Abstract network security visualization representing NIS2 incident handling infrastructure

NIS2 Incident Handling Cost: In-House SOC vs MSSP vs Hybrid Budgets (€39K–€735K+)

Article 21(2)(b) of the NIS2 Directive states the requirement for “incident handling” in three words [1]. It says nothing about what that costs. Ask five compliance consultants for a number and the answers swing between €15,000 and €500,000 — not because anyone is guessing, but because “incident handling” is really five separate cost lines: who staffs it, what tooling detects it, who you call when it’s bad, how you rehearse it, and how you document what you learned. This guide prices each one separately, in euros, so you can build a defensible budget instead of a placeholder number. It also answers the underlying question most searches for “nis2 incident response cost” are really asking: what does a compliant programme cost end to end, not just the software line item. A sourcing note: the sourcing, SIEM, and retainer figures below are industry pricing estimates originally published in US dollars; they are shown here at approximate EUR parity as a directional planning range, not an exact conversion — confirm current rates and get a formal quote before committing a budget line.

Who This Cost Guide Applies To

NIS2 splits regulated organisations into Essential and Important entities, both of which must meet the same Article 21(2)(b) incident-handling requirement — the difference is supervisory intensity and penalty ceiling, not the underlying obligation. The Directive is explicit that measures must be “appropriate and proportionate,” with cost of implementation, entity size, and risk exposure all factored into what “appropriate” means for your organisation [1]. That proportionality clause is why this guide uses ranges tied to organisation size rather than one number — a 60-person managed service provider and a 4,000-person energy operator are both in scope, and neither should be pricing against the other’s budget.

Organisation size Typical NIS2 status Incident-handling budget scales with
Small / lean Important entity (<250 staff) Important Entry-level MSSP or hybrid sourcing, open-source or bundled SIEM
Mid-market (250–1,000 staff) Essential or Important Full MSSP or hybrid sourcing, commercial SIEM at mid-tier ingest volume
Large / critical-sector (1,000+ staff) Essential In-house 24/7 SOC, enterprise SIEM, dedicated DFIR retainer

The exact euro figures for each size band are built up line-by-line in the sourcing, SIEM, retainer, and exercise sections below, then totalled in the budget synthesis table further down this page — not a Directive-mandated scale. Confirm your own status first against the site’s scope determination.

What “Incident Handling” Actually Costs

The three words in Article 21(2)(b) expand into a working obligation once Article 23 is read alongside it: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours with an initial severity and impact assessment, and a final report within one month [2]. Germany’s BSI — the competent authority responsible for supervising NIS2 entities under national law — translates that timeline into a resourcing instruction, telling regulated entities directly to “allocate sufficient budget and personnel for ongoing prevention, mitigation, and crisis management” and structures the obligation as five phases: prevention, detection, incident management, communication, and post-incident review [3]. Each phase carries its own cost driver — detection needs tooling, communication needs a rehearsed and pre-authorised process, and the 24-hour clock means someone has to be reachable outside business hours. None of that is optional once you’re in scope; what’s variable is who does it and how you tool it, which is where the real budget swings appear.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

A compliant incident-handling programme is, in practice, four separate purchases: a sourcing model (who detects and responds), a detection platform (what tells you something happened), a response capability (who handles the bad ones), and a rehearsal-and-review cycle (how you prove the first three actually work). The next four sections price each.

Sourcing Model Cost Tiers: In-House SOC vs MSSP vs Hybrid

For a CISO, the sourcing decision is a build-vs-buy staffing problem: a 24/7 in-house SOC needs a minimum of 4–5 analysts to cover shifts, holidays, and sick leave for round-the-clock coverage — fully loaded, that’s rarely under €350,000–€500,000/yr in Western Europe before tooling. For an SME owner, the same decision is simpler: can you afford a dedicated security hire at all, or does outsourcing the whole function to a managed security service provider (MSSP) make the 24-hour notification clock someone else’s problem contractually. Industry MSSP pricing tracks organisation size closely: small businesses typically pay €24,000–€84,000/yr for firewall management, endpoint monitoring, and basic incident response; mid-market organisations pay €84,000–€300,000/yr for 24/7 SOC monitoring, SIEM management, an incident response retainer, and compliance reporting bundled in; enterprise contracts run €300,000–€1,200,000+/yr and are individually negotiated [6]. A hybrid model — a small in-house team handling triage and vendor management during business hours, with an MSSP or retainer covering nights, weekends, and surge capacity — typically lands between the small and mid-market MSSP bands, because you’re paying for partial coverage on both sides rather than full coverage on either.

Model Typical annual cost Best fit
In-house SOC (24/7) €350,000–€500,000+ Large / critical-sector entities with existing security headcount
MSSP (full outsource) €24,000–€300,000 SMEs and mid-market entities without an internal SOC
Hybrid (in-house + retainer/MSSP) €60,000–€200,000 Mid-market entities with 1–2 security staff wanting after-hours coverage

Cost isn’t the only variable auditors and boards care about: IBM’s Cost of a Data Breach research found breaches contained within 200 days averaged €1.88M less than those that ran longer [5]. A cheaper sourcing model that detects slowly can cost more overall than a pricier one that catches incidents fast — factor detection speed into the sourcing decision, not just the invoice.

