NIS2 Malta: Compliance, Authorities & Key Requirements
Malta transposed NIS2 through S.L. 460.41 - the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, made by Legal Notice 71 of 2025 and amended by Legal Notice 89 of 2026. This page works from the consolidated text dated 23 January 2026: what the self-registration mechanism actually asks for, the qualified auditor you have to appoint, the Enforcement Committee that imposes the fines, and the EUR 100 per day penalty that can be backdated.
Introduction: NIS2 Directive & the Maltese context
The NIS2 Directive strengthens cybersecurity across the EU. Malta has transposed NIS2 via Legal Notice 71 of 2025 — Measures for a High Common Level of Cybersecurity Across the European Union (Malta) Order (S.L. 460.41), effective 8 April 2025. If you operate in Malta (or offer services there), assess whether you are an essential or important entity and prepare accordingly.
NIS2 Directive implementation in Malta
Malta transposed NIS2 through Legal Notice 71 of 2025, which made S.L. 460.41 - the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order. The Order was subsequently amended by Legal Notice 89 of 2026, and the consolidated text in force carries the date 23 January 2026.
Status
Transposed and in force. Legislation Malta records the Order as fully in force.
Legal instrument
S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Legal Notice 71 of 2025 as amended by Legal Notice 89 of 2026.
Registration
Article 7 requires the CIP Department to run a national self-registration mechanism and to maintain a register, reviewing and updating it regularly. See self-registration.
| Category | Notes |
|---|---|
| Essential sectors | Energy, transport, banking & FMIs, health, drinking & wastewater, digital infrastructure, public administration. |
| Important sectors | Postal & courier, waste management, food, manufacturing, chemicals, digital providers, research. |
| Size criteria | The Order applies the Commission Recommendation 2003/361/EC definitions rather than restating figures. Essential ≥250 employees or >€50m turnover (or >€43m balance sheet); important ≥50 employees or >€10m turnover. |
| Size-independent limbs | Article 3(3) brings entities in regardless of size where the entity is the sole provider of a service critical to societal or economic activity, where disruption could induce significant systemic risk, where it is critical at national level, or where it is a public administration entity — including a local government authority whose services, following a risk assessment, could be significantly disrupted. |
| Exclusions and overlaps | Bodies relating to national security, defence and law enforcement are excluded. The Order also stands down where sector-specific EU law imposes at least equivalent obligations — and expressly does not apply to entities exempted from the scope of DORA. |
Compliance & certification
Malta follows NIS2’s two-tier model (Essential / Important) and applies EU size criteria in line with the directive.
Obligations
- Risk management & security policy across IT/OT
- Incident handling & reporting (24h early warning, 72h initial, 1-month final)
- Business continuity & crisis management
- Supply-chain security & vendor risk
- Vulnerability disclosure (VDP) & secure development
- Executive/board accountability & training
Standards & alignment
No single certification mandated. Alignment with ISO/IEC 27001:2023, NIST CSF 2.0, and relevant sector standards (e.g., IEC 62443) is recommended.
Evidence & audits
Maintain policies, risk registers, supplier due diligence, incident logs, and training records to demonstrate compliance during supervisory checks.
Self-registration & what you must declare
Article 7(1)(c) requires the CIP Department to establish a national self-registration mechanism — for essential and important entities, for entities providing domain name registration services, and, unusually, for CSIRTs providing monitoring services within those entities. Article 7(1)(d) requires it to maintain a register and update it regularly.
For DNS providers, TLD name registries, domain name registration services, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, online search engines and social networking platforms, Article 24(1) sets out exactly what must be submitted:
- The name of the entity, and its sector, sub-sector and type under the First or Second Schedule.
- The address of its main establishment and its other legal establishments in the Union, or of its representative if not established in the Union.
- Up-to-date contact details, including email addresses and telephone numbers.
- The Member States where it provides services.
- The entity's IP ranges.
- A detailed list of computer, network and operational technology resources used.
Changes to any of the submitted information must be notified to the CIP Department without delay and in any event within three months of the change (Article 24(2)).
Management body duties & training
Article 18 defines the "management body" broadly — it includes the head of the entity and any other officers the head appoints for the purpose — and then places three duties on it.
- Approve the cybersecurity risk-management measures under Article 19, and oversee their implementation.
- The natural persons composing the management body may be held personally liable for the entity's infringements of Article 19, under Articles 31(10)(b) and 33.
- Follow training in order to carry out those tasks (Article 18(3)) — and the entity must offer similar training to its employees on a regular basis (Article 18(4)).
Article 18(2) preserves the separate liability rules that apply to public institutions, public servants and elected or appointed officials — the duty applies, the consequences are governed elsewhere.
The qualified auditor
This is the obligation most likely to be missed, because it has no equivalent in most transpositions. Article 14: an essential or important entity shall appoint a qualified auditor to verify whether it has implemented the cybersecurity risk-management measures required by Article 19.
The list is the state's
The CIP Department maintains the list of qualified auditors and makes it available to essential and important entities. It also establishes the procedure by which an auditor is approved.
Who qualifies
A qualified auditor must hold a certification or cybersecurity standard determined by the CIP Department, and be experienced with the skillsets the Department determines.
How this differs
Lithuania requires an audit every three years and Croatia every two. Malta requires the appointment of an approved person — the obligation attaches to who verifies you, not only to how often.
Incident reporting & the liability shield
Article 20 runs the familiar chain — but it routes it through the national CSIRT rather than the regulator, and it opens with a sentence worth knowing before you ever need it.
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours from becoming aware | Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border impact. |
| Incident notification | 72 hours | Updates the early warning, with an initial assessment of severity and impact and, where available, indicators of compromise. |
| Intermediate report | On the national CSIRT's request | Relevant status updates. |
| Final report | One month after the incident notification | Detailed description, severity and impact, threat or root cause, mitigation measures applied, and cross-border impact. |
Notifications go to the national CSIRT, which must then immediately notify the CIP Department in writing — and any other designated competent authority that regulates the affected service.
Two duties run to your customers rather than to the state. Article 20(2): where appropriate, notify the recipients of your services, without undue delay, of significant incidents likely to adversely affect the provision of those services. Article 20(4): where applicable, tell recipients potentially affected by a significant cyber threat what measures or remedies they can take — and, where appropriate, tell them about the threat itself.
CSIRT scanning, near misses & disclosure
- The national CSIRT may scan you. Article 13(2) allows proactive, non-intrusive scanning of publicly accessible network and information systems to detect vulnerable or insecurely configured systems. It must not negatively affect your services, and you must be notified in writing that it is happening.
- Near misses are reportable. Article 27 covers incidents, cyber threats and near misses — the voluntary channel Denmark, Lithuania and Estonia also provide.
- Coordinated vulnerability disclosure. The CIP Department acts as a trusted intermediary, facilitating the interaction between the person reporting a vulnerability and the entity using the potentially vulnerable product, and must immediately notify the national CSIRT in writing of vulnerabilities reported to it.
- Its technical work is expressly authorised. Where the CIP Department carries out the technical operations strictly necessary to characterise a risk or threat, it is deemed duly authorised under article 337C(2) of the Criminal Code — a carve-out from the computer misuse offences that most transpositions leave unaddressed.
- Outsourced CSIRTs are recognised. The Order defines an "autonomous CSIRT" as an outsourced CSIRT providing monitoring services to essential or important entities — and requires those to register through the national self-registration mechanism too.
National NIS2 timeline & key dates
Sector-specific notes (Malta)
- Public administration: most administrative bodies are covered; exclusions apply for defence, law enforcement, and national security bodies.
- Digital infrastructure & providers: DNS, TLD, cloud, data centres, CDNs — typically in scope, often irrespective of size.
- Finance: the Order does not apply to entities exempted from the scope of DORA, and stands down wherever sector-specific EU law imposes obligations at least equivalent in effect — including the supervision and enforcement provisions.
- Local government: a local council can be brought in by name. Article 3(3)(f)(ii) covers a local government authority which, following a risk assessment, provides services whose disruption may have a significant impact.
- Managed service and managed security service providers: squarely in the Article 24 declaration regime, which is where the IP ranges and the IT/OT asset list are demanded.
Penalties for non-compliance
The turnover-based ceilings are the ones everyone quotes. Two things about them are usually left out: what they attach to, and the daily penalty that applies while a breach continues.
- Essential entities: up to €10,000,000 or 2% of total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher.
- Important entities: up to €7,000,000 or 1.4%, whichever is higher.
- Both apply only to infringements of Articles 19 or 20 — the risk-management measures and the reporting duty. Article 32(3) and (4) attach to nothing else.
- Daily penalty payments of €100 per breach, for each day the breach persists, where an entity repeatedly fails to cease or rectify it after a prior decision. A daily penalty may be backdated to the date the breach was committed.
- Public administration entities can be fined too — Article 32(5), as substituted by Legal Notice 89 of 2026, expressly allows administrative penalties against them.
- Administrative penalties are imposed in addition to the enforcement measures, not instead of them.
The Enforcement Committee
Malta separates the regulator from the body that punishes. The CIP Department supervises and reports; the Enforcement Committee decides and fines. Article 33 gives the Committee the power to impose the administrative fines on any entity the CIP Department reports as non-compliant.
You are heard first
Before deciding whether an entity is compliant, the Committee shall allow the entity to provide documentation or make submissions as it deems fit (Article 33(2)).
Who sits on it
Each competent authority other than the CIP Department may appoint one representative. The Director General responsible for the CIP Department chairs it, the Director is deputy chairperson, and a third officer of the Department acts as secretary.
The detail that matters
The chairperson, deputy chairperson and secretary have no voting rights. The votes belong to the representatives of the other competent authorities — so the Department that brings the case does not vote on it.
How Malta differs
- You must declare an asset inventory. Article 24(1)(g) requires "a detailed list of computer, network and operational technology resources used" — beyond the IP ranges other member states ask for, and the most invasive registration field on this site.
- You must appoint a qualified auditor from a state-maintained list (Article 14), not merely commission an audit on a cycle.
- The regulator does not impose the fine. The Enforcement Committee does — and the CIP Department members who chair it cannot vote.
- The daily penalty can be backdated to the date the breach was committed, at €100 per breach per day.
- Reporting is expressly shielded — the mere act of notification cannot increase your liability.
- Outsourced "autonomous CSIRTs" are recognised and must self-register, which no other transposition on this site contemplates.
How to prepare for NIS2 in Malta
- Determine scope: confirm Annex I/II services and size thresholds; classify EE/IE.
- Prepare your declaration, including the asset list: Article 24 asks for your IP ranges and a detailed list of the computer, network and operational technology resources you use. Build that inventory before you are asked for it — it is supplied on request, and it is the hardest item to produce at short notice.
- Appoint a qualified auditor: Article 14 requires one, and the CIP Department maintains the list to choose from and sets the approval procedure.
- Governance: secure board-level accountability and budget for cybersecurity.
- Risk management: map and implement controls aligned to Article 21 (IT/OT, VDP, BC/DR).
- Supply chain: assess MSPs/MSSPs and critical suppliers; add contractual security requirements.
- Incident readiness: build the 24h / 72h / one-month workflow to the national CSIRT, and include the two customer-facing duties — notifying the recipients of your services of significant incidents, and telling them what they can do about a significant cyber threat.
- Train & evidence: leadership training, staff awareness, and auditable records.
