Abstract visualization of a rising cybersecurity risk-management budget represented by glowing data nodes

NIS2 Risk Management Cost: EUR 3,000–100,000+ Budget by Company Size (Art. 21(2)(a))

Article 21(2)(a) of the NIS2 Directive requires “policies on risk analysis and information system security” [1] — four words that, in practice, become a budget line fought over by every other department. A 2024 survey of 500+ EU IT decision-makers found that when NIS2 forces companies to divert funds from elsewhere, risk management budgets get raided more than any other line item: 34%, ahead of recruitment (30%), crisis management (29%), and emergency reserves (25%) [6]. If you’re the person defending this number to finance, you need more than a single total — you need the six things it actually pays for and why the figure changes by company size.

This guide breaks the risk-management budget into three realistic tiers, six line-item cost drivers, and the proportion of your total compliance spend it should represent. It does not price your entire NIS2 program — for that, see our full NIS2 compliance cost guide, which covers all ten Article 21(2) measures.

Who This Budget Applies To

Article 21(1) sets the legal basis for tiering this budget in the first place: measures must reflect “the cost of implementation” and “ensure a level of security of network and information systems appropriate to the risks posed,” with proportionality judged on the entity’s size, risk exposure, and incident likelihood [1]. In plain terms: the Directive itself tells you not to spend enterprise money on an SME’s risk profile — and not to under-fund a large, complex entity’s.

Entity Type Size Threshold Typical Risk-Management Reality
Important entity 50–249 staff, EUR 10–50M turnover Single risk register, one owner, few legacy systems
Important entity (larger) 250+ staff under some sector caps Multiple business units, some legacy integration debt
Essential entity 250+ staff, EUR 50M+ turnover, critical sector Multi-entity risk aggregation, board-level reporting, audit trail requirements

If you’re still confirming which category you fall into, our NIS2 risk assessment guide for SMEs walks through scope and methodology before you commit to a budget tier.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

What Article 21(2)(a) Actually Requires You to Fund

The statutory text is short — “policies on risk analysis and information system security” [1] — but it is the one Article 21(2) measure every other measure structurally depends on. Your supplier classification (Article 21(2)(d)), your incident severity thresholds (Article 21(2)(b)), and your business continuity triggers (Article 21(2)(c)) all need to reference the same risk register and the same likelihood/impact scale. Budget for risk management, in effect, buys three deliverables: a documented risk analysis methodology, a populated risk register with treatment decisions, and an information security policy that states how the organisation responds to what the register shows.

The Three Risk-Management Budget Tiers

These tiers are our own synthesis, built bottom-up from the six cost drivers below — not a single published source. We size them by organisational complexity (number of business units, existing security maturity, in-house headcount available), which tracks Article 21(1)’s own proportionality test more closely than headcount alone.

Tier Budget Range Profile
Lean SME EUR 3,000–10,000 Single entity, one risk owner (often the IT lead wearing a second hat), templated risk register, no dedicated GRC tool
Mid-market EUR 12,000–35,000 50–250 staff, part-time compliance function, entry-level GRC or spreadsheet-plus-workflow tooling, some external consultant hours
Enterprise EUR 40,000–100,000+ Multiple legal entities or business units, dedicated risk function, integrated GRC platform, recurring external audit support

For scale, Kiteworks’ whole-program NIS2 estimates put essential-sector, all-measure first-year compliance at EUR 200,000–750,000 [5]. Risk management alone should not approach that figure on its own — which is exactly why isolating this line item matters when you’re negotiating budget with finance.

Six Cost Drivers, Line by Line

Every tier above is built from the same six line items — they just scale differently by organisational complexity.

Driver Lean SME Mid-Market Enterprise
GRC tooling / risk register EUR 0–500 (spreadsheet or free tier) EUR 2,000–8,000/yr EUR 10,000–100,000+/yr
External consultant 1–3 days 5–15 days 20+ days, ongoing retainer
Internal staff time 40–80 hours 150–400 hours 800+ hours across multiple owners
Training & awareness Included in staff time EUR 1,000–3,000 EUR 5,000–15,000
Documentation Templates (low cost) Templates + light customisation Bespoke drafting + legal review
Legal review Skipped or minimal 1–2 rounds, external counsel Ongoing counsel involvement

GRC tooling is the widest-swinging driver: small-to-mid-market risk platforms run USD 10,000–100,000 a year, while enterprise multi-entity deployments with custom integration reach USD 100,000–500,000+ over a multi-year contract [4]. A lean SME with one risk owner and under 50 assets doesn’t need a platform at all — a well-structured spreadsheet plus a documented methodology satisfies Article 21(2)(a) just as legally as software does. The mistake we see most often is a 60-person company buying a EUR 40,000/year enterprise GRC platform for a risk register that fits on two tabs.

External consultant costs track day rates that have climbed 15–20% since 2024 on demand and auditor-shortage pressure: EUR 1,000–1,500/day for independent consultants, EUR 1,300–1,800 for boutique firms, and EUR 1,800–2,500 for Big Four-adjacent engagements in the EU [3]. If all you need is a methodology reviewed and a first risk register populated, 2–5 days from an independent consultant covers it — the boutique and Big Four tiers earn their premium on multi-entity aggregation and audit defensibility, not on writing the same document faster.

Internal staff time is the driver most SMEs underbudget because it doesn’t appear on an invoice. A single risk owner running interviews, gathering asset inventories, and scoring likelihood/impact across even a 50-person company reliably takes 40–80 hours the first time — hours that come out of whatever that person was already doing.

Legal review is the driver most likely to be skipped at the lean-SME tier, and the one most likely to cause rework at audit time. A risk analysis methodology that hasn’t been checked against your actual sector obligations and contractual commitments is a document you’ll be rewriting after your first supervisory authority conversation, not before.

