Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIS2 compliance cost in 2026: typical first-year ranges for important and essential entities and the official EU and German estimates

NIS2 Compliance Cost in 2026: The Complete Breakdown

The NIS2 compliance cost has no certificate at the end of it, and that is exactly why it is so hard to budget. With ISO 27001 you can at least look up a registrar’s day rate. With NIS2 there is no certification body, no audit fee and no price list — just a legal duty to take “appropriate and proportionate” measures, a supervisor who can check, and a fine if you did not. Every euro is internal spend or consultancy, and the Directive itself says the cost of implementation is one of the things that decides how much is enough.

This guide breaks the 2026 NIS2 compliance cost into the two official estimates that exist, the line items you will actually pay for, and typical first-year totals by entity type and headcount. Government figures are cited to the document they come from. Market ranges are labelled as market ranges, aggregated from published 2026 guidance by EU consultancies and managed security providers, and should be read that way.

Why the NIS2 compliance cost has no price list

NIS2 — Directive (EU) 2022/2555 — is a legal obligation, not a scheme you enrol in. Article 21(1) requires essential and important entities to take “appropriate and proportionate technical, operational and organisational measures”, and then qualifies that duty in a sentence most cost guides skip: the measures must take into account “the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation”. Proportionality is built into the law. A 60-person logistics firm is not expected to spend what a national grid operator spends.

Three consequences follow for your budget:

  • There is no assessment fee. Nobody issues a NIS2 certificate, so the line that anchors every ISO cost guide simply does not exist here. Registration with your national authority is an administrative step, not a paid one.
  • Supervision can cost you money on demand. Article 32 lets the authority order targeted security audits by an independent body for essential entities, and the Directive states that the cost of such an audit “shall be paid by the audited entity” unless the authority decides otherwise. That is a contingent line most budgets omit.
  • National law sets the detail. The Directive binds Member States; the act you comply with is the transposition. Germany’s NIS2UmsuCG entered into force on 6 December 2025. Four Member States — Ireland, Spain, France and the Netherlands — had still not notified full transposition when the Commission referred them to the Court of Justice on 8 July 2026. If you operate there, budget against the Directive text; the national act will add specifics, not remove obligations.

Our guide to NIS2 Directive compliance covers the obligations themselves. This post is about what they cost.

What the two official NIS2 compliance cost estimates say

Most cost articles quote each other. Two documents actually did the arithmetic, and neither is a vendor.

The European Commission’s impact assessment. When the Commission proposed NIS2 in December 2020, its impact assessment estimated that entities brought into scope would need an increase of up to 22% of their existing ICT security spending in the first years after the new framework, and about 12% for entities already covered by the original NIS Directive. It is a relative figure, so it is only useful if you know your current security spend — but it is the one number with the EU’s own name on it.

The German government’s bill. The impact statement attached to Germany’s NIS2 implementation bill (Bundestag Drucksache 20/13184, October 2024) is the most granular public estimate anywhere, because German law requires the government to cost every new obligation. It assumed an essential entity (“besonders wichtige Einrichtung”) incurs about 2,752 staff hours and €60,000 in material costs per year to maintain the required minimum level of IT security, and that an important entity incurs about 60% less — roughly 1,100 hours and €24,000. At the blended €52.30 hourly rate the statement uses, that is approximately:

Entity type (German bill assumption)Staff hours per yearMaterial costs per yearImplied annual costOne-off set-up
Essential entity≈ 2,752 h≈ €60,000≈ €204,000Assumed equal to one year’s recurring cost
Important entity≈ 1,100 h≈ €24,000≈ €81,500Assumed equal to one year’s recurring cost
Derived from the compliance-cost assumptions in Bundestag Drucksache 20/13184 (pp. 103–104). Hours × €52.30 + material costs, rounded. The enacted 2025 bill kept the economy-wide totals in the same range (about €2.3 billion a year, €2.2 billion one-off).

Two caveats. The German figures are averages across roughly 21,000 important and 8,000 essential entities, so a 50-person important entity will sit well below €81,500 and a large one above it. And the estimate is of incremental cost for entities that did not already meet the bar — the bill assumed about 17% of in-scope companies were already adequately protected and would spend little extra.

NIS2 compliance cost by line item

The ten measures in Article 21(2), from risk analysis and incident handling through supply chain security to multi-factor authentication, translate into a fairly predictable set of purchases. The table below gives typical 2026 market ranges for a mid-sized entity, aggregated from published guidance by EU consultancies and MSSPs. They are not quotes.

