NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
NIS2 Compliance Cost: What to Budget
Learn

NIS2 Compliance Cost: What to Budget

·Alexander Sverdlov
The short answer
There is one official estimate worth anchoring on. The impact assessment attached to Germany's NIS2 implementation bill prices the directive for the German economy at roughly EUR 2.1 billion one-off and EUR 2.2 billion every year, across about 30,000 in-scope entities. Divide it: the recurring figure averages near EUR 70,000 per entity per year, which is far above the annual number most vendor articles quote.

That arithmetic is the single most useful fact about NIS2 budgeting, and it points at the mistake most budgets make: treating NIS2 as a project with a completion date rather than a permanent operating cost. Below is where the money goes, the multiplier nobody plans for, and how to size your own number.

On this page
  1. What does NIS2 compliance cost?
  2. The one official estimate, and how to read it
  3. What the other results get wrong about NIS2 cost
  4. The seven lines every NIS2 budget contains
  5. The multiplier nobody budgets for: Member States
  6. Why the recurring cost is the real number
  7. Size your own NIS2 budget
  8. How to cut the number without cutting the compliance
  9. Frequently asked questions

What does NIS2 compliance cost?

Any single figure is wrong until four things are known: how many Member States you operate in, whether you are an essential or an important entity, how mature your security programme already is, and how many of the ten Article 21 measures you can already evidence rather than merely assert.

The useful move is to stop asking for a price and start reading the one population-level estimate a government has actually published, then adjust it for your own position. That estimate follows.

The one official estimate, and how to read it

German government impact assessment figures for NIS2: 2.1 billion one-off, 2.2 billion annual, 30,000 entities
The only population-level figures with a government's name attached, and the division most articles skip.

Directive (EU) 2022/2555 is transposed into national law by each Member State, and German legislative practice requires a bill to carry an assessment of the compliance burden it imposes, the Erfüllungsaufwand. The assessment attached to Germany's NIS2 implementation bill puts the burden on the German economy at approximately EUR 2.1 billion one-off and approximately EUR 2.2 billion recurring each year, spread across roughly 30,000 entities brought into scope.

Three things follow, and the third is the one to take to your board.

  1. These are estimates made for legislative purposes, describing an entire national economy including many organisations far larger and far smaller than yours. They are an anchor rather than a quote.
  2. They are German figures. Scope, thresholds and registration duties vary by transposition, so the population and the per-entity burden differ across Member States.
  3. The recurring number is roughly the same size as the one-off number. That is the finding worth acting on. NIS2 is not a project you finish; the annual burden the German government projects is comparable to the initial build, every year, indefinitely.

The published bill and its impact assessment are available from the German Federal Ministry of the Interior, and the bill has been revised more than once, so check the current version before quoting a figure in a board paper.

What the other results get wrong about NIS2 cost

Two errors are repeated across the pages that rank for this query, and both make budgets too small.

The annual figure gets understated. A widely repeated claim pairs the German per-entity one-off figure of around EUR 70,000 with an annual figure of around EUR 30,000. That pairing does not reconcile with the aggregate it is drawn from: roughly EUR 2.2 billion spread over roughly 30,000 entities averages far closer to EUR 70,000 a year than to EUR 30,000. If you have budgeted the low number, you have budgeted less than half the recurring cost that the source itself implies. Do the division yourself before accepting any per-entity figure.

Penalties get presented as the cost. Several results answer "what does NIS2 cost" with the fine ceilings: EUR 10 million or 2 percent of worldwide turnover for essential entities, EUR 7 million or 1.4 percent for important ones. Those numbers are real and we cover them in NIS2 fines and penalties, but they are the cost of failing, not the cost of complying. A budget built from fine exposure tells you nothing about what to spend or on what.

The seven lines every NIS2 budget contains

The seven lines in a NIS2 budget, from scoping through registration to running the programme
Seven lines. The last one recurs forever and is the one most often left out of year one.

1. Scoping. Determining which of your entities are in scope, in which countries, and whether each is essential or important. Cheap for a single-country company, substantial for a group. Start with what NIS2 is and who must comply.

2. Gap assessment. Scoring yourself against the ten risk-management measures in Article 21, with evidence rather than opinion.

3. Remediation. The largest and most variable line, because it is whatever the gap assessment finds. For an organisation with an existing management system this is small; for one without, it can include multi-factor authentication rollout, backup and crisis management, access control and asset management work.

4. Supply chain security. Article 21 requires you to account for the security of your suppliers and service providers, including their practices. That means assessing them, recording it and keeping it current. This line scales with supplier count and is routinely omitted from first budgets.

5. Incident readiness. The ability to detect, classify and report inside the Article 23 deadlines: an early warning within 24 hours, a notification within 72, and a final report within one month. The cost here is out-of-hours capability and rehearsal rather than software.

6. Registration and national interaction. Registering with the competent authority, per country, in the national format.

7. Running and evidencing the programme. Keeping measures current, testing their effectiveness as Article 21 requires, maintaining supplier assessments and recording what the management body approved. This is the recurring line, and per the German estimate it is roughly the size of everything above it combined, every year.

NIS2 gap assessment scoring the Article 21 measures with prioritised remediation
The gap assessment converts an open budget question into a costed list of findings.

