Malta

โ† All Member States
Transposed, commencement pending
NIS2 status
Transposed, commencement pending
National law
Measures for a High Common Level of Cybersecurity Order 2025 โ€” S.L. 460.41 (Legal Notice 71 of 2025, published 2025-04-08)
Competent authority
Critical Infrastructure Protection (CIP) Department, Ministry for Home Affairs
CSIRT
CSIRTMalta
Last verified
2026-07-16

Malta

๐ŸŸก NIS2 instrument published; ministerial commencement pending.

NIS2 transposition

  • National law: Measures for a High Common Level of Cybersecurity Order 2025 โ€” S.L. 460.41 (Legal Notice 71 of 2025, published 2025-04-08)
  • Status / entry into force: Instrument published; substantive provisions commence on dates set by the Minister via commencement notices โš ๏ธ VERIFY

Competent authority & CSIRT

  • Competent authority: Critical Infrastructure Protection (CIP) Department, Ministry for Home Affairs
  • CSIRT / incident response: CSIRTMalta
  • Registration: Per commencement notices

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to โ‚ฌ10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to โ‚ฌ7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. โš ๏ธ VERIFY national CER instrument.

Notes

Transposed via subsidiary legislation; phased commencement.

Sources