Search for "NIS2 costs" and you mostly find quotes: implementation projects, baseline assessments, certifications. That market exists because organisations that fall under the law themselves free up budget for it. For a supplier that does not fall under the law itself, the bill looks different, and it is considerably smaller.
Where does the NIS2 bill sit?
In hours, not in purchases. The questions customers ask cover ten topics, and for most of them the question is not whether you need to buy something, but whether you know how it is arranged at your company and whether that is written down anywhere.
The biggest cost item at suppliers is therefore figuring-out work that repeats: for every new questionnaire, working out again who knows the answer, what was configured back then and where that is recorded. One list of a hundred-plus questions easily costs a few working days when the answers are not recorded anywhere. With three customers a year, that adds up to weeks.
What do the ten measures themselves cost?
Less than the question forms suggest, because most of it already sits in your existing software:
- Multi-factor authentication is in virtually every business mail package. Switching it on costs an afternoon of walking colleagues through it, not a licence.
- Disk encryption ships with Windows and macOS.
- Backups with a restore test usually run already; the restore test itself costs an afternoon a year.
- A password manager costs a few euros per user per month.
- Security training does not have to be a classroom with actors: there is usable free material, and paid programmes start at a few tens of euros per employee per year.
What remains is writing: a risk analysis and a short security policy, an arrangement for incidents, and the answers to the ten topics recorded properly once. For a company of up to roughly fifty employees, all of that together is closer to a week spread over a quarter than to a project with a steering committee.
Do I need an advisor?
For the basics, usually not. The ten topics are not specialist work; they mostly need someone who is given a few half-days for them.
An advisor pays off at two moments. When a customer demands an audit or a formal maturity level, and when you suspect you fall under the law yourself; that last one is a legal question. Count on roughly one to two hundred euros per hour for security consultancy; a baseline assessment of a few days therefore runs into the thousands. Before you sign, ask yourself which question from which customer that amount answers.
Do I have to get ISO 27001?
Not because NIS2 says so. The law names no certificate, and most customers ask for demonstrability, not for a stamp: showing that your measures work is almost always enough.
An ISO 27001 track easily costs an SME ten thousand to several tens of thousands of euros in implementation and certification audit, plus a lead time of six to twelve months and yearly surveillance costs. That can be a good investment when large customers structurally ask for it or when it wins you tenders. Do not start on it because a quote has "NIS2" in it.
What does doing nothing cost?
No fine, because none exists for suppliers who fall outside the law themselves. The bill arrives through revenue: a customer who has to account for their supply chain and gets no answers picks a supplier who does have them at the next round. On top of that, you pay the full figuring-out time again with every questionnaire, exactly the hours that recording things once would have saved.
What does Ketenpas cost?
The scan is free and stays free: 39 questions along the ten topics, with a score and an action list, no account needed. Paying only starts when there is a customer questionnaire you do not want to fill in by hand: Pro costs € 39 per month, Plus with multiple entities and an API € 99 per month. The current amounts and what each plan includes are on the pricing page.
Where do I start?
By knowing where you stand, because that is the one part that costs nothing. Take the scan or go through the ten topics yourself, and within a morning you know which of the points above will cost you time and which are already arranged.
This page gives general information and is not advice; the amounts mentioned are indications as of August 2026. What it costs at your company depends on your size and on what is already arranged.