SIEM Cost Comparison: Splunk vs Microsoft Sentinel vs Open-Source

Whichever sourcing model you choose, someone needs a platform to aggregate logs and flag anomalies — in practice, the SIEM (Security Information and Event Management) tool that generates the evidence your incident-handling process runs on. At a representative 50GB/day ingest volume (typical for a few-hundred-employee organisation), Splunk Cloud plus its Enterprise Security add-on runs €110,000–€175,000/yr, while Microsoft Sentinel’s commitment-tier pricing runs €59,000–€78,000/yr for equivalent volume — Sentinel’s advantage comes partly from ingesting Microsoft 365 audit logs at no additional charge, which matters most for organisations already on Microsoft 365 [8]. Over a five-year horizon at the same volume, that gap compounds to roughly €1.13M for Splunk versus €709,000 for Sentinel [8]. Open-source platforms (Wazuh, Elastic Security’s free tier) remove the license fee entirely, but not the cost: a mid-market open-source SIEM deployment runs €104,000–€167,000 over three years in infrastructure, implementation, and training — against €1.4M–2.25M for an equivalent commercial three-year deployment — provided you already have, or hire, an engineer capable of tuning detection rules and running the indexer cluster [9]. That engineering dependency is the real cost of “free”: without it, false-positive rates climb and the tool stops doing the one job Article 21(2)(b) needs it for.

Platform Annual cost (~50GB/day) Main cost driver
Splunk Cloud + Enterprise Security €110,000–€175,000 Per-GB ingest license
Microsoft Sentinel €59,000–€78,000 Per-GB, discounted for Microsoft-heavy environments
Open-source (Wazuh / Elastic) €26,000–€47,000 (infra only) Dedicated engineering headcount, not license

For compliance officers building the audit trail, the platform choice matters less than retention and coverage: whichever SIEM you pick, it needs to retain enough log history to reconstruct a significant incident for the Article 23 final report a month after the fact [2].

Incident Response Retainer Costs

An IR retainer is a pre-negotiated contract with a digital forensics and incident response (DFIR) firm that guarantees a response SLA — typically 2–4 hours — and a discounted hourly rate, in exchange for an annual commitment fee. Industry pricing on retained engagements runs €175–400/hr, against €800–1,500/hr for emergency engagement with no retainer in place — roughly two to three times more expensive per hour [7]. Annual retainer fees range €10,000–€100,000/yr depending on the block of prepaid hours and response SLA, and that fee is typically credited against hours used if an incident occurs [7]. The arithmetic is straightforward: a single significant incident requiring, say, 80 hours of DFIR work costs roughly €64,000–120,000 on emergency rates versus €14,000–32,000 in billed hours plus the retainer fee under contract — which is why most mid-market and larger entities treat the retainer as a standing cost rather than an optional extra, not a nice-to-have. For an SME owner without the budget for a full retainer, the minimum viable version is a named point of contact at a DFIR firm with pre-agreed rates, even without a prepaid hour block — it still avoids the worst of the emergency-rate premium.

Tabletop Exercise Cost: Internal vs Consultant-Facilitated

BSI’s guidance treats crisis exercises as a standing expectation, not a one-off box to tick, recommending regular rehearsal of the incident-handling process rather than testing it for the first time during a real incident [3]. An internally facilitated tabletop — your own security or compliance lead running a scenario with department heads — costs mostly staff time: a half-day session for 8–12 participants runs roughly €3,000–€8,000 in loaded labour cost and produces limited value if the facilitator also wrote the incident response plan being tested, since the same blind spots tend to resurface. A consultant-facilitated exercise, run by an external DFIR or crisis-management specialist with no stake in the plan’s authorship, typically costs €8,000–€25,000 for a half- to full-day session depending on scenario complexity and seniority of participants — the premium buys objectivity, current threat intelligence, and, for board-level exercises, an outside authority participants take more seriously than a colleague.

Facilitation Typical cost per session Best used for
Internal €3,000–€8,000 Routine, lower-stakes departmental drills
Consultant-facilitated €8,000–€25,000 Annual board/executive-level exercises, first-time programmes

A practical middle ground many mid-market entities use: consultant-facilitated once a year for the board-level exercise, internally run quarterly for departmental drills in between.

Post-Incident Review Cost

Post-incident review is the fifth phase in BSI’s incident-handling model, sitting alongside prevention, detection, management, and communication as a standing obligation rather than an afterthought [3]. It rarely appears as its own line item because it’s mostly staff time — a structured review meeting, ideally held within roughly a week of the incident closing, plus the hours to document what happened, why the response worked or didn’t, and what changes follow. For a mid-market entity, that’s typically 2–4 person-days of combined security, IT, and compliance time per significant incident — call it €2,000–€6,000 in loaded labour, not a new procurement line. The real cost of skipping it isn’t the review itself; it’s repeating the same gap in the next incident, and auditors reviewing incident-handling evidence consistently look for a documented lessons-learned record precisely because a missing one signals the cycle isn’t closing.

