What does NIS2 compliance cost in Luxembourg?

What actually drives the price, what an SME should expect to pay, and how the State scheme can cover 70% of it.

There is no published tariff for NIS2 compliance, and quotes for what sounds like the same work vary by a factor of five. That is not always vendors being opportunistic. It usually reflects three things being bundled together that ought to be priced separately.

The three costs, kept apart

1. Finding out where you stand

Establishing whether the law applies to you, assessing yourself against the ten Article 21 measures, and testing what is actually exposed. This is a defined piece of work with a defined end. It should be a fixed price, and if a provider will not fix it, ask why.

2. Writing what you are required to hold

Risk analysis, security policy, multi-annual action plan, incident procedure, supplier clauses. Also finite, also fixable. The variable that moves this number is not your size — it is whether anything already exists.

3. Fixing what the assessment found

This is the one nobody can quote in advance, because it depends entirely on what is there. Rolling out multi-factor authentication across sixty users is inexpensive. Replacing an unsupported line-of-business application is not. Any provider quoting a single all-in price before assessing you is either padding heavily or planning to come back with change requests.

Insist that the first two are fixed and the third is quantified only after the assessment. That structure protects you and it is how a competent provider prefers to work anyway.

What an SME should expect

For a Luxembourg company of roughly 20 to 250 staff, with one primary IT environment, an assessment and full documentation set is a matter of weeks rather than months, and should land in the region of €6,900 as a fixed price. Below that, something is missing — usually the technical testing, leaving you with documents nobody has verified. Substantially above it, you are typically paying for a brand or for scope you do not need.

Remediation is genuinely open-ended, but for most SMEs the assessment finds a short list of unglamorous items: multi-factor authentication not fully deployed, backups never actually restored, administrator accounts nobody has reviewed in three years, and an IT contract with no security clauses. None of those is expensive to fix. They are simply nobody's job until someone writes them down.

The 70% the State may pay

The Ministry of the Economy runs a scheme called SME Packages — Cybersecurity which reimburses eligible Luxembourg SMEs 70% of eligible costs, for projects between €3,000 and €25,000 excluding VAT, capped at a maximum subsidy of €17,500.

Worked exampleAmount
Project cost, excl. VAT€6,900
Reimbursement at 70%€4,830
Net cost to you€2,070

How it works in practice

  1. You arrange an appointment through the House of Entrepreneurship at the Chamber of Commerce, or through the Chambre des Métiers if you are a craft business.
  2. The Luxembourg House of Cybersecurity carries out a preliminary analysis of your situation and identifies priority actions. This step is required, not optional.
  3. You choose your provider and obtain a quote in the format the application requires.
  4. You submit the application; the Ministry decides.
  5. The work is carried out, closed with an evaluation meeting, and you submit the final invoice for reimbursement.

Two things to plan around. Reimbursement comes after the work is complete, so you carry the cash flow in the meantime. And the decision sits with the Ministry — no provider can promise you the subsidy, and you should treat it with suspicion if one does.

The cost of not doing it

The headline figures are the administrative fines: up to €10 million or 2% of worldwide turnover for essential entities, up to €7 million or 1.4% for important entities. For most SMEs those numbers are theoretical, and quoting them as a sales tactic is a little dishonest.

Two consequences are far more likely to reach you. The first is commercial: large clients increasingly require evidence of security measures at contract renewal, and being unable to produce it costs revenue long before it costs a fine. The second is personal: the law makes the management body responsible for approving the security measures and for being trained on them, which is not a liability that can be fully delegated to an IT provider.

A note on accuracy. Scheme figures are those published by guichet.public.lu at the time of writing and should be verified before you rely on them. This is a plain-language summary for information only, not legal or financial advice.