Abstract network security visualization representing segmented network zones

NIS2 Network Security Cost: What SMEs, Mid-Market, and OT Operators Actually Pay (EUR 5K–200K+)

A EUR 50,000 SIEM quote and a EUR 6,000 SIEM quote can both be legitimate answers to “what does NIS2 network security cost,” because they’re pricing two different things. Article 21(2)(e) of the NIS2 Directive requires “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure” [1] — not a single product, but a category of spend that scales from a firewall refresh at a 60-person firm to a multi-year OT segmentation programme at an industrial operator. This guide breaks that category into three company-size tiers, prices the specific tools each tier actually buys (SIEM, EDR, NDR, segmentation, managed SOC), and reconciles those figures against Germany’s official regulatory impact assessment — which shows why any single “average NIS2 cost” figure is close to useless for budgeting.

Which Cost Tier Applies to You

Network-security spend under NIS2 tracks company size and network complexity more tightly than sector. Use this table to find your starting point before reading the detail below.

Tier Profile Typical 1st-year network-security spend What it mainly buys
SME refit 50–249 staff, single office network, no OT EUR 5,000–20,000 Firewall/segmentation refresh, endpoint protection (EDR), basic log management
Mid-market programme 250–1,000 staff, multiple sites or cloud estate EUR 20,000–60,000 SIEM or managed SIEM, formal segmentation project, MFA rollout
Enterprise / OT 1,000+ staff, or any size with industrial/OT networks EUR 50,000–200,000+ SIEM+NDR stack, IT/OT segmentation, 24/7 monitoring (in-house or managed SOC)

These are network-security-specific figures — the technical controls slice of Article 21(2), not the full NIS2 programme (which also covers policy work, incident-response planning, supply-chain due diligence, and training). For the full ten-measure budget, see our NIS2 compliance cost and budget-tier guide; network-security tooling typically runs 25–40% of that total.

What Article 21(2)(e) Actually Covers — and What It Doesn’t

Point (e) is narrower than “network security” as a marketing term. It covers the acquisition, development, and maintenance of network and information systems, plus vulnerability handling and disclosure — in practice, secure procurement, patch management, and a documented vulnerability-handling process [1]. Three adjacent Article 21(2) points do the rest of the work most people mean by “network security”: point (g) covers basic cyber hygiene, including segmentation; point (i) covers access control; and point (j) covers multi-factor authentication and secured communications. Our four-zone network segmentation guide maps all four points to a concrete architecture. Budgeting for “Article 21(2)(e) compliance cost” in isolation understates the real spend — the tools below span all four points, because that’s how security teams actually buy them.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Germany’s EUR 70,000 Average — and Why It Hides a 20x Range

Germany’s federal government published the only rigorous, primary-source cost figure available for NIS2 anywhere in the EU: its regulatory impact assessment for the NIS2UmsuCG estimates EUR 2.1 billion in one-time and EUR 2.2 billion in annual costs across roughly 30,000 affected entities — an average of about EUR 70,000 one-time and EUR 73,000 annually per company [4]. As a general guideline, treat that figure as a mean, not a plan: it’s an average across a distribution that runs from small “important entities” at 50 employees to critical-infrastructure operators with thousands. Germany’s national cybersecurity authority, the BSI, now supervises roughly 29,500 entities under the expanded law — up from 4,500 before NIS2 [2][3] — and that population skews heavily toward the small end of the range. A single mean across a 20x-wide distribution tells a 60-person firm almost nothing about its own budget; the tiered breakdown below is more useful.

Tier 1: SME Network Refit (EUR 5,000–20,000)

At 50–249 employees with a single office network, most of this budget goes to two line items: a segmentation-capable firewall refresh (EUR 3,000–8,000 in hardware/licensing) and endpoint detection and response (EDR) at EUR 3–8 per endpoint per month for entry-tier products [6] — roughly EUR 3,000–7,000 a year for a 100-seat environment. A lightweight log-management or SIEM-lite tool adds EUR 1,000–4,500 a month for self-service tiers [5], though many SMEs at this size skip a dedicated SIEM entirely and rely on their EDR vendor’s built-in alerting. External consulting for the segmentation design and documentation typically runs EUR 1,000–2,000 per day [4], with 3–5 days covering a straightforward single-site network. Our 90-day SME compliance roadmap sequences this work so the technical spend lands after the gap analysis, not before it.