If your only gap is the risk-management measure itself rather than the full ten-measure program, the NIS2 Risk Management Pack (€199) covers the methodology, register, and treatment templates without the rest of the toolkit.

Three Mistakes That Blow Past These Tiers

Three patterns push organisations from their correct tier into the next one up, without adding any real security value.

Treating the risk analysis as a one-time deliverable. A lean SME that budgets EUR 8,000 for a risk register, gets it built, and then never schedules a review cadence ends up paying full setup cost again in 18–24 months when the register is too stale to defend at audit. Budget 30–50% of year-one cost annually from year two onward for quarterly reviews — it’s cheaper than rebuilding.

Buying tooling before complexity justifies it. GRC platforms price largely by framework count and entity count, not by company size directly. A 60-person single-entity company buying a multi-entity enterprise platform pays for aggregation and workflow automation it structurally cannot use yet — often 5–10x what a mid-market tool or a well-built spreadsheet would cost for the identical Article 21(2)(a) outcome.

Skipping legal review to hit the lean-SME number. A risk methodology that copies a generic template without checking it against your actual sector’s asset-criticality definitions — healthcare and energy weight risk categories very differently, for instance — tends to survive until the first real supervisory-authority conversation or incident, at which point it gets rewritten under time pressure. The EUR 1,000–1,500 a competent independent consultant charges to sanity-check a methodology [3] is cheap insurance against redoing the entire document later at double the cost.

What ROI to Expect — and Why This Budget Gets Cut First

As a general planning guideline, risk management should represent roughly 3–15% of your total NIS2 compliance budget — low single digits for a lean SME layering it onto an existing IT security spend, up to the higher end for an enterprise standing up a dedicated risk function from scratch. That’s a wide range deliberately: risk management is the one measure that’s mostly methodology and staff time rather than capital spend, so its share shrinks as your total program (technology, training, audit) grows around it.

The ROI case is proportional, not absolute. ENISA’s 2025 survey of 1,080 EU organisations — weighted heavily toward large entities (83% of the sample), so treat the following as directional for bigger organisations rather than literal for a 60-person company — found a median cybersecurity budget of EUR 1.5 million, with 70% of respondents citing regulatory compliance (NIS2, DORA, the Cyber Resilience Act) as their primary investment driver [2]. Compliance is already the reason budgets move; risk management is the measure that determines whether the rest of that spend is aimed at your actual risks or at generic best practice.

That’s also why it’s the line item finance reaches for first when money gets tight. The Censuswide survey for Veeam found 95% of EMEA businesses required to comply with NIS2 diverted funds from elsewhere to fund it, and risk management budgets were the single most-raided source at 34% [6]. If you’re building this budget, build the case for protecting it specifically — not just for NIS2 spend in general.

How to Pitch This Budget by Role

The same number lands differently depending on who’s approving it.

For the CISO or IT security manager: lead with the dependency chain — every other Article 21(2) control cites this risk register, so under-funding it creates rework across incident response, supply chain, and business continuity documentation simultaneously. Ask for the mid-market or enterprise tier if you’re already maintaining more than one system-of-record for assets.

For the SME owner: the honest floor is EUR 3,000–10,000 for a single-entity risk analysis and policy — achievable with templates and a handful of consultant days, without a software subscription. You don’t need enterprise tooling to satisfy Article 21(2)(a); you need a documented, defensible methodology.

For the board: frame it against the proportion, not the total — 3–15% of the compliance budget is a small ask relative to the EUR 10 million / 2% of global turnover maximum administrative fine ceiling for essential entities [7], and it’s the specific line item most likely to be cut under budget pressure, which is a governance risk worth naming explicitly.

Frequently Asked Questions

Does risk management cost more than other Article 21(2) measures?
Not usually in isolation — business continuity and technical controls (patching, cryptography, access control) typically cost more in absolute terms because they involve capital spend. Risk management costs more in staff time and methodology work, which is why it’s easy to underbudget.

Can we do risk management with spreadsheets instead of a GRC tool?
Yes, for the lean-SME tier. Article 21(2)(a) requires a documented policy and analysis, not a specific tool. A well-maintained spreadsheet with a defined methodology, reviewed on a set cadence, satisfies the requirement. Move to a GRC platform when you’re managing risk across more than one business unit or need automated evidence for recurring audits.

How often should we re-budget for risk management?
Treat the first year as the highest-cost year — methodology design and initial register population are one-time costs. Ongoing years should run 30–50% of year-one spend, mostly staff time for quarterly reviews and consultant hours for an annual methodology check. Pair this with our 90-day NIS2 implementation plan to sequence the work rather than budgeting it all at once.

Should we budget before or after a maturity assessment?
After. Our NIS2 maturity assessment tells you which of the six cost drivers you can skip because you already have it (an existing ISO 27001 risk register, for instance) — budgeting first risks paying for capability you don’t need.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS 2 Directive, Article 21 — Cybersecurity risk-management measures. nis-2-directive.com
  2. ENISA, “NIS Investments 2025.” enisa.europa.eu
  3. ISO27001Cost.com, “ISO 27001 Consultant Cost — Day Rates and Engagement Models 2026.” iso27001cost.com
  4. Centraleyes, “GRC Software Pricing: What It Actually Costs in 2026.” centraleyes.com
  5. Kiteworks, “How Much Does NIS2 Compliance Really Cost? Complete Budget Guide.” kiteworks.com
  6. Veeam / Censuswide survey, “NIS2 Robs Organizations’ Resources.” veeam.com
  7. NIS 2 Directive, Article 34 — Penalties. nis-2-directive.com
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: