6 min read

The EU Cyber Resilience Act Moves From Paper to Practice: Malta Sets Up Its Enforcement Framework

The EU Cyber Resilience Act Moves From Paper to Practice: Malta Sets Up Its Enforcement Framework

On 11 September 2026, Malta published Legal Notice 238 of 2026, the Cyber Resilience Regulations, giving the EU's Cyber Resilience Act (CRA) a national supervisory and enforcement structure. The date was not a coincidence: the same day, the CRA's first substantive obligation went live across all 27 Member States, requiring manufacturers to report actively exploited vulnerabilities and severe incidents within 24 hours.

Malta's move is a useful lens on a much bigger shift. Every Member State must now put authorities, penalty rules and reporting channels in place, and every business selling connected hardware or software into the EU is already inside the regime, well before its full application on 11 December 2027.

What the Cyber Resilience Act does

The CRA (Regulation (EU) 2024/2847) is the EU's first horizontal cybersecurity law for products. It covers any hardware or software "product with digital elements" made available commercially on the EU market whose intended use involves a data connection to a device or network, from baby monitors and smart watches to apps, firmware and components sold separately. Products already covered by sector rules (such as certain vehicle legislation) are carved out.

Because it is a Regulation, the CRA applies directly in every Member State. National law does not transpose it; it supplies the machinery around it: who supervises, who notifies conformity assessment bodies, who receives incident reports, and what penalties apply.

The obligations fall on the whole supply chain:

Role

Core obligations

Manufacturer

Cybersecurity risk assessment; design to the Annex I essential requirements; vulnerability handling for a declared support period; technical documentation; conformity assessment; EU declaration of conformity and CE marking; incident and vulnerability reporting

Importer

Place only compliant non-EU products on the market; check conformity assessment, documentation and CE marking; act on non-compliance and inform the manufacturer of vulnerabilities

Distributor

Verify CE marking, contact details, user instructions and support period; withhold non-compliant products; cooperate with authorities

Open-source steward

Cybersecurity policy, cooperation with authorities, and reporting from 11 December 2027; not subject to fines

Most products can be self-assessed by the manufacturer. "Important" products (Class I and II) and "critical" products listed in Annexes III and IV face stricter routes, typically third-party assessment by a notified body or an EU certification scheme. (Commission summary)

The timeline

The CRA entered into force on 10 December 2024 but phases in over three years, and two early milestones have already passed.

[embed: node/58d4651a-0521]

Rules on notifying conformity assessment bodies have applied since 11 June 2026, and incident and vulnerability reporting since 11 September 2026. Everything else, including the design requirements, conformity assessment and CE marking, applies from 11 December 2027. Products placed on the market before that date only fall under the full rules if they are substantially modified afterwards, but reporting covers them already.

Reporting is already live

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products. This applies to every product made available on the EU market, including those placed on the market years before the CRA's main rules begin.

Report

Deadline

Early warning

Within 24 hours of becoming aware

Full notification

Within 72 hours of becoming aware

Final report, exploited vulnerability

No later than 14 days after a corrective or mitigating measure is available

Final report, severe incident

Within one month of the 72-hour notification

Manufacturers file once, through ENISA's CRA Single Reporting Platform. The report goes to the CSIRT of the Member State where the manufacturer has its main establishment and, save in exceptional cases, to ENISA at the same time. That CSIRT then shares it with CSIRTs in every other country where the product is sold. (Commission, reporting obligations)

Two practical points stand out. Micro and small enterprises cannot be fined for missing the 24-hour early-warning deadline, but the other deadlines still bind them. And the 24-hour clock is short enough that detection, triage and escalation have to be working processes now, not a 2027 project.

Legal Notice 238 of 2026 was published in Government Gazette No. 21,717 and puts the Malta Digital Innovation Authority (MDIA) at the centre of CRA enforcement. (FFL via Legal 500)

Body

Role under the CRA and related EU law

Malta Digital Innovation Authority (MDIA)

Notifying Authority for conformity assessment bodies; Market Surveillance Authority for products with digital elements. Separately, the National Cybersecurity Certification Authority under the EU Cybersecurity Act

Malta Information Technology Agency (MITA)

National CSIRT, and the CSIRT designated as coordinator under the CRA, so it receives Malta-routed reports from the Single Reporting Platform. MITA also hosts the National Coordination Centre (NCC-MT)

As Market Surveillance Authority, the MDIA can investigate compliance, demand technical documentation and order corrective measures. It can respond to infringements with warnings, corrective orders and administrative penalties, weighing the seriousness of the breach and the size of the operator.

Those national tools sit alongside the CRA's own fine ceilings: up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaching the essential requirements or the core manufacturer duties in Articles 13 and 14. The Regulations also amend Malta's Administrative Justice Act, so MDIA decisions can be challenged through the ordinary administrative review route.

For smaller firms, the framework provides for awareness and preparedness support and allows cyber resilience regulatory sandboxes, where innovative products can be developed and tested under supervision. The MDIA also points SMEs to ENISA's free CRA maturity self-assessment tool, whose results do not need to be submitted to the authority.

One correction to a common reading: December 2027 is not only the start of market surveillance. It is the date the CRA applies in full, including the design requirements, conformity assessment and CE marking.

The same build-out is happening across the EU

Malta is doing what every Member State must do. The CRA requires each country to designate notifying authorities (due by 11 June 2026, when Chapter IV began to apply), one or more market surveillance authorities, a CSIRT coordinator for reporting, and national penalty rules that are effective, proportionate and dissuasive.

Countries are making different institutional choices. Some hand the CRA to an existing cybersecurity agency, others to a product-safety or telecoms regulator, and some split roles across several bodies, as Malta does between the MDIA and MITA. For a business selling across borders, that means:

  • One report, many recipients. You report once to the CSIRT where your main EU establishment is; it forwards to the others.
  • Many potential enforcers. Any Member State's market surveillance authority can act against your product on its market. They coordinate through an Administrative Cooperation Group (ADCO) and can run joint sweeps.
  • Common rulebook, local procedure. The obligations are identical everywhere, but inspection powers, penalty scales below the EU ceilings and appeal routes are national.

The Commission has also been filling in detail. An implementing regulation of November 2025 gives technical descriptions of important and critical product categories, and on 27 July 2026 the Commission published practical guidance for manufacturers. Harmonised standards, which give a presumption of conformity, are still being developed. (Commission, CRA overview)

The CRA also sits beside NIS2: NIS2 governs how essential and important entities secure their own operations, while the CRA governs the security of the products they buy and sell. Many organisations fall under both.

What businesses should do now

Now, for obligations already in force:

  1. Map your portfolio: which products have digital elements and are sold in the EU, including legacy products still on the market.
  2. Identify your role for each product: manufacturer, importer, distributor, or open-source steward.
  3. Register with the Single Reporting Platform and confirm which national CSIRT is yours based on your main EU establishment.
  4. Build a 24/72-hour playbook: detection sources, a triage owner, escalation paths, and pre-approved report templates.
  5. Make sure suppliers and open-source components feed vulnerability information to you quickly enough to meet those clocks.

Before 11 December 2027, for full application:

  1. Classify each product as default, important (Class I or II) or critical, and plan the matching conformity route.
  2. Where a notified body is needed, engage early; capacity is expected to be tight.
  3. Run cybersecurity risk assessments and bake the Annex I requirements into design and development.
  4. Set and publish a support period for each product, with the end month and year.
  5. Prepare technical documentation, the EU declaration of conformity and CE marking processes.
  6. Smaller firms: use ENISA's maturity tool and ask your national authority about support schemes or sandboxes.

Conclusion

Malta's Legal Notice 238 shows what CRA implementation looks like on the ground: a named enforcer, a reporting coordinator, penalty and appeal machinery, and some help for smaller firms. The same architecture is being assembled in every Member State. The lesson for any company selling connected products into Europe is that the CRA is no longer a 2027 deadline. Reporting duties are live today, and the 15 months to full application are the window to build secure-by-design products that can pass conformity assessment.

This article is a general overview, not legal advice. Check the Regulation and your national authority's guidance for your specific situation.

Sources