Tier 2: Mid-Market Network Security Programme (EUR 20,000–60,000)

Once a company runs multiple sites or a meaningful cloud estate, the cost driver shifts from hardware to log volume and integration work. Managed SIEM for a mid-market environment (25–100 employees generating moderate log volume) runs roughly EUR 2,300–6,000 a month, or EUR 28,000–72,000 a year [5] — the single largest line item at this tier. Mid-market EDR sits at EUR 7–17 per endpoint per month [6]. A formal segmentation project (documented zones, access-control policy, remote-access hardening per CIR Annex requirements) adds a one-time EUR 8,000–25,000 depending on site count. Multi-factor authentication rollout across the estate is comparatively cheap — usually EUR 2–5 per user per month on top of an existing identity platform — but the integration and helpdesk load around it is where mid-market budgets consistently overshoot initial estimates.

Tier 3: Enterprise and OT Network Security (EUR 50,000–200,000+)

Above roughly 1,000 employees, or at any size once industrial (OT) networks are in scope, cost stops scaling linearly. Enterprise SIEM processing 500 GB of logs a day runs EUR 320,000–400,000 a year in fully loaded cost once storage, deployment, and tuning are included [7] — which is why many enterprise security teams pair a flatter-priced network detection and response (NDR) platform alongside it (see the comparison below) rather than scaling SIEM ingestion alone. Genuine OT/ICS network segmentation is where the “+” in this tier’s range matters: initial microsegmentation deployments for manufacturing environments run EUR 460,000–3.7 million, and full IEC 62443-aligned industrial segmentation programmes run EUR 2.8–7.4 million over 18–36 months [8]. If your organisation’s OT footprint is limited to a handful of production-line PLCs behind an existing IT/OT firewall, expect the lower half of the EUR 50,000–200,000 band; if it includes a distributed industrial network across multiple sites, budget toward the multi-million-euro segmentation figures separately — don’t fold them into a generic “network security” line item.

SIEM vs. EDR vs. NDR: What Each One Actually Costs

These three tool categories get bundled into “network security cost” constantly, but they price on entirely different models, which is the main reason budgets miss.

Tool Pricing model Typical annual cost (mid-market) Best fit
SIEM Per-GB log ingestion — scales with every new app, cloud workload, or device [5][7] EUR 28,000–72,000 (managed, mid-market); EUR 320,000–400,000+ at enterprise volume Compliance evidence, cross-source correlation, audit trail
EDR / MDR Per-endpoint per month — predictable, scales with headcount not data volume [6] EUR 7–17/endpoint/month (EDR); add EUR 23–46/endpoint/month for managed detection and response Endpoint containment, ransomware response
NDR Flat, throughput-based — no per-log or per-device charge [7] EUR 74,000–185,000/year licensing (enterprise) + EUR 9,000–28,000 storage East-west traffic visibility, unmanaged/IoT/OT devices SIEM can’t instrument

The practical rule: SIEM’s ingestion-based pricing means costs grow with every system you add, which is exactly wrong for a network that keeps expanding. NDR’s flat throughput pricing makes it the more budget-predictable choice as you scale, at the cost of a higher entry price — which is why NDR only shows up in the enterprise tier above, not the SME tier. Vendor benchmarks put a fully loaded three-year enterprise SIEM programme at EUR 910,000–1.56 million against EUR 320,000–830,000 for a comparable NDR deployment [7]; most enterprise teams run both, using NDR for network-layer detection and SIEM for the compliance-grade audit trail Article 21(2)(f) effectiveness reviews require.

