Critical Sectors

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Critical Sectors

The protection of critical sectors is an integral part of many cyber and information security strategies. Cybersecurity covers a broad spectrum of ICT-related security issues, of which the protection of critical sectors is an essential part. National strategies should include objectives and priorities related to the protection of critical sectors in particular those referred to Annexes I and II of the NIS2 Directive. In addition, as part of their national strategy, Member States shall also adopt specific policies, related to sustaining the general availability, integrity and confidentiality of the critical sectors including, the public core of the internet and where relevant, the cybersecurity of undersea communications cables.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Malta flag
Malta

Malta transposed the NIS2 Directive into national legislation with Legal Notice 71 of 2025, known as the Measures for a High Common Level of Cybersecurity Across the European Union (Malta) Order (Subsidiary Legislation 460.41). https://legislation.mt/eli/sl/460.41/eng

Attachments:
Related objective Protect Critical Sectors

Malta has transposed the CER Directive into its national legislation through a new legal instrument titled the Resilience of Critical Entities and Infrastructures (Identification, Designation and Protection) Order, 2026. The Order was first published on 16 January 2026 as L.N. 5 of 2026. The text of the Order has been formally brought into force as Subsidiary Legislation 460.43. The Order’s provisions are fully in force from 23 January 2026, following the publication of Legal Notice 23 of 2026 (Commencement Notice). This means Malta’s CER framework, which identifies, designates and protects critical entities and infrastructures, is now officially effective and enforceable.  https://legislation.mt/eli/ln/2026/5/eng

Attachments:
Related objective Protect Critical Sectors

Malta published Legal Notice 166 of 2024 titled “Malta Financial Services Authority Act (Digital Operational Resilience Act (DORA)) Regulations, 2024” under the Malta Financial Services Authority Act (Cap. 330). This legal notice locally implements the key provisions of the DORA Regulation and designates the MFSA as the competent supervisory authority for DORA-related compliance. These Malta DORA Regulations came into force on 17 January 2025, matching the Regulation’s EU-wide applicability date. They largely mirror the EU Regulation without adding or reducing material obligations — but provide the national legal basis for enforcement and supervisory powers. https://legislation.mt/eli/ln/2024/166/eng

Related objective Protect Critical Sectors

The implementation of Regulation (EU) 2024/1366 n cybersecurity aspects of cross-border electricity flows will take place through the implementation of the NIS2 Directive. Malta CIP, as the supervisory authority for the NIS2 Directive will act as the competent authority for Regulation (EU) 2024/1366.

Attachments:
Related objective Protect Critical Sectors

Obligations arising from EU Regulation (EU) 2019/1583 – Cybersecurity Measures in Aviation Security are reflected in Malta’s National Civil Aviation Security Programme through the Aviation Security Directorate within the Ministry For Home Affairs that issues guidance and instructions to industry accordingly. https://www.transport.gov.mt/aviation/regulation-policy/european-legislation-702

Related objective Protect Critical Sectors

In Malta, the Civil Aviation Directorate (TM-CAD) is responsible for applying and enforcing Part-IS requirements (EASA Part-IS – Information Security for Aviation Safety) for entities certificated/approved in Malta. https://www.transport.gov.mt/aviation/regulation-policy/european-legislation-702

Related objective Protect Critical Sectors