← Malta

L.S. 591.02 Regolamenti dwar Cybersecurity Certification

[ S.L. 591.02 CYBERSECURITY CERTIFICATION 1 SUBSIDIARY LEGISLATION 591.02 CYBERSECURITY CERTIFICATION REGULATIONS 14th June, 2024 LEGAL NOTICE 133 of 2024. 1.

(1)The title of these regulations is the Cybersecurity Certification Regulations. Citation and scope.
(2)These regulations implement the requisites of the provisions of Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act). 2. requires:
(1)In these regulations, unless the context otherwise "Act" means the Malta Digital Innovation Authority Act; "Authority" means the Malta Digital Authority as established by article 5 of the Act; Interpretation. Cap. 591. Innovation "ECCG" means the European Cybersecurity Certification Group; "ENISA" means the European Union Agency for Cybersecurity; "national liaison officer" means the point of contact at national level who facilitates cooperation between ENISA and national experts in the context of the implementation of ENISA’s annual work programme; "Regulation (EU) 2019/881" means Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act).
(2)Unless the context otherwise requires, words and phrases used in these regulations and in Regulation (EU) 2019/881 which are not herein defined shall have the same meaning as that assigned to them in the Act.
  1. The Authority shall appoint a member and, or an alternate to sit on the Management Board of ENISA on the basis of his knowledge in the field of cybersecurity, taking into account his relevant managerial, administrative and budgetary skills and in accordance with the provisions of Regulation (EU) 2019/
  2. Appointment of a member on the Management Board of ENISA. 2 [ S.L. 591.02 CYBERSECURITY CERTIFICATION Appointment of national liaison officer.
  3. The Authority shall appoint one
(1)representative and, or its alternate to the National Liaison Officers Network set up in accordance with Article 23 of Regulation (EU) 2019/
  1. Cybersecurity certification.
  2. ICT products, ICT services, ICT processes and managed security services that have been certified under a European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881 shall in terms of Article 56 of Regulation (EU) 2019/881 be presumed to comply with the requirements of such scheme and the certificate shall have the effect intended by Regulation (EU) 2019/881 in Malta. Designation, functions and powers of the Authority as the national cybersecurity certification authority. 6.
(1)For the purposes of Article 58 of Regulation (EU) 2019/881, the Authority shall be designated as the national cybersecurity certification authority responsible for the supervisory tasks in Malta and shall have all the functions prescribed in Regulation 2019/881, including the function of: (a) supervising and enforcing rules included in European cybersecurity certification schemes in accordance with Article 54
(1)(
  1. j)of Regulation (EU) 2019/881, for the monitoring of compliance of ICT products, ICT services, ICT processes and managed security services with the requirements of the European cybersecurity certificates that have been issued in Malta, in cooperation with other relevant market surveillance authorities; (
  2. b)monitoring compliance with and enforcing the obligations of manufacturers or providers of ICT products, ICT services, ICT processes or managed security services that are established in Malta and that carry out conformity selfassessment, and shall, in particular, monitor compliance with and enforce the obligations of such manufacturers or providers specified in Article 53
(2)and
(3)of Regulation (EU) 2019/881 and the corresponding European cybersecurity certification scheme; (c) without prejudice to Article 60
(3)of Regulation (EU) 2019/881, actively assisting and supporting the national accreditation bodies in the monitoring and supervision of the activities of conformity assessment bodies, for the purposes of Regulation (EU) 2019/881; (d) monitoring and supervising the activities of the public bodies accredited as conformity assessment bodies in accordance with Article 56
(5)Regulation (EU) 2019/881; (e) where applicable, authorising conformity assessment bodies in accordance with Article 60
(3)of the Regulation (EU) 2019/881 and restrict, suspend or withdraw existing authorisation where conformity assessment bodies CYBERSECURITY CERTIFICATION [ S.L. 591.02 infringe the requirements of Regulation (EU) 2019/881 and these regulations; (f) handling complaints by natural or legal persons in relation to European cybersecurity certificates issued by national cybersecurity certification authorities or to European cybersecurity certificates issued by conformity assessment bodies in accordance with Article 56
(6)of Regulation (EU) 2019/881 or in relation to EU statements of conformity issued under Article 53 of Regulation (EU) 2019/881, and shall investigate the subject matter of such complaints to the extent appropriate, and shall inform the complainant of the progress and the outcome of the investigation within a reasonable period; (g) providing an annual summary report on the activities conducted under paragraphs (b), (c) and (d) or under sub-regulation
(2)to ENISA and the ECCG; (