The multiplier nobody budgets for: Member States

How NIS2 cost scales across one country, five countries and a fifteen entity group
Measures are shared across countries. Scoping, registration and local deviations are not.

NIS2 is a Directive, so what binds you is your national transposition rather than the Directive text. For a company operating in one Member State this is a detail. For a group operating in several it is a structural cost driver, because some lines replicate per country and some do not.

Budget lineReplicates per Member State?Why
Article 21 measuresNoOne control set can satisfy every country's transposition
Evidence collectionNoThe same evidence answers the same measure everywhere
Scoping and classificationYesThresholds and sector definitions vary by transposition
RegistrationYesEach competent authority runs its own process and portal
Incident reporting routeYesDifferent CSIRT, format and national deadlines within the framework
Local legal reviewYesNational law adds requirements the Directive does not contain

The lesson for budgeting is that five countries does not mean five times the cost, provided you build one control set and one evidence library and treat only registration, reporting routes and local legal review as per-country work. Organisations that instead run a separate programme per country pay something much closer to the naive multiple.

Why the recurring cost is the real number

Most NIS2 budgets are written as a project: assess, remediate, register, done. The German figures say otherwise, and so does the text of the Directive. Article 21 requires policies to assess the effectiveness of the measures, which is a recurring activity. Supplier security has to reflect current practice. The management body has to oversee implementation on an ongoing basis, which means something to oversee and a record of having done it. Incident capability decays without rehearsal.

The practical test for a budget: if year two is a small fraction of year one, the plan has probably funded building the measures and not funded evidencing them. That is the shape of programme that passes its first year and produces an adverse finding in its third.

Size your own NIS2 budget

QuestionEffect on your number
In how many Member States are you in scope?Multiply scoping, registration and reporting-route lines only
Essential or important entity?Essential entities face proactive supervision, so evidence quality has to be higher from day one
Do you hold ISO 27001 or an equivalent management system?Most of the remediation line falls away and the work becomes mapping and evidencing
How many suppliers are in scope for assessment?Drives the supply chain line directly, and it recurs
Can you evidence, today, that measures are tested for effectiveness?If not, add the recurring line properly rather than as a rounding item
Do you run other frameworks with overlapping controls?Shared controls turn several programmes into one, and this is the largest available saving

How to cut the number without cutting the compliance

  • Build one control set for every framework you run. The Article 21 measures overlap heavily with ISO 27001 and with DORA for entities caught by both. Maintaining a separate programme per framework is the most expensive way to reach the same position.
  • Do the scoping properly once. Being in scope in a country you are not actually in scope in is a pure waste, and the reverse is a finding.
  • Automate evidence rather than remediation. Remediation is real work that has to be done. Evidence collection is repetitive and is where recurring cost accumulates.
  • Rehearse incident reporting before you need it. A missed 24 hour deadline is cheap to prevent and expensive to explain.
  • Budget year two before you approve year one. If nobody can say what year two costs, year one is not a plan.
One control mapped across NIS2, ISO 27001 and DORA with shared evidence
The largest available saving: one control, one piece of evidence, counted by every framework that asks for it.

Do this in Venvera

Venvera runs NIS2 as a maintained control set covering the Article 21 measures, per-country transposition differences, supplier assessments, incident classification with the Article 23 clocks, and a board record of what was approved and when. Evidence attached once is reused by every framework that asks for the same control, which is exactly the lever that turns the recurring line from a multiple into a single number. See the NIS2 workspace, or start with the free NIS2 compliance checklist to find your gaps before committing budget. Pricing is published and flat, from EUR 399 per month.

Frequently asked questions

How much does NIS2 compliance cost?

The only population-level figures published by a government come from the impact assessment attached to Germany's NIS2 implementation bill: approximately EUR 2.1 billion one-off and EUR 2.2 billion annually across roughly 30,000 entities. Averaged, that is near EUR 70,000 per entity per year recurring. Your own number depends on country count, entity classification, existing security maturity and supplier count.

Is the annual cost of NIS2 really as high as the setup cost?

On the German government's own figures, the recurring burden is comparable to the one-off burden. That reflects what the Directive asks for: testing the effectiveness of measures, keeping supplier assessments current, maintaining management body oversight and holding incident capability ready.

Does NIS2 cost more if we operate in several EU countries?

Yes, but less than proportionally if the programme is built correctly. The Article 21 measures and the evidence behind them can be shared across countries. Scoping, registration, incident reporting routes and local legal review replicate per Member State.

Does ISO 27001 reduce NIS2 cost?

Substantially. An existing management system covers much of what Article 21 asks for, so the remediation line shrinks and the work becomes mapping and evidencing. The saving depends on controls being shared across frameworks rather than duplicated per framework.

Should we budget for fines?

Fines are the cost of failing rather than the cost of complying, so they do not belong in an implementation budget. They matter for prioritisation, since the ceilings are high and management bodies carry personal exposure, which is covered in NIS2 fines and penalties.

What is the most commonly underestimated NIS2 cost?

The recurring line, followed by supply chain assessment. Both are ongoing obligations that first-year budgets tend to treat as one-off tasks.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING