Skip to main content
In forceNIS2

NIS2 in Malta

Malta transposed NIS2 via the NIS 2 Ordinance (Legal Notice 71 of 2025), in force since 8 April 2025. MITA regulates network defence and guides organisations through self-registration.

Transposition law
NIS 2 Ordinance (Legal Notice 71 of 2025)
In force since
8 April 2025
Competent authority
Malta Information Technology Agency (MITA) / CSIRT-MT
Max fine (Essential)
€10 million or 2% of global annual turnover
Max fine (Important)
€7 million or 1.4% of global annual turnover
Law adopted
8 April 2025

Key Deadlines

Law in force
17 October 2024

Competent Authority

Malta Information Technology Agency (MITA) / CSIRT-MT
National competent authority and operational cybersecurity lead
https://mita.gov.mt

MITA operates a centralized approach, hosting information sessions, defining cybersecurity baselines, and maintaining the secure register.

Registration Process

Fill in company credentials via the secure registration form at mita.gov.mt.

📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

Key Requirements

  • 1Register with MITA via digital portal interfaces
  • 2Acknowledge strict supplier auditing parameters
  • 324-hour warning message for major anomalies

National Additions

Malta adds tailored guidelines for online gaming support infrastructure and maritime service systems

FAQ: NIS2 in Malta

What is CSIRT-MT?
It is Malta's national computer security incident response team coordinating all network incident notifications.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.