Check in 60 seconds whether NIS2 applies to you
NIS2 compliance in Malta — clarity in three minutes
NIS2 documents for 23 countries — based on each country's own law
Start the test — enter your details
The result with reasoning is shown immediately after answering. We use your details only for providing the NIS2 service.
Ask the NIS2 assistant A free expert assistant answers your questions about the Directive and S.L. 460.41.
Take the free gap assessment 20 questions on the Article 21(2) measures — see instantly where the gaps are.
Free surface scan — your domain's security picture in one minute
View sample Free sample package before you decide
Straight from the law
4. (1) For the purposes of this order, the following entities shall be considered to be essential entities: (a) entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of the Annex to the Commission Recommendation 2003/361/EC; (b) qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size; (c) providers of public electronic communications networks or of publicly available electronic communications services which qualify as medium-sized enterprises in accordance with Article 2 of the Annex to the Commissioner Recommendation 2003/361/EC; (d) public administration entities mentioned in article 3(3)(f)(i); (e) any other entity of a type referred to in the First or Second Schedule that are identified by the CIP Department or where designated the competent authority as an essential entity pursuant to articles 3(3)(b) to (e); (f) entities identified as critical entities under the Resilience of Critical Entities and Infrastructures (Identification, Designation and Protection) Order in article 3(4); (g) entities which the CIP Department or where designated the competent authority identified before 16 January 2023 as operators of essential services in conformity with: (i) Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive); or (ii) national law. (2) For the purposes of this order, entities of a type referred to in the First or Second Schedule which do not qualify as essential entities pursuant to sub-article (1) shall be considered to be important entities. This includes entities identified by the CIP Department or where designated the competent authority as important entities pursuant to articles 3(3)(b) to (e). PART II – ENFORCEMENT COMMITTEE, CRITICAL INFRASTRUCTURE PROTECTION DEPARTMENT AND CSIRTs
S.L. 460.41 article 4
The text is from the country's official, enacted law — verbatim, not paraphrased.
What is NIS2 and who does it affect in Malta?
NIS2 is the European Union cybersecurity directive (EU) 2022/2555, transposed in Malta by the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41). It significantly widens the scope of obligations: energy, transport, healthcare, digital infrastructure, manufacturing, food industry and many other sectors must implement risk management measures and report incidents to the Critical Infrastructure Protection Department (CIP Department) (Critical Infrastructure Protection Department).
The deadlines are strict: a significant incident requires an early warning within 24 hours, a full notification within 72 hours and a final report within one month. Non-compliance can cost an essential entity up to 10 million euros or 2% of worldwide turnover, and an important entity up to 7 million euros or 1.4%.
Our portal turns NIS2 requirements into practice: the free scoping test shows whether NIS2 applies to your company, and the document package is generated automatically, grounded in the officially applicable law text for your country. Start with the test — it takes three minutes.
The complete NIS2 guide — Malta →
NIS2 transposition status by EU country →
NIS2 incident reporting deadlines by EU country →
NIS2 risk-management measures vs ISO 27001, DORA and GDPR →
NIS2 administrative fines by country →
NIS2 management body training obligation by country →
The results are an indicative assessment, not legal advice. Your company remains responsible for the final content of any document.