What Does NIS2 Cost?
Key Takeaways
- NIS2 fines reach EUR 10 million for essential entities and EUR 7 million for important entities. Under Germany's implementation, the turnover-based alternative of 2 percent or 1.4 percent only applies to entities with more than EUR 500 million in total turnover.
- The German government estimates the compliance burden on business at roughly EUR 2.2 billion one-time and EUR 2.3 billion annually (BR-Drs. 369/25, August 15, 2025). Spread across the approximately 29,500 affected entities, that works out to about EUR 75,000 one-time and EUR 78,000 per year each.
- The recurring cost exceeds the initial implementation cost. NIS2 is a permanent line item, not a project with an end date.
- Management liability under § 38 BSIG runs only internally, toward the entity itself, and applies subsidiarily to company law. The waiver prohibition contained in earlier drafts is not in the enacted statute.
NIS2 creates two separate cost blocks: implementing it, and the risk of not implementing it. On the implementation side, the German government puts the figure at roughly EUR 75,000 one-time and EUR 78,000 annually per affected entity (a calculated average derived from BR-Drs. 369/25). Smaller entities with an existing security baseline land well below that, while large groups and operators of critical installations land well above. On the risk side sit fines of up to EUR 10 million, although the violations that occur most often in practice, such as a missed registration with the supervisory authority, fall into lower brackets of EUR 500,000. In both cases the most expensive item is rarely the technology. It is the people, and the evidence that the measures work continuously.
How much are the fines for NIS2 violations?
NIS2 is a directive, so the fines you actually face are set by your country's transposition, not by the directive itself. Article 34 of Directive (EU) 2022/2555 sets the floors: at least EUR 10 million or 2 percent of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4 percent for important entities, whichever is higher. Germany transposed this in the BSIG as amended by the NIS2 Implementation Act (published as BGBl. 2025 I No. 301, in force since December 6, 2025), and § 65 BSIG tiers the fines by the type of violation. The widely quoted EUR 10 million is the ceiling for the most serious breaches, not the standard case.
| Maximum fine | Obligations covered (selection) |
|---|---|
| EUR 10 million (essential entities) / EUR 7 million (important entities) | Risk-management measures under § 30, reporting obligations under § 32 |
| EUR 5 million | Violations under § 65 (2) no. 11 |
| EUR 2 million | Failure to comply with an enforceable order from the supervisory authority |
| EUR 1 million | Evidence obligations for operators of critical installations under § 39 |
| EUR 500,000 | Registration obligation under § 33 (missing, incorrect, incomplete, or late) |
| EUR 100,000 | Failure to keep the contact point reachable under § 33 (2) sentence 2 |
Source: § 65 (5) BSIG, version of December 2, 2025. Verified August 2026.
When does the 2 percent rule actually apply?
This is where German law departs from the directive, and where most published summaries get it wrong. Article 34 NIS2 uses the formula "whichever is higher." § 65 BSIG does not. The turnover variant of 2 percent (§ 65 (6)) and 1.4 percent (§ 65 (7)) applies expressly only to entities with total turnover above EUR 500 million, and it then replaces the fixed amount rather than competing with it. For a company with EUR 80 million in revenue, the governing ceiling is therefore the fixed amount, not 2 percent of turnover. The relevant figure is the worldwide total turnover of the undertaking the entity belongs to, and it may be estimated (§ 65 (8)). If you operate in several member states, check each transposition separately. The directive sets floors, and national legislators are free to go above them.
How much does NIS2 implementation cost per company?
The most defensible public figure comes from the regulatory impact assessment in the German government bill. It describes an average across very different entities, which makes it a useful budget anchor and a poor planning basis for any individual case.
| Item | One-time | Annual |
|---|---|---|
| Business, total | approx. EUR 2.2 billion | approx. EUR 2.3 billion |
| Per entity (calculated, across approx. 29,500 affected entities) | approx. EUR 75,000 | approx. EUR 78,000 |
| Federal government | EUR 63 million | EUR 119 million |
| Federal states | not stated | EUR 166,000 |
Source: German government bill, BR-Drs. 369/25 of August 15, 2025, explanatory memorandum section E. Number of affected entities: approximately 29,500 companies and federal administration bodies, per the German supervisory authority (as of December 2025). The per-entity values are derived by us from both sources and appear in neither.
Which cost components does NIS2 actually create?
