The NIS2 ROI Model in 3 Scenarios: Why the EUR 10M Fine Is the Weakest Line in Your Business Case
Most NIS2 budget papers open with the same slide: a EUR 10 million penalty ceiling next to a compliance budget one-twentieth its size. The ratio looks unanswerable. It gets rejected anyway, because a CFO reads that slide as a probability claim — and the probability it silently asserts is 100%.
An expected-value model fixes that. It splits the benefit side into three lines that can each be estimated, argued about and revised: the regulatory exposure you avoid, the incident cost you avoid, and the revenue you retain. Run honestly, the fine line usually turns out to be the smallest of the three — and the case becomes more persuasive the moment you say so out loud. There is a second reason to build it: Article 21(1) requires measures that are “appropriate and proportionate” and lists “the cost of implementation” among the factors deciding what proportionate means. A documented ROI model is the working paper behind that judgement.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
The Arithmetic Mistake in Almost Every NIS2 Budget Paper
In plain terms: a maximum fine is a ceiling, not a forecast. Comparing it to a budget multiplies it by an unstated probability of one, and everyone in the room knows that number is wrong.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The ceilings themselves are not in dispute. Article 34 sets floors that Member States may exceed but not undercut [1]:
| Entity class | Fixed ceiling (minimum) | Turnover alternative | Which applies |
|---|---|---|---|
| Essential | EUR 10,000,000 | 2% of total worldwide annual turnover | “whichever is higher” |
| Important | EUR 7,000,000 | 1.4% of total worldwide annual turnover | “whichever is higher” |
Article 34(6) adds that Member States may impose periodic penalty payments to force an ongoing infringement to stop [1]. The full sanction structure, including national variations, is set out in our guide to NIS2 penalties, fines and management liability.
What none of that gives you is the expected cost of non-compliance, which is the only figure a capital allocation decision can use. Expected cost is the ceiling multiplied by the chance of being examined, by the chance an examination finds something material, by the fraction of the ceiling a proportionate fine would actually represent. Each multiplier sits well below one, and their product usually lands two orders of magnitude below the headline.
There is also a ceiling on how large the ask can defensibly be. Lawrence Gordon and Martin Loeb showed in The Economics of Information Security Investment (ACM TISSEC, 2002) that it is generally uneconomical to spend more than 37% of the expected loss on preventing it [7]. They derived that for the expected loss from a breach; applying it to a composite figure carrying regulatory and commercial exposure too is an extension of their framing, not their published result. Used that way it remains the fastest sanity check available — if the programme costs more than roughly a third of the annual expected loss it addresses, the scope is wrong before the negotiation starts.
Set Your Inputs First: Essential or Important Changes the Odds, Not the Ceiling
In plain terms: the probability of ever being examined is not a guess you make. It is written into the supervision articles, and it differs by entity class.
For essential entities, Article 32(2) empowers competent authorities to apply “regular and targeted security audits carried out by an independent body or a competent authority”, alongside on-site inspections, random checks and security scans [2]. Regular means recurring, without a trigger. For important entities, Article 33(1) starts the clock elsewhere: authorities act “where necessary, through ex post supervisory measures” once they receive “evidence, indication or information that an important entity allegedly does not comply” [3]. Article 33(2)(b) gives them targeted security audits — the word regular is absent. Supervision is conditional on a trigger: an incident report, a complaint, a sector sweep, a customer escalation.
| Input | Essential entity | Important entity |
|---|---|---|
| Supervision regime | Proactive (Art. 32) | Ex post, on trigger (Art. 33) |
| Audit language in the Directive | “regular and targeted security audits” | “targeted security audits” |
| Reasonable probability input | High over a multi-year window; approaches certainty for regulated critical installations | Driven by your own incident and complaint history |
| What lowers it | Nothing you control | Fewer reportable incidents, cleaner customer relationships |
National law sharpens this. Germany’s BSI, the national competent authority, states in its NIS-2 FAQ that most entities supply evidence only “auf Anfrage im Falle einer Anordnung durch das BSI” — on request, following an order. Operators of critical installations are the exception: they “müssen auch ohne Aufforderung Nachweise in Form von Sicherheitsaudits, Prüfungen oder Zertifizierungen einreichen”, on a cycle that has moved “von zwei auf drei Jahre” [10]. For that population the probability input is not a probability at all. It is a calendar. The same page confirms there is no general NIS2 certificate (“Ein allgemeines Zertifikat zum Nachweis der Anforderungen gibt es nicht”) — worth knowing when someone proposes certification as the cheap route to the same outcome.
Our guide to NIS2 supervisory measures covers the full essential-versus-important power split. For the model, three inputs are enough: your class, your national evidence duty, and your own five-year history of reportable events.
Scenario A: The Fine You Avoid, Priced Honestly
Write the line as a product, not a ceiling:
Expected annual regulatory cost = P(supervisory event) × P(material finding | event) × expected fine given a finding
Take a worked example and carry it through: an essential entity with EUR 180 million turnover, 600 staff and an IT budget of EUR 9 million. Its Article 34(4) ceiling is EUR 10 million, because 2% of turnover is only EUR 3.6 million and the higher figure governs [1].
| Input | Illustrative value | Where the number comes from |
|---|---|---|
| P(supervisory event per year) | 20% | Art. 32(2)(b) regular audits, spread across a three-year cycle |
| P(material finding, given an event) | 40% | Your own gap analysis result, expressed as a probability |
| Expected fine, given a material finding | EUR 250,000 | Placeholder: a proportionate first-instance sanction, far below the ceiling |
| Expected annual regulatory cost | EUR 20,000 | 0.20 × 0.40 × 250,000 |
Twenty thousand euros. Against a programme costing tens of times that, this line loses the argument on its own — which is precisely why leading with it costs you the room. The third input is the softest of the three: there is no systematic public register of NIS2 fines to calibrate against, so treat it as a parameter counsel sets and finance stress-tests, not as a researched figure.
The regulatory line has a tail no fine ceiling captures, and it belongs in the paper as a stated risk rather than a number. If softer enforcement measures fail and a remedy deadline passes, Article 32(5) allows temporary suspension of “a certification or authorisation concerning part or all of the relevant services”, and a temporary prohibition on any person “responsible for discharging managerial responsibilities at chief executive officer or legal representative level” from exercising managerial functions [2]. Those are uncapped in financial terms and unavailable to insurance. Article 20(1) separately requires management bodies to approve the Article 21 measures, oversee implementation, and states they “can be held liable for infringements by the entities of that Article” [5] — a personal exposure sitting on the same people who approve the budget.
That is the fine line priced honestly, and it is deliberately the smallest of the three. For the full picture of what non-compliance actually bills you — the Article 34 fine alongside personal liability under Articles 20(1) and 32(6), lost contracts, and disclosure ordered under Articles 32(4)(h) and 23(7) — see our breakdown of the four costs of NIS2 non-compliance.
Scenario B: The Incident Cost You Avoid, Without Inflating It
In plain terms: take published breach averages as an upper anchor for a large organisation, then adjust twice — once for your size and sector, once for the share of the risk your programme actually removes.
IBM’s Cost of a Data Breach Report 2026, released on 29 July 2026 and covering 602 organisations breached between March 2025 and February 2026, puts the global average at USD 4.99 million, a 12% year-on-year rise, with healthcare at USD 6.6 million, financial services at USD 6.3 million, and industrial and technology at USD 5.5 million each [6].
Two errors follow from dropping that number straight into a model. The first is treating a global, cross-size average as an estimate for one mid-market European entity; the average is pulled upward by large organisations and US cost structures. The second, more damaging in a CFO review, is implying the programme removes the entire loss. It does not — it buys a reduction in a probability and a reduction in severity. The honest form of the line makes that explicit:
Expected annual incident cost avoided = P(significant incident) × expected cost of that incident × the share of that expected loss the programme removes
For the sector adjustment, ENISA’s Threat Landscape 2025 analysed 4,875 incidents between July 2024 and June 2025 and found that 53.7% concerned essential entities as defined by NIS2, with public administration most targeted at 38.2%, ahead of transport (7.5%), digital infrastructure and services (4.8%), finance (4.5%) and manufacturing (2.9%) [9]. Those shares describe where incidents land, not your individual likelihood — use them to argue a direction of adjustment against your own history, never as a probability in their own right.
Carrying the worked example forward: a 12% annual chance of a significant incident, an expected cost of EUR 2.2 million at this size, and a 30% reduction attributable to the programme gives EUR 79,200 a year. Nearly four times the regulatory line, and still not the largest. The cost cascade behind that EUR 2.2 million — response, regulatory, commercial and downtime layers — is broken down in our NIS2 investment case analysis.
Gordon and Loeb’s second finding is worth applying while setting that reduction share: optimal spending does not rise indefinitely with vulnerability, so if your 30% is being bought almost entirely in the hardest corner of the estate, the same spend redirected will usually buy more [7].
Scenario C: The Revenue You Retain, Which Is Usually the Biggest Line
In plain terms: your customers are under a legal obligation to assess you. That turns security posture from a risk topic into a revenue topic — and revenue is the one line a CFO can verify from the pipeline.
Article 21(2)(d) requires entities to manage “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”, and Article 21(3) obliges them to take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers” [4]. Every in-scope customer you serve carries that duty toward you. The questionnaire, the audit clause and the notification flow-down are not procurement fashion — they are how your customer discharges Article 21(3).
The pressure is measurable. ENISA’s NIS Investments 2025 report, surveying 1,080 professionals across all 27 Member States, found supply-chain risk among the three hardest NIS2 areas to implement (37%), and supply chain and third-party compromise the second most cited future concern (47%) [8]. Entities struggling with their own supplier assurance push that burden outward, contractually.
Price the line from your own contract base:
- Revenue subject to security clauses. Pull contracts containing security schedules, audit rights or incident-notification obligations. In the worked example, EUR 55 million of EUR 180 million.
- Annual probability of loss or non-renewal on assurance grounds, absent the programme. Take it from your own tender and renewal history, not a benchmark. Illustrative: 4%.
- Convert to contribution, not revenue. Lost revenue is not lost profit. At a 35% contribution margin, EUR 55m × 4% × 35% is EUR 770,000 of contribution at risk annually.
- Attribute honestly. The programme addresses most, not all, of that exposure. At 70% attribution, the line is EUR 539,000.
This line survives challenge better than the other two because every input is auditable inside the business: sales confirms the contract base, finance owns the margin, and renewal history is a matter of record. It also reframes the spend from a levy into a condition of trading, which is the framing that gets budget approved.
Putting the Three Lines on One Page
| Scenario | Annual expected value | Confidence in the inputs | Who can challenge it |
|---|---|---|---|
| A — Regulatory exposure avoided | EUR 20,000 | Low (no public fine register to calibrate against) | Legal |
| B — Incident cost avoided | EUR 79,200 | Medium (published averages, self-assessed reduction) | CISO, risk |
| C — Revenue retained | EUR 539,000 | High (internal contract and renewal data) | Sales, finance |
| Total annual expected benefit | EUR 638,200 | — | — |
Against a EUR 600,000 first-year programme and a EUR 180,000 annual run rate, three-year benefits of roughly EUR 1.91 million sit against roughly EUR 960,000 of cost: a shade under 2:1. That is a defensible number. The 15:1 ratios produced by dividing a penalty ceiling by a budget are not, and a finance director who has seen one discounts everything that follows.
Then run the Gordon-Loeb check in reverse. Gross annual expected loss across the three scenarios — before any attribution or reduction factor — is roughly EUR 1.05 million for this entity. Thirty-seven per cent of that is about EUR 390,000; the three-year average annual spend is EUR 320,000 [7]. The ask sits under the ceiling, which is a useful thing to be able to say before anyone else calculates it.
For the cost side, ENISA’s benchmark is the cleanest available: cybersecurity investment across surveyed organisations sits at roughly 9% of IT budgets, median EUR 1.5 million, with 70% naming regulatory compliance as the main driver of that spend [8]. Nine per cent of the worked example’s EUR 9 million IT budget is EUR 810,000 — so a EUR 600,000 uplift is a step change, not a rounding adjustment, and should be presented as one. Detailed figures for the cost side are in our 2026 NIS2 compliance cost breakdown.
| Role | What to take from this model |
|---|---|
| CISO / IT security manager | Own Scenario B. Defend the reduction share control by control; that single percentage carries the whole line. |
| CFO / finance | Own the margin and discount assumptions. Insist the three lines carry separate confidence levels rather than being summed into one figure. |
| Compliance officer | Own the assumptions register. It is the audit trail for the proportionality judgement, not just a working file. |
| Board / management body | Approve the model, not just the number. Article 20(1) makes approval of the Article 21 measures your documented act. |
The Model Is Also Your Article 21(1) Evidence
Article 21(1) requires “appropriate and proportionate technical, operational and organisational measures”, and states the assessment shall take into account “the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact”, as well as “the cost of implementation” [4]. Read that list against the model: exposure, size, likelihood, severity and cost are the five inputs the three scenarios are built from.
An organisation that has priced those inputs, written down where each number came from and had the management body approve the result holds something close to a direct answer to the question a supervisor asks when a control is missing — why did you decide this was proportionate? It does not make the organisation compliant, and the model should never be presented as proof that it is. Proportionality is assessed against the measures actually implemented, and a competent authority is not bound by an entity’s own economic reasoning. What the model evidences is that the judgement was made deliberately, on stated assumptions, at a known date, which is a materially better position than a decision nobody can reconstruct.
Keep four things where an auditor can find them: the assumptions register with a source and date per input; the version of the model that was approved; the minute recording management body approval under Article 20(1); and the review date. Article 20(2) also requires management body members to follow training — while only encouraging entities to offer similar training to employees on a regular basis [5] — so the same file is where you evidence that the people approving the model were equipped to read it. Our guides to Article 20 governing body obligations and NIS2 risk assessment cover the surrounding documentation.
Where to Start
Build Scenario C first, even though it comes last in the logic. It uses data you already hold, it produces the largest number, and it changes how the room hears the other two. Add Scenario B once your gap analysis can support a defensible reduction share. Add Scenario A last, present it as the smallest line, and say plainly that it is the smallest — the credibility that buys is worth more than the number itself.
Frequently Asked Questions
What time horizon should a NIS2 ROI model use?
Three years is the practical default. It matches the length of most compliance programmes, smooths the year-one capital spike against the run rate, and in Germany lines up with the three-year evidence cycle the BSI applies to operators of critical installations [10]. Anything longer invites technology-refresh arguments that have nothing to do with the compliance decision.
Can I use IBM’s average breach cost directly as my Scenario B input?
Not without adjustment. The USD 4.99 million global average covers 602 organisations across all sizes and regions and is pulled upward by large enterprises and US cost structures [6]. Use it as an upper anchor, scale it to your revenue, headcount and data sensitivity, then apply a reduction share for what the programme actually removes.
We are an important entity, not essential. Does the model still work?
Yes, with two shifts. Scenario A shrinks, because Article 33 supervision is ex post and trigger-driven rather than regular [3]. Scenario C often grows, because important entities are more likely to sit inside somebody else’s supply chain and to face the Article 21(3) assessment duty from the customer side [4]. Run both changes; the total moves less than people expect.
Does a positive ROI model prove our measures are proportionate under Article 21(1)?
No. It evidences that a proportionality judgement was made on stated assumptions at a known date. The assessment itself is made against the measures implemented, and a competent authority reaches its own view. Treat the model as supporting documentation, never as a compliance conclusion.
Sources
- Directive (EU) 2022/2555, Article 34 — General conditions for imposing administrative fines.
- Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures in relation to essential entities.
- Directive (EU) 2022/2555, Article 33 — Supervisory and enforcement measures in relation to important entities.
- Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures.
- Directive (EU) 2022/2555, Article 20 — Governance.
- IBM, Cost of a Data Breach Report 2026, published 29 July 2026 — as reported by Infosecurity Magazine, “The Average Cost of a Data Breach Rises to $5 Million” (linked above).
- Lawrence A. Gordon and Martin P. Loeb, “The Economics of Information Security Investment”, ACM Transactions on Information and System Security, November 2002, pp. 438–457 — summarised by the Robert H. Smith School of Business, University of Maryland (linked above).
- ENISA, NIS Investments 2025 — Main Report, December 2025 (ISBN 978-92-9204-777-1), survey of 1,080 professionals across the 27 Member States (linked above).
- ENISA, Threat Landscape 2025 — 4,875 incidents analysed, July 2024 to June 2025 (linked above).
- BSI (Bundesamt für Sicherheit in der Informationstechnik), Fragen und Antworten zu NIS-2 — German national competent authority FAQ (linked above).
- Full consolidated text: Directive (EU) 2022/2555 on EUR-Lex.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
