That arithmetic is the single most useful fact about NIS2 budgeting, and it points at the mistake most budgets make: treating NIS2 as a project with a completion date rather than a permanent operating cost. Below is where the money goes, the multiplier nobody plans for, and how to size your own number.
- What does NIS2 compliance cost?
- The one official estimate, and how to read it
- What the other results get wrong about NIS2 cost
- The seven lines every NIS2 budget contains
- The multiplier nobody budgets for: Member States
- Why the recurring cost is the real number
- Size your own NIS2 budget
- How to cut the number without cutting the compliance
- Frequently asked questions
What does NIS2 compliance cost?
Any single figure is wrong until four things are known: how many Member States you operate in, whether you are an essential or an important entity, how mature your security programme already is, and how many of the ten Article 21 measures you can already evidence rather than merely assert.
The useful move is to stop asking for a price and start reading the one population-level estimate a government has actually published, then adjust it for your own position. That estimate follows.
The one official estimate, and how to read it

Directive (EU) 2022/2555 is transposed into national law by each Member State, and German legislative practice requires a bill to carry an assessment of the compliance burden it imposes, the Erfüllungsaufwand. The assessment attached to Germany's NIS2 implementation bill puts the burden on the German economy at approximately EUR 2.1 billion one-off and approximately EUR 2.2 billion recurring each year, spread across roughly 30,000 entities brought into scope.
Three things follow, and the third is the one to take to your board.
- These are estimates made for legislative purposes, describing an entire national economy including many organisations far larger and far smaller than yours. They are an anchor rather than a quote.
- They are German figures. Scope, thresholds and registration duties vary by transposition, so the population and the per-entity burden differ across Member States.
- The recurring number is roughly the same size as the one-off number. That is the finding worth acting on. NIS2 is not a project you finish; the annual burden the German government projects is comparable to the initial build, every year, indefinitely.
The published bill and its impact assessment are available from the German Federal Ministry of the Interior, and the bill has been revised more than once, so check the current version before quoting a figure in a board paper.
What the other results get wrong about NIS2 cost
Two errors are repeated across the pages that rank for this query, and both make budgets too small.
The annual figure gets understated. A widely repeated claim pairs the German per-entity one-off figure of around EUR 70,000 with an annual figure of around EUR 30,000. That pairing does not reconcile with the aggregate it is drawn from: roughly EUR 2.2 billion spread over roughly 30,000 entities averages far closer to EUR 70,000 a year than to EUR 30,000. If you have budgeted the low number, you have budgeted less than half the recurring cost that the source itself implies. Do the division yourself before accepting any per-entity figure.
Penalties get presented as the cost. Several results answer "what does NIS2 cost" with the fine ceilings: EUR 10 million or 2 percent of worldwide turnover for essential entities, EUR 7 million or 1.4 percent for important ones. Those numbers are real and we cover them in NIS2 fines and penalties, but they are the cost of failing, not the cost of complying. A budget built from fine exposure tells you nothing about what to spend or on what.
The seven lines every NIS2 budget contains

1. Scoping. Determining which of your entities are in scope, in which countries, and whether each is essential or important. Cheap for a single-country company, substantial for a group. Start with what NIS2 is and who must comply.
2. Gap assessment. Scoring yourself against the ten risk-management measures in Article 21, with evidence rather than opinion.
3. Remediation. The largest and most variable line, because it is whatever the gap assessment finds. For an organisation with an existing management system this is small; for one without, it can include multi-factor authentication rollout, backup and crisis management, access control and asset management work.
4. Supply chain security. Article 21 requires you to account for the security of your suppliers and service providers, including their practices. That means assessing them, recording it and keeping it current. This line scales with supplier count and is routinely omitted from first budgets.
5. Incident readiness. The ability to detect, classify and report inside the Article 23 deadlines: an early warning within 24 hours, a notification within 72, and a final report within one month. The cost here is out-of-hours capability and rehearsal rather than software.
6. Registration and national interaction. Registering with the competent authority, per country, in the national format.
7. Running and evidencing the programme. Keeping measures current, testing their effectiveness as Article 21 requires, maintaining supplier assessments and recording what the management body approved. This is the recurring line, and per the German estimate it is roughly the size of everything above it combined, every year.