Building Your Incident-Handling Budget

Adding the five cost lines together by organisation size gives a defensible total — the synthesis no single vendor page provides, because vendors price their own layer, not the stack. This is the incident-handling slice specifically; for the full NIS2 programme budget across all ten Article 21 measures, see the site’s whole-programme compliance cost guide.

Budget line Small (<250 staff) Mid-market (250–1,000) Large (1,000+)
Sourcing (MSSP/hybrid/SOC) €24,000–€60,000 €60,000–€200,000 €350,000+
SIEM / detection €0–€35,000 (open-source or bundled) €59,000–€110,000 €110,000–€250,000+
IR retainer €10,000–€25,000 €25,000–€60,000 €60,000–€100,000+
Tabletop exercise (annual) €3,000–€8,000 €8,000–€15,000 €15,000–€25,000
Post-incident review (per incident) €2,000–€4,000 €3,000–€6,000 €6,000–€10,000+
Approximate annual total €39,000–€132,000 €155,000–€391,000 €541,000–€735,000+

This table is original synthesis built from the sourcing, SIEM, retainer, and exercise figures cited above — treat it as a planning starting point, not a quote. Actual spend depends on sector risk profile, existing tooling, and how much is already covered by broader IT security budget rather than a dedicated NIS2 line.

What to Present to the Board vs What Compliance Officers Need

These two roles need the same numbers framed differently. The board wants the total annual figure set against the alternative: NIS2 fines can reach €10 million or 2% of global annual turnover for essential entities, with management held personally accountable for compliance failures — a budget conversation that lands better as risk avoidance and audit-readiness than as a cybersecurity line item. See the site’s penalties guide for the full fine structure by entity type. Compliance officers need the same total broken into evidence: which line items produce the documentation an auditor will ask for — the incident log, the notification forms mapped to the Article 23 timeline, the tabletop exercise record, and the post-incident review write-up. Budget conversations that only cite the total figure tend to lose the line-item detail auditors actually check; keep both versions ready.

Frequently Asked Questions

What’s the minimum I need to spend to comply with NIS2 Article 21(2)(b)?
There’s no fixed minimum — the Directive requires proportionate measures relative to your size and risk exposure [1]. In practice, a small Important entity can meet the baseline with a documented incident-handling policy, a notification workflow mapped to the 24h/72h/1-month clock, and either an entry-level MSSP contract or a named DFIR point of contact, landing near the low end of the €25,000–€90,000/yr band above.

Is an in-house SOC or an MSSP cheaper for a mid-sized company?
For most organisations under roughly 1,000 employees, MSSP or hybrid sourcing is cheaper than building 24/7 in-house coverage, because a round-the-clock internal SOC needs 4–5 analysts minimum to cover shifts — a headcount cost that doesn’t scale down for smaller log volumes the way outsourced pricing does.

Do I need a commercial SIEM to comply with NIS2 incident handling?
No specific tool is mandated. What’s required is the ability to detect and evidence a significant incident within the Article 23 timeline [2] — an open-source platform can satisfy that if you have the engineering capacity to run it; if not, the license cost of a commercial SIEM is effectively buying that missing engineering capacity.

How much should I budget for an incident response retainer?
Industry pricing runs €10,000–€100,000/yr depending on prepaid hours and response SLA [7]; most mid-market entities land in the €25,000–€60,000/yr range, which typically covers a 2–4 hour response SLA and enough retained hours to handle one moderate incident without triggering emergency rates.

Are tabletop exercises mandatory under NIS2?
The Directive itself doesn’t name tabletop exercises specifically, but Germany’s BSI explicitly recommends regular crisis exercises as part of the incident-handling obligation [3], and auditors in most member states treat an untested incident response plan as a compliance gap in practice.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. “Article 21 — Cybersecurity risk-management measures,” NIS2 Directive (EU) 2022/2555 — nis-2-directive.com
  2. “Article 23 — Reporting obligations,” NIS2 Directive (EU) 2022/2555 — nis-2-directive.com
  3. “NIS-2 Incident Response,” Bundesamt für Sicherheit in der Informationstechnik (BSI) — bsi.bund.de
  4. “NIS-2-Meldepflicht,” BSI — bsi.bund.de
  5. “Cost of a Data Breach 2026: IBM Benchmarks and Reduction Plan” (citing IBM Cost of a Data Breach Report 2025) — deepstrike.io
  6. “How Much Does an MSSP Cost in 2026?” MSSPProviders.io — msspproviders.io
  7. “Incident Response Cost 2026: $300-$1,500/hr & Retainers,” IncidentCost.com — incidentcost.com
  8. “Splunk vs Microsoft Sentinel Cost: 2026 Side-by-Side at 5/50/200 GB,” SIEMCostCalculator.com — siemcostcalculator.com
  9. “Open Source SIEM for MSPs: Wazuh vs Splunk Cost Analysis,” OpenMSP.ai — openmsp.ai
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: