Resources

NIS2

In depth

D.Lgs. 138/2024

Updated 23 September 2026

by Victor Mita

How much NIS2 compliance costs an SME

Consultancy, kits, platforms, technical work and internal time. The figures published by the market, where they come from and how to read them.

In brief

There is no official price for NIS2 compliance. The cost depends on how big you are, whether you are an essential or an important entity, how well organised you already are and how much technical work you still need. The estimates published by the people who sell these services range from a few hundred euros for a document kit to €5,000 to €40,000 for an SME, and up to €30,000 to €70,000 in the first year for a company with 50 to 200 employees, technical work included. The cost that almost nobody puts in the quote is your people's time.

All the figures in this article come from firms that sell consultancy, kits or software, ourselves included. We found no independent surveys of NIS2 costs in Italy: read them as market estimates, not as reference prices.

The five cost items

  1. Consultancy: initial analysis (gap analysis), drafting policies and procedures, ongoing support.
  2. Kits and packaged software: document templates and small tools you use on your own.
  3. Platform: software that organises measures, evidence, incidents, suppliers and deadlines.
  4. Technical work: multi-factor authentication, tested backups, endpoint protection, monitoring. The measures of the ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) require some of it. It is often the largest item, and no compliance software does it.
  5. Internal time: the people who gather information, decide, approve and keep everything up to date.

What the published estimates say

Consultancy. Edirama (September 2025) publishes some examples of fees:

  • preliminary assessment for a manufacturing SME, about 5 days: €5,000 to €7,500;
  • staff training, 3 days: €3,000 to €5,000;
  • ongoing annual consultancy with vulnerability monitoring and incident support: €20,000 to €50,000 a year;
  • full six-month project for a large organisation: €100,000 to €200,000.

Full programme for an SME. Three estimates from IT and security firms:

  • BullTech (March 2026): €5,000 to €15,000 for simple SMEs and €15,000 to €40,000 for complex SMEs, covering the initial audit, technical measures, training and, where needed, an external DPO (data protection officer).
  • BullTech (March 2026): €30,000 to €70,000 estimated for the first year, of which €3,000 to €8,000 for gap analysis and initial consultancy and €15,000 to €40,000 for technical implementation, then €2,000 to €5,000 a month with a managed service provider. The author explains that the figures come from their own experience with companies of 50 to 200 employees in Lombardy.
  • ESM Italia (June 2026): €30,000 to €150,000 spread over two or three years for an SME with 50 to 200 employees. The items include: gap analysis €3,000 to €15,000, policies and procedures €3,000 to €10,000, training €2,000 to €8,000 a year, SOC (security operations centre) or managed security services €10,000 to €40,000 a year.

So the widely quoted range of €30,000 to €70,000 for the first year includes the technical work. It is not the price of document consultancy alone.

Kits. Edirama sells a kit of six software tools for NIS2 inspections for €1,200 plus VAT and a software tool for relevant suppliers for €399. These are discounted prices, seen on the website on 22 September 2026.

Platforms. Legiscope, which itself sells software, estimates (July 2026) €5,000 to €40,000 a year for platforms aimed at SMEs and mid-sized companies, and from €50,000 to over €200,000 a year for enterprise suites. Many platforms, ours included, do not publish a price list.

The hidden cost: internal time

We found no reliable public data on how many hours it takes, so we do not give a number. We do know what the rules ask for. According to the ACN Reading Guide (Guida alla lettura), the requirements of the basic measures are “for the most part organisational”: policies, plans, inventories, procedures and registers. Even with a consultant, someone in the company has to:

  • provide the information on systems, suppliers and processes;
  • decide which systems are relevant and which risks to accept;
  • have the policies approved by the management bodies, which must also take cybersecurity training (Article 23 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition);
  • keep inventories, registers and evidence up to date every year, as well as the submissions on the ACN portal (see registration and the annual update).

When you compare two quotes, ask how much of your time each one assumes. A low quote that leaves all the work to you can cost more than a high one.

How to keep the cost under control

  • Use the scope the rules allow you. Many requirements apply “to at least the relevant information and network systems” or “in accordance with the results of the risk assessment”. A good list of relevant systems reduces the work (see the ACN basic measures).
  • Reuse what you have. ISO 27001 documents, GDPR records and supplier contracts are often a good starting point. ACN does not impose a template for the risk assessment (FAQ MSB.9).
  • Separate documents from technical work. Ask for separate quotes for the document side and for the technical work: that way you understand what you are buying.
  • Look at the second year. The annual update, the supplier list and the policy review come back every year. Ask for the cost of maintenance, not just the cost of the first year.
  • Consider the MIMIT voucher. The Cloud & Cybersecurity voucher from MIMIT (Italy's Ministry of Enterprises and Made in Italy) covers 50% of eligible costs, up to €20,000 per company (the MIMIT notice also states a minimum of €4,000). Applications can be submitted from 10 November 2026 to 20 January 2027 and are handled in order of arrival. It only applies to purchases from suppliers on the MIMIT list: check this before you sign.

And the cost of not doing it?

For the most serious violations, fines reach up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities, with a minimum set by law (Article 38). The full picture, with a worked calculation, is in the guide to NIS2 fines. There is no need to panic: you just need to know it when you compare quotes.

How much Epic Assess costs

Epic Assess does not have a public price. There is a single plan, with a price tailored to each company that we set with you in a 30-minute call. When you compare it with the other items, remember that a platform organises the document work but does not replace the technical work or the decisions of your directors. If you want to compare it with the alternatives, read how to choose NIS2 software.

Sources

The sources are published in Italian.