The total is less useful than its components, because the components move independently of one another. The ranges below are market orientation figures for the German and wider EU market as of August 2026. They are not a survey.
| Cost component | Orientation | What drives it |
|---|---|---|
| In-house information security officer | EUR 80,000 to 120,000 per year, fully loaded | Availability in the labor market |
| External ISO or CISO mandate | EUR 1,500 to 3,000 per month | Scope and response times |
| External consulting | EUR 1,000 to 2,000 per day | Maturity at project start |
| Technical measures (MFA, segmentation, backup, logging) | Highly dependent on starting point | Legacy systems, sites, OT environments |
| Training for management and staff | EUR 200 to 500 per person per year | Mandatory under § 38 (3) BSIG |
| Supply chain security | Recurring, scales with the number of critical suppliers | Art. 21 (2)(d) NIS2, § 30 (2) no. 4 BSIG |
| Evidence and documentation | The most consistently underestimated item | Review cycles, audit readiness |
Article 21 (2) NIS2 sets out ten minimum measures, mirrored in § 30 (2) BSIG: risk analysis, incident handling, business continuity, supply chain security, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication. The effort is distributed very unevenly. If you already run backup and MFA properly, most of your spend goes to evidence and governance.
What does NIS2 cost on an ongoing basis, after go-live?
More than the initial implementation. That is the most important and least frequently stated fact about NIS2 costs. The German impact assessment explicitly shows a higher recurring figure, EUR 2.3 billion annually, than one-time figure, EUR 2.2 billion. The drivers are the reporting cascade under Article 23 NIS2 and § 32 BSIG (24-hour early warning, 72-hour notification, and a final report after 30 days), the on-call capacity that cascade requires, recurring training, ongoing supplier management, and continuous upkeep of evidence. Operators of critical installations additionally carry the cost of security audits, inspections, or certifications every three years under § 39 BSIG. Contrary to a common claim, that periodic evidence obligation does not apply to all essential entities. It applies to operators of critical installations.
Are managing directors personally liable, and what does that cost?
The answer is more sober than the widespread warnings about liability with personal assets suggest. § 38 (1) BSIG obliges management to implement the risk-management measures under § 30 and to supervise their implementation. The German statute says implement, not approve, which goes beyond the wording of Article 20 NIS2. § 38 (2) establishes liability toward the entity itself under the company law applicable to its legal form, and applies expressly on a subsidiary basis, meaning only where company law contains no liability rule of its own. For a GmbH or an AG, § 43 GmbHG and § 93 AktG therefore govern, not the BSIG.
Two points are frequently misreported. First, the prohibition on waiving or settling damages claims that appeared in earlier drafts is not in the enacted statute. Second, the fine brackets in § 65 are addressed to the entity and run through corporate liability under § 30 OWiG. The BSIG provides no separate fine bracket against individual managers. What does remain is the personal training obligation under § 38 (3), for which the statute prescribes no interval and no proof, only regularity. This section is a professional assessment and does not constitute legal advice.
How much does an existing ISO 27001 ISMS reduce NIS2 costs?
Considerably, but not entirely. If you run a certified ISMS, risk analysis, access control, cryptography, supplier management, and business continuity already exist as managed processes and do not need to be built from scratch. The remaining gap typically sits in the NIS2-specific obligations: registration with the supervisory authority, the reporting cascade with its 24-hour early warning, the management training obligation, and, depending on classification, the evidence obligation. One caveat matters: an ISO 27001 certification does not automatically satisfy § 30 BSIG. It shortens the path. It does not replace assessment against the ten measure categories.
What does it cost to ignore NIS2?
In Germany, the registration deadline under § 33 BSIG has already passed. As of June 30, 2026, 17,945 entities had registered, of which 6,215 were essential and 11,501 important entities. Measured against the roughly 29,500 entities expected to be in scope, a substantial share is still missing. A missed or incomplete registration is an administrative offense carrying a bracket of up to EUR 500,000, and supervisory and enforcement powers apply regardless of whether an entity has registered. The second and, in practice, larger item is the incident itself. The German government bill assumes roughly EUR 250,000 in damage avoided per affected company per year in its cost-benefit calculation.
How does Kertos reduce NIS2 costs?
The cost driver in NIS2 is not the one-time rollout. It is the permanent obligation to evidence. That is where Kertos works. The agentic platform KAIA collects the current state through more than 100 integrations, maps it to the ten measure categories under Article 21 NIS2 and § 30 BSIG, and keeps the evidence current continuously instead of reassembling it before every review. In parallel, certified Kertos experts handle what software cannot, including external CISO and DPO mandates, management training, and building out the reporting cascade. Companies covering NIS2 alongside ISO 27001, ISO 27701, ISO 42001, GDPR, the EU AI Act, SOC 2, TISAX, or C5 maintain each control once rather than repeatedly. Practical starting points: check whether NIS2 applies to you, automate NIS2 compliance, and common NIS2 misconceptions.
Kertos is built in Germany and runs on European infrastructure. Companies working with Kertos see up to 60 percent lower costs than with traditional consulting and around 80 percent less manual compliance effort, with a 100 percent audit pass rate and 98 percent customer satisfaction.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.

