The NIS2 Directive, the European Union’s second Network and Information Security directive (formally Directive (EU) 2022/2555), has now landed properly in Maltese law. Malta transposed it through Legal Notice 71 of 2025, creating Subsidiary Legislation 460.41, and updated the framework again with Legal Notice 89 of 2026. This came after the original EU transposition deadline of 17 October 2024, which Malta, along with a good number of other member states, did not meet.
For larger operators with compliance teams, this is already in hand. For the small and medium-sized businesses that make up most of our local scene, the questions are more basic and more urgent: does this actually apply to us, and if it does, what are we expected to do about it. It is worth spending some time with both, because the answer to the first question surprises people, and the answer to the second is more manageable than the length of the directive suggests.
Are you in scope?
Two tests decide it: sector and size. NIS2 applies to organisations operating in the sectors listed in the directive’s annexes, and only once they reach a size threshold. That threshold follows the standard EU definition: fifty or more employees, or an annual turnover above ten million euro. A genuinely small business under both of those figures is, in most cases, outside the scope of the obligations.
The part that catches people is the sector list. It is broader than the old NIS1. It now covers digital infrastructure, ICT service management, managed service providers, postal and courier services, waste management, food production and distribution, and more, on top of the traditional essential services like energy, water, transport and health. If you are a medium-sized managed service provider or a digital infrastructure operator serving clients in Malta, you may well be in scope whether or not you thought of yourself as critical infrastructure.
The directive also splits organisations into two categories. Essential entities are the larger operators in the most critical sectors, and they face proactive supervision. Important entities, which is where most in-scope medium-sized businesses land, face a lighter, mainly after-the-fact supervisory regime. The obligations are broadly similar; the intensity of oversight and the timing of it differ.
What you are actually expected to do
Stripped of the legal language, the requirements come down to four practical areas.
Register with the authority. Malta designated the Critical Infrastructure Protection Department as the national single point of contact and supervisory authority, with the Malta Communications Authority acting as the competent authority for digital infrastructure and postal and courier services. Sector regulators, including the Malta Gaming Authority and the Malta Financial Services Authority, retain powers within their own sectors. In-scope entities are expected to identify themselves to the relevant authority rather than wait to be found.
Put risk-management measures in place. The directive sets out an all-hazards baseline: risk analysis and security policies, incident handling, business continuity and backups, supply-chain security, security in procurement and development, policies to assess whether the measures work, basic cyber-hygiene practices and staff training, cryptography where appropriate, and access control including multi-factor authentication. None of this is exotic. Most of it is the same list a competent security programme would have anyway; NIS2 simply makes it a legal expectation rather than a good idea.
Be ready to report incidents on the clock. For a significant incident, the reporting timeline is specific. An early warning goes to the national CSIRT or competent authority within twenty-four hours, a fuller notification within seventy-two hours, and a final report within one month. The practical implication is that the reporting workflow has to exist before the incident, not be improvised during one. Knowing who sends the early warning, and to which address, at two in the morning is the part worth rehearsing.
Get management to own it. This is the shift most organisations underestimate. NIS2 makes senior management responsible for approving and overseeing the risk-management measures, and it allows for management to be held liable for failures. It is deliberately not framed as an IT department problem. Board-level or director-level sign-off is part of the compliance, not an optional extra.
Where local businesses actually are
From what we have been hearing across the community, the picture is mixed. Firms with existing compliance functions are folding NIS2 into work they were already doing for GDPR and other obligations. Smaller operators are still at the earlier stage of working out whether they are in scope at all, which is understandable given how much the sector list expanded.
If you suspect you might be caught by this, a sensible starting sequence is: confirm your sector and size classification honestly, name a person who is accountable, write the incident-reporting workflow down before you need it, and begin with the cyber-hygiene basics that the risk-management article requires in any case, multi-factor authentication, tested backups, a patching routine, and staff awareness. The European Commission’s NIS2 overview is a reasonable place to orient yourself, and Maltese law firms have published readable summaries of the local Legal Notices for the specifics.
It is worth noting that this is not a one-off exercise. Supervision and enforcement ramp up over time, and the fact that Malta already amended the framework in 2026 with Legal Notice 89 is a fair signal that it will keep moving. For our community, the honest advice is the unglamorous kind: if there is a reasonable chance you are in scope, it is better to work that out yourselves now than to establish it for the first time in the twenty-four hours after a significant incident.