Line itemWhat drives itTypical range (2026, EUR)One-off or recurring
Gap assessment against Article 21Scope, sites, whether you already run an ISMS€5,000–€25,000One-off
Policies, procedures and registersWritten from scratch vs. adapted from templates€3,000–€40,000One-off, then maintenance
Consultancy for the implementation projectDay rates of €1,000–€2,000; 10–80 days€10,000–€150,000One-off
Technical controls (MFA, backup and recovery, logging, vulnerability and patch management, encryption)Starting maturity; how much is already licensed€10,000–€150,000+Mostly recurring licences
Detection and response (SIEM or MDR service)Endpoint and log volume; 24/7 vs. business hours€12,000–€120,000 per yearRecurring
Incident response readiness and reportingRetainer, playbooks, the 24 h / 72 h / one-month reporting clocks in Article 23€5,000–€40,000 per yearRecurring
Management body training (Article 20)Board size; in-house vs. external€1,000–€10,000 per yearRecurring
Supplier security reviewsNumber of critical suppliers and contract re-papering€3,000–€30,000Annual cycle
Security lead (fractional CISO or in-house)Fractional at €1,500–€3,000 per month; in-house €80,000+€18,000–€120,000 per yearRecurring
Testing (penetration test, effectiveness assessment)Number of external services and applications€5,000–€40,000 per yearRecurring
Supervisory audit ordered under Article 32Essential entities only, at the authority’s discretion€10,000–€50,000 when triggeredContingent
Typical ranges from published 2026 guidance by EU consultancies and managed security providers. Treat every figure as a planning range, not a price.

Notice which rows dominate. Documentation and consultancy are where a first-time entity overspends, because they scale with how much you outsource rather than with your risk. Technical controls and detection are where the money has to go, and they recur. A budget that is 70% consultancy and 30% controls usually means the project has been framed as paperwork.

NIS2 compliance cost by organisation size

Headcount is a rough proxy, but it is the one every budget conversation starts with. The scenarios below assume an entity that is not already ISO 27001 certified; the following section explains why that changes the numbers.

ScenarioTypical first-year cost (EUR)Typical ongoing cost per yearMain driver
Important entity, 50–100 staff, basics already in place (MFA, tested backups, some written policies)€25,000–€60,000€10,000–€25,000Filling policy and evidence gaps; incident reporting readiness
Important entity, 100–250 staff, moderate gaps€50,000–€120,000€20,000–€45,000Detection and response tooling; supplier reviews
Essential entity, 250+ staff or a high-criticality sector€150,000–€500,000+€60,000–€200,000+Segmentation, 24/7 monitoring, ex ante supervision, multiple sites
Digital infrastructure or managed service provider of any sizeAdd 20–40% to the row above that matches youSame upliftImplementing Regulation (EU) 2024/2690 prescribes the technical measures and incident thresholds in detail
Planning ranges, aggregated from 2026 published guidance. Compare them with the German government’s per-entity averages above: important ≈ €81,500 a year, essential ≈ €204,000 a year.

The uplift in the last row is real. Providers of DNS, cloud, data centre, CDN, managed and managed security services, marketplaces, search engines, social platforms and trust services do not get to argue proportionality control by control — the Commission’s Implementing Regulation of 17 October 2024 tells them what the measures are and when an incident counts as significant. Less discretion means more mandatory spend.

Essential vs important entities: what changes the bill

Both entity types owe the same Article 21 measures and the same Article 23 reporting duties. The cost difference comes from enforcement, not from the checklist. Our guide to who NIS2 applies to walks through the classification; the table below shows why it matters financially.

Essential entityImportant entity
SupervisionEx ante — regular and targeted audits, random checks (Article 32)Ex post — only on evidence or indication of non-compliance (Article 33)
Who pays for an ordered auditThe entity, unless the authority decides otherwiseSame rule, but audits are far less frequent
Maximum fine (Article 34)At least €10,000,000 or 2% of worldwide annual turnover, whichever is higherAt least €7,000,000 or 1.4%, whichever is higher
Evidence you must keep readyContinuous — expect to produce it without noticeOn request — but the same evidence, so build it anyway
Budget implicationRecurring audit-readiness cost; the German bill assumes roughly 2.5× the annual effort of an important entityLower recurring cost, same one-off build

The practical rule: an important entity can phase its spend across two budget years. An essential entity cannot, because a regular audit can land in year one.

Where an ISO 27001 ISMS cuts the NIS2 compliance cost

Article 21(1) points to “relevant European and international standards” as a yardstick for proportionality, and in practice that means ISO/IEC 27001. If you already hold a certificate with a scope that covers the NIS2-relevant systems, most of the one-off build is done: risk assessment, policy set, supplier security, access control, incident management and management review already exist as controlled documents with audit history. The remaining NIS2 compliance cost is usually a mapping exercise, the Article 23 reporting workflow with its 24-hour and 72-hour clocks, management-body training, and any technical measures your Statement of Applicability excluded.

