NIS2 in Malta — S.L. 460.41, an asset-level register, and audits from 2027.
Malta transposed NIS2 through Legal Notice 71 of 2025 — the Measures for a High Common Level of Cybersecurity Across the European Union (Malta) Order, codified as Subsidiary Legislation 460.41. Published on 8 April 2025 and fully in force since 23 January 2026, it puts the Critical Infrastructure Protection (CIP) Department at the Ministry for Home Affairs in charge as competent authority and single point of contact, with CSIRTMalta as the national incident-response team and an Enforcement Committee deciding penalties.
Malta's register asks for more than a name and a sector. Entities submit contact details, IP ranges and a detailed inventory of computer, network and operational-technology resources — asset-level registration, unusual in the Union. The entity deadline is set administratively ("by the prescribed date" in the Order), so the practical duty is to be ready before the CIP Department prescribes it. Fines follow the directive ceilings — up to EUR 10 million or 2% of worldwide turnover for essential entities — plus daily penalties of EUR 100 per breach for persistent non-compliance. The first CIP Department audits are scheduled for the second half of 2027.
Who it applies to
Essential and important entities across the NIS2 sectors, including digital providers — DNS, cloud, data centers, online marketplaces, search engines, social platforms — regardless of size where the directive says so. Registration is on the CIP Department's national mechanism and requires asset-level detail: IP ranges and an inventory of IT and OT resources. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.
The clock
Competent authority: CIP Department (Ministry for Home Affairs). Transposition: Measures for a High Common Level of Cybersecurity (Malta) Order, 2025 — S.L. 460.41.
| When | What happens |
|---|---|
| 8 Apr 2025 | Legal Notice 71/2025 published |
| 30 Oct 2025 | CIP Department registration mechanism established |
| 23 Jan 2026 | S.L. 460.41 fully in force |
| H2 2027 | First CIP Department audits scheduled |
Registration at asset level — IP ranges and OT included
Most member states register an entity; Malta registers its estate. The CIP Department's mechanism requires IP address ranges and a detailed list of computer, network and operational-technology resources — which means the registration itself presupposes an asset inventory many organizations do not have. That single requirement changes the order of operations: you cannot file the Maltese registration as a paperwork exercise and build the inventory later, because the inventory is the filing. With first audits scheduled for the second half of 2027 and daily penalties for persistent breaches, the sequence matters. TruSecure's asset inventory is the registration input directly — the same records that feed the control library produce the IT and OT detail the CIP form asks for.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Malta transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with the CIP Department — IP ranges and IT/OT inventory included | Asset inventory · registration detail generated from live records |
| Implement the Article 19 risk-management measures | Control library · mapped, owned, evidenced |
| Report incidents per Article 20: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Survive the first CIP audit (from H2 2027) | Audit-ready evidence · sealed exports, no re-collection scramble |
| Avoid daily penalties for persistent breaches | Finding closure tracked · open items visible by age |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- CIP registration
- drafted · IP ranges + IT/OT inventory generated from live records
- Scope basis
- essential entity · digital infrastructure sector
- Controls evidenced
- 71/96 · Article 19 measures mapped
- Audit horizon
- H2 2027 · evidence sealing rehearsed
- Export
- sealed · sha256:1f6c...72aa
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your asset inventory producing the registration detail, the Article 19 measures mapped, and evidence sealed ahead of the 2027 audit window. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Malta by CIP Department (Ministry for Home Affairs). TruSecure determines applicability against Malta's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.