
No. Alignment with ISO/IEC 27001:2023, NIST CSF 2.0, and sector standards is recommended.
What are the fines?
Essential entities: up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher. Important entities: €7,000,000 or 1.4%. Both apply only to infringements of Articles 19 or 20. Separately, a daily penalty of €100 per breach per day applies while a breach persists after a prior decision, and it can be backdated to the date the breach was committed.
Information provided for general guidance and verified against the consolidated text of S.L. 460.41 (Legal Notice 71 of 2025 as amended by Legal Notice 89 of 2026); always consult the Order, CIP Department publications and legal counsel for definitive NIS2 compliance requirements.