Typical experience is that an existing ISO 27001 ISMS removes somewhere between a third and a half of first-year spend for an important entity, mostly from the gap assessment, documentation and consultancy rows. Our comparison of NIS2 vs ISO 27001 maps the ten Article 21 measures to Annex A, and our breakdown of ISO 27001 certification cost shows what the certificate itself costs if you are weighing both.

Two warnings. First, NIS2 does not require ISO 27001, and a certificate is not a defence on its own; the authority supervises the measures, not the badge. Second, Article 24 lets Member States require certified ICT products or services under EU cybersecurity certification schemes for particular requirements — if your national act uses that option, procurement gets more expensive regardless of your ISMS.

The cost of getting NIS2 wrong

The fines are the headline, but they are rarely the first consequence. Under Article 20 the management body must approve the risk-management measures, oversee their implementation and can be held liable for breaches; members must also complete training themselves. Our guide to NIS2 management liability covers the three duties in detail. For a supervisor, the cheapest enforcement tools are binding instructions, deadlines and public notices — and each of those forces spend on the supervisor’s timetable rather than yours.

One development to watch without budgeting on it: on 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of a wider cybersecurity package, including a new “small mid-cap” category intended to reduce burden for around 22,500 companies. It is a proposal. Until it is adopted and transposed, the obligations you are costing are the ones in Directive (EU) 2022/2555 and your national act.

How to reduce your NIS2 compliance cost honestly

  • Classify yourself before you spend. Essential vs important, and whether you fall under the digital infrastructure implementing regulation, changes the budget by a multiple. Get that answer in writing from counsel or your authority’s guidance first.
  • Scope the systems, not the company. NIS2 measures apply to the network and information systems used for your operations and services. Segmenting a legacy estate out of the critical path is often cheaper than securing it to the same standard.
  • Start from templates for the documentation layer. Policies, registers, incident forms and training records look much the same in every important entity. Paying consultancy day rates to draft them is the most avoidable line in the table.
  • Buy detection as a service. A 100-person entity almost never gets value from building a SOC. An MDR contract turns a capital project into a predictable recurring line and covers the 24-hour early warning duty in practice.
  • Reuse what you already report. If DORA, GDPR breach notification or a sector regulator already has you reporting incidents, build one process and map the clocks. Our note on DORA vs NIS2 explains how financial entities avoid paying twice.

What does not work is treating NIS2 as a document project. Policies with no working MFA, no tested backups and no log retention behind them cost money and satisfy nobody.

NIS2 compliance cost FAQ

Is there a NIS2 certification fee?

No. NIS2 has no certification and no certification bodies. Registration with your national competent authority is an administrative duty, not a paid service. Every cost is internal spend, consultancy or tooling, plus any audit a supervisor orders.

How much does NIS2 compliance cost for a 100-person company?

For an important entity with the basics in place, typical published 2026 ranges land between €25,000 and €60,000 in the first year and €10,000 to €25,000 a year after that. With significant gaps, or if you are an essential entity, budget €50,000 to €120,000 in year one. The German government’s bill assumed an average of about €81,500 a year across all important entities, which includes much larger firms.

Does ISO 27001 certification satisfy NIS2?

Not on its own. NIS2 references international standards as a proportionality benchmark, and an ISO 27001 ISMS covers most of the Article 21 measures, but the authority supervises the measures, not the certificate. Expect to add the Article 23 reporting workflow, management-body training and any controls your scope excluded.

What is the ongoing NIS2 compliance cost after year one?

Typically 30–40% of first-year spend for an important entity, driven by monitoring, testing, training and supplier reviews. Essential entities should assume a higher recurring share because ex ante supervision means audit-readiness is continuous.

Can a supervisor make us pay for an audit?

Yes, for essential entities. Article 32 provides that the cost of a targeted security audit carried out by an independent body is paid by the audited entity unless the authority decides otherwise in a duly substantiated case.

Where this leaves you

Budget the NIS2 compliance cost as three things: a one-off build that is mostly documentation, assessment and control gaps; a recurring operating line that is mostly detection, testing and training; and a contingent line for supervision and incident response that essential entities cannot ignore. The first is where most organisations overspend. The second is where the money has to go.

If the documentation build is what is slowing you down, our NIS2 Toolkit gives you 75+ editable templates covering the Article 21 policy set, the scope and registration document, the significant incident reporting form and the management records, for $99. It will not run your SOC, but it removes the most avoidable row in the table above.

Start with the obligations. Our guides to NIS2 requirements and NIS2 penalties and deadlines cover what you are buying compliance with, and what it costs not to.

References

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.