The multiplier nobody budgets for: Member States

NIS2 is a Directive, so what binds you is your national transposition rather than the Directive text. For a company operating in one Member State this is a detail. For a group operating in several it is a structural cost driver, because some lines replicate per country and some do not.
| Budget line | Replicates per Member State? | Why |
|---|---|---|
| Article 21 measures | No | One control set can satisfy every country's transposition |
| Evidence collection | No | The same evidence answers the same measure everywhere |
| Scoping and classification | Yes | Thresholds and sector definitions vary by transposition |
| Registration | Yes | Each competent authority runs its own process and portal |
| Incident reporting route | Yes | Different CSIRT, format and national deadlines within the framework |
| Local legal review | Yes | National law adds requirements the Directive does not contain |
The lesson for budgeting is that five countries does not mean five times the cost, provided you build one control set and one evidence library and treat only registration, reporting routes and local legal review as per-country work. Organisations that instead run a separate programme per country pay something much closer to the naive multiple.
Why the recurring cost is the real number
Most NIS2 budgets are written as a project: assess, remediate, register, done. The German figures say otherwise, and so does the text of the Directive. Article 21 requires policies to assess the effectiveness of the measures, which is a recurring activity. Supplier security has to reflect current practice. The management body has to oversee implementation on an ongoing basis, which means something to oversee and a record of having done it. Incident capability decays without rehearsal.
The practical test for a budget: if year two is a small fraction of year one, the plan has probably funded building the measures and not funded evidencing them. That is the shape of programme that passes its first year and produces an adverse finding in its third.
Size your own NIS2 budget
| Question | Effect on your number |
|---|---|
| In how many Member States are you in scope? | Multiply scoping, registration and reporting-route lines only |
| Essential or important entity? | Essential entities face proactive supervision, so evidence quality has to be higher from day one |
| Do you hold ISO 27001 or an equivalent management system? | Most of the remediation line falls away and the work becomes mapping and evidencing |
| How many suppliers are in scope for assessment? | Drives the supply chain line directly, and it recurs |
| Can you evidence, today, that measures are tested for effectiveness? | If not, add the recurring line properly rather than as a rounding item |
| Do you run other frameworks with overlapping controls? | Shared controls turn several programmes into one, and this is the largest available saving |
How to cut the number without cutting the compliance
- Build one control set for every framework you run. The Article 21 measures overlap heavily with ISO 27001 and with DORA for entities caught by both. Maintaining a separate programme per framework is the most expensive way to reach the same position.
- Do the scoping properly once. Being in scope in a country you are not actually in scope in is a pure waste, and the reverse is a finding.
- Automate evidence rather than remediation. Remediation is real work that has to be done. Evidence collection is repetitive and is where recurring cost accumulates.
- Rehearse incident reporting before you need it. A missed 24 hour deadline is cheap to prevent and expensive to explain.
- Budget year two before you approve year one. If nobody can say what year two costs, year one is not a plan.

Do this in Venvera
Venvera runs NIS2 as a maintained control set covering the Article 21 measures, per-country transposition differences, supplier assessments, incident classification with the Article 23 clocks, and a board record of what was approved and when. Evidence attached once is reused by every framework that asks for the same control, which is exactly the lever that turns the recurring line from a multiple into a single number. See the NIS2 workspace, or start with the free NIS2 compliance checklist to find your gaps before committing budget. Pricing is published and flat, from EUR 399 per month.
Frequently asked questions
How much does NIS2 compliance cost?
The only population-level figures published by a government come from the impact assessment attached to Germany's NIS2 implementation bill: approximately EUR 2.1 billion one-off and EUR 2.2 billion annually across roughly 30,000 entities. Averaged, that is near EUR 70,000 per entity per year recurring. Your own number depends on country count, entity classification, existing security maturity and supplier count.
Is the annual cost of NIS2 really as high as the setup cost?
On the German government's own figures, the recurring burden is comparable to the one-off burden. That reflects what the Directive asks for: testing the effectiveness of measures, keeping supplier assessments current, maintaining management body oversight and holding incident capability ready.
Does NIS2 cost more if we operate in several EU countries?
Yes, but less than proportionally if the programme is built correctly. The Article 21 measures and the evidence behind them can be shared across countries. Scoping, registration, incident reporting routes and local legal review replicate per Member State.
Does ISO 27001 reduce NIS2 cost?
Substantially. An existing management system covers much of what Article 21 asks for, so the remediation line shrinks and the work becomes mapping and evidencing. The saving depends on controls being shared across frameworks rather than duplicated per framework.
Should we budget for fines?
Fines are the cost of failing rather than the cost of complying, so they do not belong in an implementation budget. They matter for prioritisation, since the ceilings are high and management bodies carry personal exposure, which is covered in NIS2 fines and penalties.
What is the most commonly underestimated NIS2 cost?
The recurring line, followed by supply chain assessment. Both are ongoing obligations that first-year budgets tend to treat as one-off tasks.





