Cyber Resilience Act Malta

On 11 September 2026, Malta published Legal Notice 238 of 2026, titled the Cyber Resilience Regulations, 2026 (the “Regulations”). These establish the national arrangements supporting the Cyber Resilience Act (“CRA”), with the Malta Digital Innovation Authority (“MDIA”) taking a central role in its implementation.

The CRA establishes cybersecurity requirements for “products with digital elements”, defined under its Article 3(1) as “a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”.

As an EU regulation, it applies directly in Member States according to its own timetable. The Regulations provide the domestic framework for its administration and enforcement and must accordingly be read in conjunction with the CRA.

As delved in our previous article, the CRA captures software and connected hardware made available on the EU market, subject to specific exclusions. Manufacturers will need to incorporate cybersecurity into product development and manage vulnerabilities throughout the applicable support period. Conformity assessment establishes whether the essential cybersecurity requirements have been met, with CE marking indicating compliance. In line with the EU’s approach to product safety, importers and distributors bear separate obligations according to their position within the supply chain.

The Regulations designate the MDIA as Malta’s Notifying Authority, responsible for notifying the European Commission of the bodies authorised to carry out conformity assessments under the CRA. Assessment and monitoring of such bodies are entrusted to the National Accreditation Board Malta. In practice, this provides the local framework for independent bodies to assess products where external conformity assessment is required before those products enter the EU market.

Commencement

With regard to commencement, the MDIA’s designation as Notifying Authority is already effective. The corresponding CRA provisions have applied since 11 June 2026. The national provisions governing market surveillance and enforcement take effect on 11 December 2027, alongside the CRA’s general application. From that date, the MDIA will oversee compliance as Malta’s Market Surveillance Authority, including the proper use of CE marking.

 

The provisions on support for smaller businesses and the national incident response team’s coordinating role also commence then.

Reporting

Whilst much of the framework applies from December 2027, manufacturers’ reporting duties under Article 14 of the CRA have applied since 11 September 2026. These concern security weaknesses which are being actively exploited and severe incidents affecting a product’s security. By way of example, evidence that an attacker has exploited a weakness in a product may trigger notification. Reporting takes place through the Single Reporting Platform operated by the European Union Agency for Cybersecurity (“ENISA”), enabling the relevant national incident response team and ENISA to receive the information.

An early warning must be submitted without undue delay and within 24 hours of awareness, followed by a fuller notification without undue delay and within 72 hours of awareness. For exploited vulnerabilities, a final report is due within 14 days of a corrective or mitigating measure becoming available. For severe incidents, the final report is generally due within one month of the fuller notification. Saliently, these obligations also capture relevant products placed on the market before 11 December 2027.

Penalties

From December 2027, the Regulations will apply the MDIA Act’s administrative penalty framework, with appeals against the Authority’s decisions. They also allow the MDIA to require written undertakings to remedy infringements. Under the CRA, specified breaches may attract fines of up to €15 million or, for undertakings, 2.5% of worldwide annual turnover for the preceding financial year, whichever is higher.

The Regulations further provide for assistance to microenterprises and small enterprises, where appropriate. The MDIA may also establish regulatory sandboxes, allowing businesses to test innovative products under its supervision before placing them on the market.

For captured businesses, the immediate priority is to ensure that reporting procedures can meet the applicable deadlines. Preparation for December 2027 should address which products fall within scope and the required conformity assessment route. Supplier contracts should also secure timely information about vulnerabilities, with continuing security support reflected in product planning.

GTG can assist with assessing the CRA’s application to your business and preparing for the Maltese framework. For further information or assistance, please contact us at info@gtg.com.mt.

Author: Dr J.J. Galea

 

Disclaimer This article is not intended to impart legal advice and readers are asked to seek verification of statements made before acting on them.
Skip to content