  1. h)cooperating with other national cybersecurity certification authorities or other public authorities, including by sharing information on the possible non-compliance of ICT products, ICT services, ICT processes and managed security services with the requirements of these regulations and Regulation (EU) 2019/881 or with the requirements of specific European cybersecurity certification schemes; (
  2. i)monitoring relevant developments in the field of cybersecurity certification; (
  3. j)participating in the ECCG in an active, effective, efficient and secure manner for the effective implementation of Regulation (EU) 2019/881; (
  4. k)cooperating with other national cybersecurity certification authorities and with the European Commission, in particular, by exchanging information, experience and good practices as regards cybersecurity certification and technical issues concerning the cybersecurity of ICT products, ICT services, ICT processes and managed security services; and (
  5. l)participating in peer reviews with other national cybersecurity certification authorities within the European Union in accordance with Regulation (EU) 2019/881.
(2)Without prejudice to the Authority’s powers under the Act, for the purpose of the implementation of Regulation (EU) 2019/ 881, the Authority shall be empowered to: (
  1. a)request conformity assessment bodies, European cybersecurity certificates’ holders and issuers of EU statements of conformity to provide any information it requires for the 3 4 [ S.L. 591.02 CYBERSECURITY CERTIFICATION performance of its tasks; (
  2. b)carry out investigations, in the form of audits of conformity assessment bodies, European cybersecurity certificates’ holders and issuers of EU statements of conformity, for the purpose of verifying their compliance with Title III of Regulation (EU) 2019/881; (
  3. c)take appropriate measures, in accordance with the laws of Malta, to ensure that conformity assessment bodies, European cybersecurity certificates’ holders and issuers of EU statements of conformity comply with Regulation (EU) 2019/ 881 or with a European cybersecurity certification scheme; (
  4. d)obtain access to the premises of any conformity assessment bodies or holders of European cybersecurity certificates, for the purpose of carrying out investigations in accordance with Union or Maltese procedural law; (
  5. e)withdraw, in accordance with the laws of Malta, European cybersecurity certificates issued by the national cybersecurity certification authorities or European cybersecurity certificates issued by conformity assessment bodies in accordance with Article 56
(6)of Regulation (EU) 2019/881, where such certificates do not comply with Regulation (EU) 2019/881 or with a European cybersecurity certification scheme; and (f) impose penalties in accordance with the laws of Malta, as provided for in Article 65 of Regulation (EU) 2019/ 881, and to require the immediate cessation of infringements of the obligations set out in Regulation (EU) 2019/881.
(3)Without prejudice to point (a) of Article 56
(5)and Article 56
(6)of Regulation (EU) 2019/881, the Authority shall be independent of the entities it supervises in its organisation, funding decisions, legal structure and decision-making.
(4)In terms of Article 58
(4)of Regulation (EU) 2019/881, the activities of the Authority that relate to the issuance of European cybersecurity certificates referred to in point (a) of Article 56
(5)and Article 56
(6)of Regulation (EU) 2019/881 shall be strictly separated from its supervisory activities set out in Article 58 of the Regulation (EU) 2019/881 and these activities shall be carried out independently from each other.
(5)In accordance with the Act and subject to the provisions of any other law in force in Malta relating to public procurement, the Authority shall be empowered as stipulated in Article 58
(5)of Regulation (EU) 2019/881 to employ and engage any services and procure the resources necessary to exercise its powers and functions CYBERSECURITY CERTIFICATION [ S.L. 591.02 under these regulations and Regulation (EU) 2019/881 effectively and efficiently. 7.
(1)The provisions of Part IX of the Act shall apply to: Right to an effective judicial remedy. (
  1. a)decisions taken by the Authority pursuant to these regulations, including with regard to the improper issuing, failure to issue or recognition of a European cybersecurity certificate held by natural and legal persons; and (
  2. b)a failure of the Authority to act on a complaint filed with the said Authority.
(2)Proceedings for a judicial remedy shall be brought before the Civil Court (First Hall): (
  1. a)from decisions taken by the conformity assessment body located in Malta pursuant to these regulations, including with regard to the improper issuing, failure to issue or recognition of a European cybersecurity certificate held by natural and legal persons; or (
  2. b)due to the failure of the conformity assessment body located in Malta to act on a complaint filed with the said conformity assessment body. 8. Article 42 of the Act shall apply to infringements of these regulations, infringements of the provisions of Title II of Regulation (EU) 2019/881 and to infringements of European cybersecurity certification schemes. Infringements. 5

🔗 Għas-sors uffiċjali

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.