What does NIS2 implementation cost on average?
Germany's NIS2UmsuCG impact assessment projects about €70,000 one-off and €73,000 annually per affected company — an average across roughly 30,000 very different entities.
Cost & effort calculator
The honest answer: it depends on three factors you can determine in two minutes — classification, size and starting point. This free calculator turns them into a reasoned range instead of a sales number.
Estimate in under 2 minutes what NIS2 implementation will realistically cost you — as a reasoned range based on scope, size, starting point and implementation path. No sign-up, no data leaving your browser.
Basis: NIS2UmsuCG impact assessment, ENISA NIS Investments 2025, DACH market rates · assumptions open as JSON
Your §28 BSIG classification sets supervision and evidence depth — and with it, the cost.
| Cost item | Guide value |
|---|---|
| Ø one-off per company (official estimate) | ~€70,000 |
| Ø annual per company (official estimate) | ~€73,000 |
| SME (50–250 employees), one-off | ~€20,000–150,000 depending on starting point |
| NIS2 consulting, day rate | €1,000–2,000 |
| NIS2/ISMS software licence | ~€350–1,800 per month by size |
| NIS2 gap-closing with an existing ISO 27001 ISMS | ~€20,000–50,000 |
| ISO 27001 certification (SME, first year total) | ~€50,000–150,000 |
| Ongoing costs | typically 20–30% of the initial investment per year |
First, classification: essential entities carry roughly a third more effort through proactive BSI supervision and evidence depth; companies affected only via the supply chain mainly need a lean evidence package. Second, size: more systems, sites and people to train. Third — the biggest lever — your starting point: with an ISO 27001 ISMS in place, closing the NIS2 gaps (reporting, BSI registration, supply chain) costs about €20,000–50,000. If MFA, backup and patch management already run in your Microsoft 365 environment, much of the evidence exists — what's missing is structure, not technology.
Market day rates run €1,000–2,000. Over a guided six-to-twelve-month project that quickly adds up to five- or six-figure fees — the largest single item in many NIS2 budgets. Consulting is worth it for judgement work: legal edge cases, sector-specific interpretation, building an ISMS from scratch. It is not worth it for repeatable evidence work — clarifying scope, capturing measure status, structuring evidence. Doing that groundwork yourself often halves the consulting days you need.
First things first: there is no software requirement. §30 BSIG is technology-neutral — it demands measures and evidence, not a particular product. If you do adopt an ISMS or GRC platform, SMEs typically pay €350–600 per month for starter packages and €800–1,800 per month in the 50–250 employee class; enterprise GRC reaches five-figure annual sums. Honestly assessed, every licence decision should start with what your existing Microsoft 365 environment already delivers — often more than the vendor comparison suggests.
| Self + targeted consulting | Platform-supported | Consultant-led | |
|---|---|---|---|
| External costs | low — consulting days for edge cases only | medium — licence plus setup | high — day rates over months |
| Internal effort | highest | medium | medium — the groundwork stays with you |
| Ongoing costs | internal, low | licence from ~€4,000/year | follow-up engagements are common |
| Suited for | SMEs with a solid IT baseline | mid-sized firms without ISMS experience | edge cases, ISMS build from scratch |
Fines up to €10m or 2% of global annual turnover and personal management liability under §38 BSIG are real — but no reason for panic buying. The impact assessment itself calculates that the effort is offset many times over by avoided damage. The goal is not the biggest possible project but provable effect: measures that work and evidence that stays current. That can be planned — and far more cheaply when the groundwork is right.
Germany's NIS2UmsuCG impact assessment projects about €70,000 one-off and €73,000 annually per affected company — an average across roughly 30,000 very different entities.
Realistically €20,000–150,000 one-off, depending on the starting point: with an existing ISMS only the gap-closing remains (~€20,000–50,000); with a solid Microsoft 365 baseline it's mainly structuring existing evidence. Ongoing costs typically run 20–30% of the initial investment per year.
Typically €1,000–2,000 per day. Consulting pays off for edge cases and ISMS builds — not for repeatable evidence work you can do yourself.
No. §30 BSIG is technology-neutral — there is no software requirement. If you adopt a platform, SMEs typically pay €350–1,800 per month; first check what your Microsoft 365 environment already covers.
If you're already certified, closing the NIS2 gaps costs about €20,000–50,000. Without an existing ISMS, certification is no shortcut: for SMEs the first year totals roughly €50,000–150,000 — and NIS2-specific duties such as reporting and registration come on top.