Build vs. Buy: In-House SOC vs. Managed SOC

For any organisation without an existing 24/7 security team, the build-vs-buy decision on monitoring dwarfs every tool line item above. Managed SOC services in 2026 run roughly EUR 9–55 per device per month depending on coverage hours and response depth, with mid-market packages typically landing at EUR 14–28 per endpoint per month for continuous monitoring, detection, and response [9]. For a representative 500-employee organisation with 800 endpoints, that works out to roughly EUR 660,000–995,000 over three years for a managed service — against an estimated EUR 5.8 million over the same period to build and staff an equivalent in-house SOC (three shifts of analysts, tooling, and management overhead) [9]. As a general guideline, in-house SOC only pencils out once headcount and log volume justify a dedicated team of six or more analysts; below that, a managed SOC or MDR contract typically both costs less and covers gaps a single in-house analyst can’t staff around the clock.

A Practical Way to Build the Budget

Rather than pricing tools first, work backward from your gaps. Run a current-state vs. required-state gap analysis against Article 21(2)(e), (g), (i), and (j) specifically — our NIS2 maturity self-assessment gives a structured way to do this — and price only the gaps, not a full re-architecture. A company with a modern next-gen firewall and existing EDR may only need segmentation documentation and an MFA rollout to close its network-security gap, landing well under the SME tier ceiling; a company still running flat, unsegmented networks on legacy firewalls will hit the top of its tier even at modest headcount. Vulnerability handling and disclosure — the second half of point (e) — is frequently the cheapest line item to close and the one most gap analyses skip; see our vulnerability disclosure policy guide for what CSIRT coordination actually requires in documentation terms.

For the board conversation, frame the number both ways: as a percentage of the EUR 10 million essential-entity penalty ceiling, and as a percentage of existing IT spend. A mid-market programme at the top of its EUR 20,000–60,000 tier is still 0.6% or less of that penalty ceiling — but it’s also a real, recurring line in next year’s IT budget, and framing it only against the fine risks under-resourcing the ongoing monitoring costs (managed SOC, SIEM licensing) that don’t disappear after year one. Present both the one-time project cost and the annual run-rate separately; boards approve the first number faster than they approve the second, and NIS2 network security spend is dominated by the second.

FAQ

Is EUR 5,000 realistic for full NIS2 network security compliance?
Only for a small, already-reasonably-secure organisation closing specific gaps — not for a full network security programme from a standing start. Treat the EUR 5,000–20,000 SME band as a range, not a floor.

Does network security cost count toward the EUR 10 million penalty exposure?
No — they’re separate. The penalty is a consequence of non-compliance with Article 21 or Article 23; network-security spend is the cost of avoiding that exposure. See our access control and HR security guide for how point (i) spend interacts with the same risk-management obligation.

Do I need both SIEM and NDR, or just one?
Most mid-market organisations start with SIEM (or managed SIEM) alone, since it doubles as compliance evidence. NDR typically gets added once IoT, OT, or unmanaged devices create blind spots SIEM’s log-based approach can’t cover — usually at the enterprise/OT tier, not before.

Why do OT security costs vary so much more than IT costs?
Because OT segmentation projects touch legacy industrial protocols that can’t simply be patched or replaced, and downtime during implementation risks production — both factors that push cost and timeline well beyond a comparable office-IT project [8].

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS 2 Directive (EU) 2022/2555, Article 21(2) — full sub-point text
  2. BSI (Germany’s national NIS2 competent authority) — NIS-2-regulierte Unternehmen
  3. BSI press release, 2025-12-05 — NIS-2-Umsetzungsgesetz in Kraft
  4. secjur.com, citing the German federal government’s regulatory impact assessment (Bundestag Drucksache 20/13184) — NIS2 Kosten: Was die Umsetzung wirklich kostet
  5. Cribl — Understanding SIEM costs in 2026
  6. Bellator Cyber — MDR vs EDR Pricing Comparison 2025-2026
  7. Vectra AI — SIEM vs NDR compared
  8. Elisity — Cybersecurity Budget 2026: Benchmarks & Spending Trends
  9. UnderDefense — Managed SOC in 2026: The Complete Guide
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: